Technical Manager – Hardware Root of Trust & Platform Security
Lumentum · Ottawa, Canada · 1d ago
It's fun to work in a company where people truly BELIEVE in what they're doing!
We're committed to bringing passion and customer focus to the business.
If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!
Lumentum Canada was awarded the 2022 National Capital Region’s Top Employers for the 6th consecutive year and the 2022 Career Directory Canada’s Best Employers for Recent Graduates for the 5th consecutive year.
About Lumentum
At Lumentum, we’re building the tech behind the world’s fastest networks and most advanced systems. Our optical and photonic solutions power everything from AI and cloud computing to data centers, telecom, and advanced manufacturing.
We’re a global team of innovators working where light meets technology, solving big challenges that keep the world connected and moving forward. If shaping the future of connectivity excites you, you’ll fit right in.
Why You’ll Love This Role
We are seeking a Technical Manager to lead a team responsible for hardware-based security, trusted device identity, secure provisioning, and network authentication. This role will define and deliver security capabilities based on hardware roots of trust, gNSI, Secure Zero Touch Provisioning, and mutual TLS.
The manager will work across hardware, firmware, operating-system, networking, cloud, manufacturing, and product teams to establish a trusted security lifecycle from device manufacturing through deployment, operation, upgrade, and retirement.
What You’ll Be Doing
- Lead, mentor, and develop a team responsible for hardware and platform security.
- Define and implement hardware root-of-trust strategies for embedded and networking products.
- Oversee the use of TPMs, secure boot, measured boot, hardware-backed keys, device identity, attestation, and trusted execution mechanisms.
- Lead development and integration of TPM-based DevID and ODevID solutions.
- Establish device identity lifecycle processes, including enrollment, provisioning, renewal, rotation, revocation, recovery, and retirement.
- Lead implementation of gNSI security services, including certificate management, authentication, authorization, path authorization, and credential management.
- Oversee Secure Zero Touch Provisioning, including secure device onboarding, bootstrap trust, ownership validation, policy enforcement, and protection against unauthorized provisioning.
- Oversee the implementation of the mTLS architectures for gNMI, gNOI, gNSI, management interfaces, and service-to-service communication.
- Establish certificate authority, PKI, certificate-profile, trust-bundle, and revocation-management requirements.
- Coordinate security architecture across hardware, bootloader, firmware, Linux, containers, networking services, and cloud infrastructure.
- Define attestation requirements, including PCR selection, measurement policy, device-state validation, and anti-rollback controls.
- Lead threat modeling, security design reviews, and technical risk assessments for platform and network-security features.
- Develop security requirements, architecture documents, interface specifications, test plans, and operational procedures.
- Coordinate interoperability, integration, penetration, negative, fault-injection, and lifecycle testing.
- Support customer security reviews, product certifications, audits, and incident investigations.
What We’re Looking For
Education:
Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or a related field.
Experience:
- Experience leading teams developing platform security, embedded security, network security, or infrastructure security products.
- Strong understanding of hardware roots of trust, TPM 2.0, secure boot, measured boot, device identity, and remote attestation.
- Experience designing or deploying PKI, certificates, certificate authorities, trust stores, and mTLS.
- Experience with identity lifecycle management, key rotation, certificate renewal, revocation, and compromise recovery.
- Knowledge of gRPC, gNMI, gNOI, gNSI, TLS, authorization, authentication, and policy enforcement.
- Experience with secure provisioning, ZTP, SZTP, device enrollment, or manufacturing-time device personalization.
- Familiarity with Linux, embedded systems, networking protocols, and cloud-based security services.
- Strong technical leadership, communication, documentation, and cross-functional collaboration skills.
- Ability to convert security architecture into implementable product requirements and verifiable test cases.
Asset/Nice to Have
- Experience with OpenConfig security services, gNSI, TPM2-Tools, TSS, DevID, IDevID, ODevID, or DICE.
- Experience with Intel Boot Guard, UEFI Secure Boot, measured boot, PCR policies, UKIs, dm-verity, or anti-rollback mechanisms.
- Knowledge of SPIFFE/SPIRE, OAuth/OIDC, LDAP, RADIUS, or enterprise identity systems.
- Experience with Kubernetes, containers, service meshes, cloud PKI, or cloud KMS.
- Familiarity with OpenSSL, BoringSSL, wolfSSL, PKCS#11, HSMs, and cryptographic-agility requirements.
- Experience securing SONiC, network operating systems, routers, switches, optical systems, or telecommunications equipment.
Success in This Role
Success means delivering a trusted device identity and provisioning lifecycle, strengthening the hardware root of trust, achieving reliable gNSI and mTLS integration, reducing deployment risk, and enabling secure device operation from manufacturing through field deployment and end of life
Perks You’ll Love
- Flexible time off
- Health and wellness benefits (physical and mental)
- Tuition reimbursement and career growth support
- A workplace built for you: free gym, games room, prayer room
- Subsidized meals, free coffee/tea
- Employee stock options and incentive plans
- A collaborative, innovative, and inclusive culture
Salary Range
The salary range for this position is $130,000 - $180,000 CAD (Flexible).
Final compensation will be determined based on factors such as experience, skills, and qualifications. In line with our commitment to being a great place to work, Lumentum offers competitive total rewards which may include annual bonus, equity, and comprehensive health and welfare benefits.
Join a Team That’s Shaping the Future
At Lumentum, we’re more than just a workplace—we’re a launchpad for creativity and innovation. We’re committed to celebrating your unique talents and helping you grow. Our guiding principles—Innovate, Engage, Deliver, Excel, and Win—aren’t just words; they’re the heart of what we do.
Let’s Build a Brighter Future Together!
We’re committed to building an inclusive workplace where everyone feels valued and empowered. We welcome applicants from all backgrounds and provide accommodations for individuals with disabilities throughout the hiring process. Your uniqueness makes us stronger, sparks creativity, and drives our success.
Please contact us at talentacquisition@lumentum.com to request accommodation.
Join us—your future starts here!