Lumentum Logo

Lumentum

Technical Manager – Product Security, Vulnerability Management & Software Assurance

Posted Yesterday
Be an Early Applicant
In-Office
Ottawa, ON, CAN
Entry level
In-Office
Ottawa, ON, CAN
Entry level
Leads a team responsible for product security, vulnerability management, software assurance, secure manufacturing, and cloud security applications. Establishes vulnerability remediation processes, manages SCA tools, oversees SBOM and VEX reporting, secures software signing and release operations, and develops secure customer-facing cloud platforms and APIs for exchanging trusted device and product-security information.
The summary above was generated by AI

It's fun to work in a company where people truly BELIEVE in what they're doing!
We're committed to bringing passion and customer focus to the business.

If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!

Lumentum Canada was awarded the 2022 National Capital Region’s Top Employers for the 6th consecutive year and the 2022 Career Directory Canada’s Best Employers for Recent Graduates for the 5th consecutive year.
 

About Lumentum

At Lumentum, we’re building the tech behind the world’s fastest networks and most advanced systems. Our optical and photonic solutions power everything from AI and cloud computing to data centers, telecom, and advanced manufacturing.


We’re a global team of innovators working where light meets technology, solving big challenges that keep the world connected and moving forward. If shaping the future of connectivity excites you, you’ll fit right in.


Why You’ll Love This Role

We are seeking a Technical Manager to lead a team responsible for product vulnerability management, software assurance, secure manufacturing processes, and cloud-based security applications. This role will oversee the identification, assessment, remediation, and reporting of software vulnerabilities across embedded and network products.


The manager will also lead the development of a secure cloud application and supporting APIs for exchanging device information with customers. This may include certificates, device identity, software versions, security status, SBOMs, vulnerability data, VEX reports, attestation results, and lifecycle information.


The role will work closely with software engineering, product security, cloud engineering, manufacturing, and customer-facing teams.


What You’ll Be Doing

  • Lead, mentor, and develop a team responsible for software security, vulnerability management, and cloud security applications.
  • Establish processes for identifying, analyzing, prioritizing, remediating, and tracking software vulnerabilities.
  • Manage Black Duck and related Software Composition Analysis tools, including project configuration, scanning, policy review, reporting, and issue resolution.
  • Oversee the creation, validation, and distribution of SBOM and VEX reports.
  • Define vulnerability triage criteria using severity, exploitability, product exposure, reachability, and customer impact.
  • Lead the use of AI-assisted code scanning and security analysis while ensuring findings are validated by qualified engineers.
  • Develop secure software-signing processes, including key management, signing workflows, access control, auditability, and protection against unauthorized signing.
  • Secure and review software manufacturing procedures, including build integrity, artifact provenance, release controls, and production access.
  • Manage the development of a secure cloud application for exchanging device and product-security information with customers.
  • Establish mechanisms for securely ingesting and sharing device information, including device identity, software versions, SBOMs, vulnerabilities, VEX status, attestation results, and security events.
  • Coordinate vulnerability remediation with development and release teams.
  • Promote secure software development practices, threat modeling, code review, and security testing.

What We’re Looking For


Education:
Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or a related field.


Experience:

  • Experience leading software security, product security, vulnerability management, application security, or cloud security teams.
  • Strong understanding of vulnerability management, CVE analysis, CVSS, CWE, SBOM, VEX, and software supply-chain security.
  • Experience with Black Duck, SCA tools, code scanning, or comparable security platforms.
  • Experience defining and operating software-signing and release-security processes.
  • Experience leading the development of cloud applications, secure APIs, or customer-facing security platforms.
  • Knowledge of cloud security principles, identity and access management, encryption, API security, audit logging, and secure data exchange.
  • Experience working with embedded Linux, networking software, or complex hardware/software products.
  • Strong communication, project management, and cross-functional leadership skills.
  • Ability to translate complex security findings into clear engineering and business decisions.

