Technical Manager – Product Security, Vulnerability Management & Software Assurance

Lumentum Operations LLC

Ottawa

On-site

CAD 130,000 - 180,000

Full time

10 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Flexible time off
Health and wellness benefits
Tuition reimbursement
Workspace amenities
Subsidized meals
Employee stock options
Collaborative culture

Job summary

Lumentum is seeking a Technical Manager to lead a team responsible for product vulnerability management, software assurance, secure manufacturing processes, and cloud-based security applications. This role oversees identification, remediation, and reporting of vulnerabilities across embedded and network products, while guiding secure cloud API development and data exchange.

You’ll coordinate with software engineering, product security, cloud engineering, manufacturing, and customer-facing teams

Qualifications

  • Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or a related field.
  • Experience leading software security, product security, vulnerability management, application security, or cloud security teams.
  • Strong understanding of vulnerability management, CVE analysis, CVSS, CWE, SBOM, VEX, and software supply-chain security.
  • Experience with Black Duck, SCA tools, code scanning, or comparable security platforms.
  • Experience defining and operating software-signing and release-security processes.
  • Experience leading the development of cloud applications, secure APIs, or customer-facing security platforms.
  • Knowledge of cloud security principles, identity and access management, encryption, API security, audit logging, and secure data exchange.
  • Experience working with embedded Linux, networking software, or complex hardware/software products.
  • Strong communication, project management, and cross-functional leadership skills.
  • Ability to translate complex security findings into clear engineering and business decisions.
  • Asset/Nice to Have Experience with GCP, Cloud Run, API gateways, cloud databases, cloud KMS, or cloud-based certificate authorities.
  • Experience with REST, gRPC, OAuth 2.0, OIDC, mTLS, PKI, and multi-tenant application design.
  • Experience with SONiC, Linux, containers, firmware, networking, or telecommunications products.
  • Familiarity with SPDX, CycloneDX, CSAF, VEX, SLSA, and SBOM conformance.
  • Experience with CodeQL, Coverity, Blackduck, or similar tools.
  • Knowledge of cryptographic key management, HSMs, cloud KMS, PKI, and trusted build environments.
  • Experience securing manufacturing, provisioning, or product-release operations.

Responsibilities

  • Lead, mentor, and develop a team responsible for software security, vulnerability management, and cloud security applications.
  • Establish processes for identifying, analyzing, prioritizing, remediating, and tracking software vulnerabilities.
  • Manage Black Duck and related Software Composition Analysis tools, including project configuration, scanning, policy review, reporting, and issue resolution.
  • Oversee the creation, validation, and distribution of SBOM and VEX reports.
  • Define vulnerability triage criteria using severity, exploitability, product exposure, reachability, and customer impact.
  • Lead the use of AI-assisted code scanning and security analysis while ensuring findings are validated by qualified engineers.
  • Develop secure software-signing processes, including key management, signing workflows, access control, auditability, and protection against unauthorized signing.
  • Secure and review software manufacturing procedures, including build integrity, artifact provenance, release controls, and production access.
  • Manage the development of a secure cloud application for exchanging device and product-security information with customers.
  • Establish mechanisms for securely ingesting and sharing device information, including device identity, software versions, SBOMs, vulnerabilities, VEX status, attestation results, and security events.
  • Coordinate vulnerability remediation with development and release teams.
  • Promote secure software development practices, threat modeling, code review, and security testing.

Skills

Software security leadership
Vulnerability management
Cloud security
SBOM / VEX reporting
Security testing
Threat modeling
Code review
Secure software signing
Key management
API security / IAM
Embedded Linux / networking
Cross-functional leadership
Project management
Communication
Cloud APIs / OAuth / PKI
Cloud KMS / certificates

Education

Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or related field

Tools

Black Duck
SCA tools
Code scanning tools
CI/CD security tooling

Job description

Why You’ll Love This Role

We are seeking a Technical Manager to lead a team responsible for product vulnerability management, software assurance, secure manufacturing processes, and cloud-based security applications. This role will oversee the identification, assessment, remediation, and reporting of software vulnerabilities across embedded and network products. The manager will also lead the development of a secure cloud application and supporting APIs for exchanging device information with customers. This may include certificates, device identity, software versions, security status, SBOMs, vulnerability data, VEX reports, attestation results, and lifecycle information. The role will work closely with software engineering, product security, cloud engineering, manufacturing, and customer-facing teams.

