Technical Manager – Hardware Root of Trust & Platform Security

lumentum· Lumentum Ottawa ULC
Apply Now ↗
📍 Canada - Ottawa (Bill Leathem)Full time💰 CAD 130K–180K

About this role

It's fun to work in a company where people truly BELIEVE in what they're doing!
We're committed to bringing passion and customer focus to the business.


If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!


Lumentum Canada was awarded the 2022 National Capital Region’s Top Employers for the 6th consecutive year and the 2022 Career Directory Canada’s Best Employers for Recent Graduates for the 5th consecutive year.
 

About Lumentum

At Lumentum, we’re building the tech behind the world’s fastest networks and most advanced systems. Our optical and photonic solutions power everything from AI and cloud computing to data centers, telecom, and advanced manufacturing.


We’re a global team of innovators working where light meets technology, solving big challenges that keep the world connected and moving forward. If shaping the future of connectivity excites you, you’ll fit right in.


Why You’ll Love This Role

We are seeking a Technical Manager to lead a team responsible for hardware-based security, trusted device identity, secure provisioning, and network authentication. This role will define and deliver security capabilities based on hardware roots of trust, gNSI, Secure Zero Touch Provisioning, and mutual TLS.


The manager will work across hardware, firmware, operating-system, networking, cloud, manufacturing, and product teams to establish a trusted security lifecycle from device manufacturing through deployment, operation, upgrade, and retirement.


What You’ll Be Doing

  • Lead, mentor, and develop a team responsible for hardware and platform security.
  • Define and implement hardware root-of-trust strategies for embedded and networking products.
  • Oversee the use of TPMs, secure boot, measured boot, hardware-backed keys, device identity, attestation, and trusted execution mechanisms.
  • Lead development and integration of TPM-based DevID and ODevID solutions.
  • Establish device identity lifecycle processes, including enrollment, provisioning, renewal, rotation, revocation, recovery, and retirement.
  • Lead implementation of gNSI security services, including certificate management, authentication, authorization, path authorization, and credential management.
  • Oversee Secure Zero Touch Provisioning, including secure device onboarding, bootstrap trust, ownership validation, policy enforcement, and protection against unauthorized provisioning.
  • Oversee the implementation of the mTLS architectures for gNMI, gNOI, gNSI, management interfaces, and service-to-service communication.
  • Establish certificate authority, PKI, certificate-profile, trust-bundle, and revocation-management requirements.
  • Coordinate security architecture across hardware, bootloader, firmware, Linux, containers, networking services, and cloud infrastructure.
  • Define attestation requirements, including PCR selection, measurement policy, device-state validation, and anti-rollback controls.
  • Lead threat modeling, security design reviews, and technical risk assessments for platform and network-security features.
  • Develop security requirements, architecture documents, interface specifications, test plans, and operational procedures.
  • Coordinate interoperability, integration, penetration, negative, fault-injection, and lifecycle testing.
  • Support customer security reviews, product certifications, audits, and incident investigations.

What We’re Looking For


Education:
Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or a related field.


Experience:

  • Experience leading teams developing platform security, embedded security, network security, or infrastructure security products.
  • Strong understanding of hardware roots of trust, TPM 2.0, secure boot, measured boot, device identity, and remote attestation.
  • Experience designing or deploying PKI, certificates, certificate authorities, trust stores, and mTLS.
  • Experience with identity lifecycle management, key rotation, certificate renewal, revocation, and compromise recovery.
  • Knowledge of gRPC, gNMI, gNOI, gNSI, TLS, authorization, authentication, and policy enforcement.
  • Experience with secure provisioning, ZTP, SZTP, device enrollment, or manufacturing-time device personalization.
  • Familiarity with Linux, embedded systems, networking protocols, and cloud-based security services.
  • Strong technical leadership, communication, documentation, and cross-functional collaboration skills.
  • Ability to convert security architecture into implementable product requirements and verifiable test cases.