Asset/Nice to Have

  • Experience with GCP, Cloud Run, API gateways, cloud databases, cloud KMS, or cloud-based certificate authorities.
  • Experience with REST, gRPC, OAuth 2.0, OIDC, mTLS, PKI, and multi-tenant application design.
  • Experience with SONiC, Linux, containers, firmware, networking, or telecommunications products.
  • Familiarity with SPDX, CycloneDX, CSAF, VEX, SLSA, and SBOM conformance.
  • Experience with CodeQL, Coverity, Blackduck, or similar tools.
  • Knowledge of cryptographic key management, HSMs, cloud KMS, PKI, and trusted build environments.
  • Experience securing manufacturing, provisioning, or product-release operations.

Success in This Role

Success means establishing a predictable vulnerability-remediation process, improving the quality and timeliness of SBOM and VEX reports, protecting software-signing operations, reducing software supply-chain risk, and delivering a secure cloud platform that enables customers to exchange and review trusted device and product-security information.


Perks You’ll Love

  • Flexible time off
  • Health and wellness benefits (physical and mental)
  • Tuition reimbursement and career growth support
  • A workplace built for you: free gym, games room, prayer room
  • Subsidized meals, free coffee/tea
  • Employee stock options and incentive plans
  • A collaborative, innovative, and inclusive culture

Salary Range
The salary range for this position is $130,000 - $180,000 CAD (Flexible).

Final compensation will be determined based on factors such as experience, skills, and qualifications. In line with our commitment to being a great place to work, Lumentum offers competitive total rewards which may include annual bonus, equity, and comprehensive health and welfare benefits.


Join a Team That’s Shaping the Future

At Lumentum, we’re more than just a workplace—we’re a launchpad for creativity and innovation. We’re committed to celebrating your unique talents and helping you grow. Our guiding principles—Innovate, Engage, Deliver, Excel, and Win—aren’t just words; they’re the heart of what we do.

Let’s Build a Brighter Future Together!


We’re committed to building an inclusive workplace where everyone feels valued and empowered. We welcome applicants from all backgrounds and provide accommodations for individuals with disabilities throughout the hiring process. Your uniqueness makes us stronger, sparks creativity, and drives our success.

Please contact us at [email protected] to request accommodation.

Join us—your future starts here!

Lumentum Ottawa, Ontario, CAN Office

61 Bill Leathem Drive, Ottawa, Ontario, Canada, K2J 0P7

Similar Jobs

Senior level
Fintech • Financial Services
Leads international compliance and operational risk governance across legal entities and business lines. Owns regulatory change, risk assessments, reporting, monitoring, governance, and control oversight. Produces executive and board reporting, provides independent challenge, manages remediation and corrective actions, and advises senior stakeholders across multiple jurisdictions. Partners with Audit, Legal, regulators, and enterprise teams to identify, escalate, and mitigate compliance and operational risks.
Top Skills: AI
7 Hours Ago
Hybrid
Senior level
Senior level
Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Provide cryptography consulting for financial services clients by developing governance frameworks, policies, standards, and technical requirements. Assess enterprise cryptographic and data security gaps, support encryption across on-premises and cloud environments, and guide PKI, certificates, TLS, key lifecycle management, and database encryption. Develop remediation plans, address audit findings, monitor compliance, and communicate practical recommendations to technical teams, asset owners, and stakeholders. The role also covers post-quantum cryptography and cryptographic agility.
Top Skills: CryptographyEncryptionIbm Db2Microsoft AdcsMicrosoft Sql ServerMongoDBOracle DatabasePkiPublic CloudSshTlsTls Cipher SuitesTransparent Data Encryption (Tde)VenafiX.509
Internship
Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
Graduate research co-op focused on building Customer World Models and proactive intelligence: designing representation learning, foundation-model, reinforcement learning, and agentic systems; running experiments, publishing, and deploying research into production to improve long-horizon decision-making and customer-facing automation.
Top Skills: JaxPythonPyTorch

What you need to know about the Ottawa Tech Scene

The capital city of Canada and the nation's fourth-largest urban area, Ottawa has proven a rapidly growing global tech hub. With over 1,800 tech companies, many of which are leaders in their sectors, the city's tech talent now makes up more than 13 percent of its total workforce. This growth is driven not only by the big players like UL Solutions and Dropbox, but also by a thriving startup ecosystem, as new businesses emerge to follow in the footsteps of those that came before them.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account