JobRaahGet matched free

Jobs

Technical Manager – Hardware Root of Trust & Platform Security

lumentum · Canada - Ottawa (Bill Leathem) · On-site

Pay: CAD 130,000 – 180,000 a year

Posted Sep 30, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

It's fun to work in a company where people truly BELIEVE in what they're doing! We're committed to bringing passion and customer focus to the business. If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us! Lumentum Canada was awarded the 2022 National Capital Region’s Top Employers for the 6th consecutive year and the 2022 Career Directory Canada’s Best Employers for Recent Graduates for the 5th consecutive year .   About Lumentum At Lumentum, we’re building the tech behind the world’s fastest networks and most advanced systems. Our optical and photonic solutions power everything from AI and cloud computing to data centers, telecom, and advanced manufacturing. We’re a global team of innovators working where light meets technology, solving big challenges that keep the world connected and moving forward. If shaping the future of connectivity excites you, you’ll fit right in. Why You’ll Love This Role We are seeking a Technical Manager to lead a team responsible for hardware-based security, trusted device identity, secure provisioning, and network authentication. This role will define and deliver security capabilities based on hardware roots of trust, gNSI, Secure Zero Touch Provisioning, and mutual TLS. The manager will work across hardware, firmware, operating-system, networking, cloud, manufacturing, and product teams to establish a trusted security lifecycle from device manufacturing through deployment, operation, upgrade, and retirement. What You’ll Be Doing Lead, mentor, and develop a team responsible for hardware and platform security. Define and implement hardware root-of-trust strategies for embedded and networking products. Oversee the use of TPMs, secure boot, measured boot, hardware-backed keys, device identity, attestation, and trusted execution mechanisms. Lead development and integration of TPM-based DevID and ODevID solutions. Establish device identity lifecycle processes, including enrollment, provisioning, renewal, rotation, revocation, recovery, and retirement. Lead implementation of gNSI security services, including certificate management, authentication, authorization, path authorization, and credential management. Oversee Secure Zero Touch Provisioning, including secure device onboarding, bootstrap trust, ownership validation, policy enforcement, and protection against unauthorized provisioning. Oversee the implementation of the mTLS architectures for gNMI, gNOI, gNSI, management interfaces, and service-to-service communication. Establish certificate authority, PKI, certificate-profile, trust-bundle, and revocation-management requirements. Coordinate security architecture across hardware, bootloader, firmware, Linux, containers, networking services, and cloud infrastructure. Define attestation requirements, including PCR selection, measurement policy, device-state validation, and anti-rollback controls. Lead threat modeling, security design…