Asset/Nice to Have

  • Experience with OpenConfig security services, gNSI, TPM2-Tools, TSS, DevID, IDevID, ODevID, or DICE.
  • Experience with Intel Boot Guard, UEFI Secure Boot, measured boot, PCR policies, UKIs, dm-verity, or anti-rollback mechanisms.
  • Knowledge of SPIFFE/SPIRE, OAuth/OIDC, LDAP, RADIUS, or enterprise identity systems.
  • Experience with Kubernetes, containers, service meshes, cloud PKI, or cloud KMS.
  • Familiarity with OpenSSL, BoringSSL, wolfSSL, PKCS#11, HSMs, and cryptographic-agility requirements.
  • Experience securing SONiC, network operating systems, routers, switches, optical systems, or telecommunications equipment.

Success in This Role

Success means delivering a trusted device identity and provisioning lifecycle, strengthening the hardware root of trust, achieving reliable gNSI and mTLS integration, reducing deployment risk, and enabling secure device operation from manufacturing through field deployment and end of life


Perks You’ll Love

  • Flexible time off
  • Health and wellness benefits (physical and mental)
  • Tuition reimbursement and career growth support
  • A workplace built for you: free gym, games room, prayer room
  • Subsidized meals, free coffee/tea
  • Employee stock options and incentive plans
  • A collaborative, innovative, and inclusive culture

Salary Range
The salary range for this position is $130,000 - $180,000 CAD (Flexible).

Final compensation will be determined based on factors such as experience, skills, and qualifications. In line with our commitment to being a great place to work, Lumentum offers competitive total rewards which may include annual bonus, equity, and comprehensive health and welfare benefits.


Join a Team That’s Shaping the Future

At Lumentum, we’re more than just a workplace—we’re a launchpad for creativity and innovation. We’re committed to celebrating your unique talents and helping you grow. Our guiding principles—Innovate, Engage, Deliver, Excel, and Win—aren’t just words; they’re the heart of what we do.

Let’s Build a Brighter Future Together!


We’re committed to building an inclusive workplace where everyone feels valued and empowered. We welcome applicants from all backgrounds and provide accommodations for individuals with disabilities throughout the hiring process. Your uniqueness makes us stronger, sparks creativity, and drives our success.

Please contact us at talentacquisition@lumentum.com to request accommodation.

Join us—your future starts here!

Frequently Asked Questions

What is the salary for the Technical Manager – Hardware Root of Trust & Platform Security role at lumentum?
The listed salary for this Technical Manager – Hardware Root of Trust & Platform Security position at lumentum is CAD 130K–180K. This is an Full time role.
Where is the Technical Manager – Hardware Root of Trust & Platform Security position at lumentum located?
This Technical Manager – Hardware Root of Trust & Platform Security role at lumentum is based in Canada - Ottawa (Bill Leathem). The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Technical Manager – Hardware Root of Trust & Platform Security role at lumentum full-time or part-time?
This is listed as a Full time position. It is posted as a Technical Manager – Hardware Root of Trust & Platform Security role in the Lumentum Ottawa ULC department at lumentum.
Which team or department does the Technical Manager – Hardware Root of Trust & Platform Security at lumentum belong to?
This Technical Manager – Hardware Root of Trust & Platform Security position is part of the Lumentum Ottawa ULC department at lumentum. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Technical Manager – Hardware Root of Trust & Platform Security position at lumentum?
Click the "Apply Now" button on this page. You will be redirected to lumentum's official application portal hosted on workday where you can submit your application directly.
When was the Technical Manager – Hardware Root of Trust & Platform Security job at lumentum posted?
This Technical Manager – Hardware Root of Trust & Platform Security position at lumentum was posted on Sep 30, 2026. Apply as soon as possible — early applications are often reviewed first.
Technical Manager – Hardware Root of Trust & Platform Security
lumentum · 💰 CAD 130K–180K
Apply for this role ↗

You'll be redirected to lumentum's official application page on Workday.