What You’ll Be Doing
  • Lead, mentor, and develop a team responsible for software security, vulnerability management, and cloud security applications.
  • Establish processes for identifying, analyzing, prioritizing, remediating, and tracking software vulnerabilities.
  • Manage Black Duck and related Software Composition Analysis tools, including project configuration, scanning, policy review, reporting, and issue resolution.
  • Oversee the creation, validation, and distribution of SBOM and VEX reports.
  • Define vulnerability triage criteria using severity, exploitability, product exposure, reachability, and customer impact.
  • Lead the use of AI-assisted code scanning and security analysis while ensuring findings are validated by qualified engineers.
  • Develop secure software-signing processes, including key management, signing workflows, access control, auditability, and protection against unauthorized signing.
  • Secure and review software manufacturing procedures, including build integrity, artifact provenance, release controls, and production access.
  • Manage the development of a secure cloud application for exchanging device and product-security information with customers.
  • Establish mechanisms for securely ingesting and sharing device information, including device identity, software versions, SBOMs, vulnerabilities, VEX status, attestation results, and security events.
  • Coordinate vulnerability remediation with development and release teams.
  • Promote secure software development practices, threat modeling, code review, and security testing.
What We’re Looking For
  • Education: Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or a related field.
  • Experience: Experience leading software security, product security, vulnerability management, application security, or cloud security teams.
  • Strong understanding of vulnerability management, CVE analysis, CVSS, CWE, SBOM, VEX, and software supply-chain security.
  • Experience with Black Duck, SCA tools, code scanning, or comparable security platforms.
  • Experience defining and operating software-signing and release-security processes.
  • Experience leading the development of cloud applications, secure APIs, or customer-facing security platforms.
  • Knowledge of cloud security principles, identity and access management, encryption, API security, audit logging, and secure data exchange.
  • Experience working with embedded Linux, networking software, or complex hardware/software products.
  • Strong communication, project management, and cross-functional leadership skills.
  • Ability to translate complex security findings into clear engineering and business decisions.
  • Asset/Nice to Have Experience with GCP, Cloud Run, API gateways, cloud databases, cloud KMS, or cloud-based certificate authorities.
  • Experience with REST, gRPC, OAuth 2.0, OIDC, mTLS, PKI, and multi-tenant application design.
  • Experience with SONiC, Linux, containers, firmware, networking, or telecommunications products.
  • Familiarity with SPDX, CycloneDX, CSAF, VEX, SLSA, and SBOM conformance.
  • Experience with CodeQL, Coverity, Blackduck, or similar tools.
  • Knowledge of cryptographic key management, HSMs, cloud KMS, PKI, and trusted build environments.
  • Experience securing manufacturing, provisioning, or product-release operations.
Success in This Role

Success means establishing a predictable vulnerability‑remediation process, improving the quality and timeliness of SBOM and VEX reports, protecting software‑signing operations, reducing software supply‑chain risk, and delivering a secure cloud platform that enables customers to exchange and review trusted device and product‑security information.

Perks You’ll Love
  • Flexible time off
  • Health and wellness benefits (physical and mental)
  • Tuition reimbursement and career growth support
  • A workplace built for you: free gym, games room, prayer room
  • Subsidized meals, free coffee/tea
  • Employee stock options and incentive plans
  • A collaborative, innovative, and inclusive culture
Salary Range

The salary range for this position is $130,000 - $180,000 CAD (Flexible). Final compensation will be determined based on factors such as experience, skills, and qualifications. In line with our commitment to being a great place to work, Lumentum offers competitive total rewards which may include annual bonus, equity, and comprehensive health and welfare benefits.

