Technical Manager – Hardware Root of Trust & Platform Security (Quebec City)

Technical Manager – Hardware Root of Trust & Platform Security (Quebec City)

09 Oct
|
Lumentum Operations
|
Quebec City

09 Oct

Lumentum Operations

Quebec City

It's fun to work in a company where people truly BELIEVE in what they're doing! We're committed to bringing passion and customer focus to the business. If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us! Lumentum Canada was awarded the 2022 National Capital Region’s Top Employers for the 6th consecutive year and the 2022 Career Directory Canada’s Best Employers for Recent Graduates for the 5th consecutive year. About Lumentum At Lumentum, we’re building the tech behind the world’s fastest networks and most advanced systems. Our optical and photonic solutions power everything from AI and cloud computing to data centers, telecom, and advanced manufacturing. We’re a global team of innovators working where light meets technology, solving big challenges that keep the world connected and moving forward. If shaping the future of connectivity excites you, you’ll fit right in.
Why You'll Love This Role We are seeking a Technical Manager to lead a team responsible for hardware-based security, trusted device identity, secure provisioning, and network authentication. This role will define and deliver security capabilities based on hardware roots of trust, gNSI, Secure Zero Touch Provisioning, and mutual TLS. The manager will work across hardware, firmware, operating-system, networking, cloud, manufacturing, and product teams to establish a trusted security lifecycle from device manufacturing through deployment, operation, upgrade, and retirement.
What You'll Be Doing Lead, mentor, and develop a team responsible for hardware and platform security.
Define and implement hardware root-of-trust strategies for embedded and networking products.
Oversee the use of TPMs, secure boot, measured boot, hardware-backed keys, device identity, attestation, and trusted execution mechanisms.
Lead development and integration of TPM-based DevID and ODevID solutions.
Establish device identity lifecycle processes, including enrollment, provisioning, renewal, rotation, revocation, recovery, and retirement.
Lead implementation of gNSI security services, including certificate management, authentication, authorization, path authorization, and credential management.
Oversee Secure Zero Touch Provisioning, including secure device onboarding, bootstrap trust, ownership validation, policy enforcement, and protection against unauthorized provisioning.
Oversee the implementation of the mTLS architectures for gNMI, gNOI, gNSI, management interfaces, and service-to-service communication.
Establish certificate authority, PKI, certificate-profile, trust-bundle, and revocation-management requirements.
Coordinate security architecture across hardware, bootloader, firmware, Linux, containers, networking services, and cloud infrastructure.
Define attestation requirements, including PCR selection,



measurement policy, deviceu2011state validation, and antiu2011rollback controls.
Lead threat modeling, security design reviews, and technical risk assessments for platform and networku2011security features.
Develop security requirements, architecture documents, interface specifications, test plans, and operational procedures.
Coordinate interoperability, integration, penetration, negative, faultu2011injection, and lifecycle testing.
Support customer security reviews, product certifications, audits, and incident investigations.
What We're Looking For Education: Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or a related field.
Experience Experience leading teams developing platform security, embedded security, network security, or infrastructure security products.
Strong understanding of hardware roots of trust, TPM 2.0, secure boot, measured boot, device identity, and remote attestation.
Experience designing or deploying PKI, certificates, certificate authorities, trust stores, and mTLS.
Experience with identity lifecycle management, key rotation, certificate renewal, revocation, and compromise recovery.
Knowledge of gRPC, gNMI, gNOI, gNSI, TLS, authorization, authentication, and policy enforcement.
Experience with secure provisioning, ZTP, SZTP, device enrollment, or manufacturingu2011time device personalization.
Familiarity with Linux, embedded systems, networking protocols, and cloudu2011based security services.
Strong technical leadership, communication, documentation, and crossu2011functional collaboration skills.
Ability to convert security architecture into implementable product requirements and verifiable test cases.
Asset/Nice to Have Experience with OpenConfig security services, gNSI, TPM2u2012Tools, TSS, DevID, IDevID, ODevID, or DICE.
Experience with Intel Boot Guard, UEFI Secure Boot, measured boot, PCR policies, UKIs, dmu2011verity, or antiu2011rollback mechanisms.
Knowledge of SPIFFE/SPIRE, OAuth/OIDC, LDAP, RADIUS, or enterprise identity systems.
Experience with Kubernetes, containers, service meshes, cloud PKI, or cloud KMS.
Familiarity with OpenSSL, BoringSSL, wolfSSL, PKCS#11, HSMs, and cryptographicu2011agility requirements.
Experience securing SONiC, network operating systems, routers, switches, optical systems, or telecommunications equipment.
Success in This Role Success means delivering a trusted device identity and provisioning lifecycle,



strengthening the hardware root of trust, achieving reliable gNSI and mTLS integration, reducing deployment risk, and enabling secure device operation from manufacturing through field deployment and end of life.
Perks You'll Love Flexible time off
Health and wellness advantages (physical and mental)
Tuition reimbursement and career growth support
A workplace built for you: free gym, games room, prayer room
Subsidized meals, free coffee/tea
Employee stock options and incentive plans
A collaborative, innovative, and inclusive culture
Salary Range The salary range for this position is $130,000 - $180,000 CAD (Flexible). Final compensation will be determined based on factors such as experience, skills, and qualifications. In line with our commitment to being a great place to work, Lumentum offers competitive total rewards which may include annual bonus, equity, and comprehensive health and welfare benefits.
Join a Team That's Shaping the Future At Lumentum, we’re more than just a workplaceu2014we’re a launchpad for creativity and innovation. We’re committed to celebrating your unique talents and helping you grow. Our guiding principlesu2014Innovate, Engage, Deliver, Excel, and Winu2014aren’t just words; they’re the heart of what we do. Let’s Build a Brighter Future Together! We’re committed to building an inclusive workplace where everyone feels valued and empowered. We welcome applicants from all backgrounds and provide accommodations for individuals with disabilities throughout the hiring process. Your uniqueness makes us stronger, sparks creativity, and drives our success.
Lumentum is illuminating the networks of tomorrow with advanced photonic technologies that enable AI, data centers, telecom, industrial, and sensing applications. As AI accelerates the global demand for bandwidth and energy efficiency, we deliver the building blocks that keep data moving reliably, efficiently, and at massive scale. Our optical products support AI and compute infrastructure, cloud and DCI environments, metro and longu2011haul networks, while our lasers drive breakthroughs in precision manufacturing and sensing. For nearly five decades, Lumentum has been at the intersection of light and innovation. What began as a vision with JDS Uniphase to harness the power of photonics has evolved into a global force driving the communication infrastructure of tomorrow. At Lumentum, we’re building more than a businessu2014we’re building a team of passionate innovators whose drive to collaborate, create, and connect the world fuels everything we do. We are part of the AI technology revolution and we are illuminating the path forward. Headquartered in San Jose, California, we operate worldwide through a network of R&D;, manufacturing, and sales locations.

#J-18808-Ljbffr

📌 Technical Manager – Hardware Root of Trust & Platform Security (Quebec City)
🏢 Lumentum Operations
📍 Quebec City

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: technical manager – hardware root of trust & platform security (quebec city) / quebec city

Subscribe to this job alert:

Get the latest job offers by email for: technical manager – hardware root of trust & platform security (quebec city) / quebec city