Join a Team That’s Shaping the Future

At Lumentum, we’re more than just a workplace—we’re a launchpad for creativity and innovation. We’re committed to celebrating your unique talents and helping you grow. Our guiding principles—Innovate, Engage, Deliver, Excel, and Win—aren’t just words; they’re the heart of what we do. Let’s Build a Brighter Future Together! We’re committed to building an inclusive workplace where everyone feels valued and empowered. We welcome applicants from all backgrounds and provide accommodations for individuals with disabilities throughout the hiring process. Your uniqueness makes us stronger, sparks creativity, and drives our success. Join us—your future starts here!

Lumentum is illuminating the networks of tomorrow with advanced photonic technologies that enable AI, data centers, telecom, industrial, and sensing applications. As AI accelerates the global demand for bandwidth and energy efficiency, we deliver the building blocks that keep data moving reliably, efficiently, and at massive scale. Our optical products support AI and compute infrastructure, cloud and DCI environments, metro and long‑haul networks, while our lasers drive breakthroughs in precision manufacturing and sensing. For nearly five decades, Lumentum has been at the intersection of light and innovation. What began as a vision with JDS Uniphase to harness the power of photonics has evolved into a global force driving the communication infrastructure of tomorrow. At Lumentum, we’re building more than a business—we’re building a team of passionate innovators whose drive to collaborate, create, and connect the world fuels everything we do. We are part of the AI technology revolution and we are illuminating the path forward. Headquartered in San Jose, California, we operate worldwide through a network of R&D, manufacturing, and sales locations.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Technical Manager – Hardware Root of Trust & Platform Security
Technical Manager – Hardware Root of Trust & Platform Security

Lumentum Operations LLC • Ottawa

On-site
CAD 130,000 - 180,000
Flexible time off
Health and wellness benefits
Tuition reimbursement
+2
Senior Software Automation Engineer
Senior Software Automation Engineer

Lumentum Operations LLC • Ottawa

On-site
CAD 71,000 - 102,000
Flexible time off
Health and wellness benefits (physical
Health and wellness benefits (physical
+2
Automation and Test Engineer - Photonics
Automation and Test Engineer - Photonics

Lumentum Operations LLC • Ottawa

On-site
CAD 110,000 - 150,000
Flexible time off
Health and wellness benefits
Tuition reimbursement and careerGrowth
+3
Product Environmental Compliance Engineer
Product Environmental Compliance Engineer

Lumentum Operations LLC • Ottawa

On-site
CAD 71,000 - 102,000
Flexible time off
Health and wellness benefits
Tuition reimbursement and career growt
Product Engineering Program Manager
Product Engineering Program Manager

Lumentum Operations LLC • Ottawa

On-site
CAD 90,000 - 125,000
Flexible time off
Health and wellness benefits
Tuition reimbursement
+4
Senior Embedded Software Designer
Senior Embedded Software Designer

Lumentum Operations LLC • Ottawa

On-site
CAD 110,000 - 150,000
Flexible time off
Health and wellness benefits
Tuition reimbursement and career growh
End User Services Manager, North America
End User Services Manager, North America

Lumentum Operations LLC • Ottawa

On-site
CAD 90,000 - 130,000
Flexible time off
Health & wellness benefits
Tuition reimbursement
+4
Senior Optical Characterization and Test Engineer
Senior Optical Characterization and Test Engineer

Lumentum Operations LLC • Ottawa

On-site
CAD 75,000 - 124,000
Flexible time off
Health and wellness benefits
Tuition reimbursement
+4
Embedded Software DevSecOps Engineer (Co-op Student)
Embedded Software DevSecOps Engineer (Co-op Student)

Lumentum Operations LLC • Ottawa

On-site
CAD 33,000 - 48,000
Free parking
Free gym
Cafeteria with subsidized meals and 0.
+2
Embedded Software Engineer Co-op/Intern
Embedded Software Engineer Co-op/Intern

Lumentum Operations LLC • Ottawa

On-site
CAD 33,000 - 48,000
Free parking
Free gym
Cafeteria with subsidized meals and免費咖
+2