Technical Manager – Product Security, Vulnerability Management & Software Assurance at Lumentum Operations LLC in Ottawa, Ottawa region. Skills: AI-Assisted Development, API Development, Black Duck, Cloud Security, Leadership. Apply on NeverHard.
Company
Lumentum Operations LLC
Location
Ottawa, Ottawa region
Type
not_specified
Required skills:
AI-Assisted Development
API Development
Black Duck
Cloud Security
Leadership
Mentoring
Program Assurance
SBOM
Software analysis
Technical Management
**Why You’ll Love This Role**We are seeking a Technical Manager to lead a team responsible for product vulnerability management, software assurance, secure manufacturing processes, and cloud-based security applications. This role will oversee the identification, assessment, remediation, and reporting of software vulnerabilities across embedded and network products. The manager will also lead the development of a secure cloud application and supporting APIs for exchanging device information with customers. This may include certificates, device identity, software versions, security status, SBOMs, vulnerability data, VEX reports, attestation results, and lifecycle information. The role will work closely with software engineering, product security, cloud engineering, manufacturing, and customer-facing teams. **What You’ll Be Doing*** Lead, mentor, and develop a team responsible for software security, vulnerability management, and cloud security applications.* Establish processes for identifying, analyzing, prioritizing, remediating, and tracking software vulnerabilities.* Manage Black Duck and related Software Composition Analysis tools, including project configuration, scanning, policy review, reporting, and issue resolution.* Oversee the creation, validation, and distribution of SBOM and VEX reports.* Define vulnerability triage criteria using severity, exploitability, product exposure, reachability, and customer impact.* Lead the use of AI-assisted code scanning and security analysis while ensuring findings are validated by qualified engineers.* Develop secure software-signing processes, including key management, signing workflows, access control, auditability, and protection against unauthorized signing.* Secure and review software manufacturing procedures, including build integrity, artifact provenance, release controls, and production access.* Manage the development of a secure cloud application for exchanging device and product-security information with customers.* Establish mechanisms for securely ingesting and sharing device information, including device identity, software versions, SBOMs, vulnerabilities, VEX status, attestation results, and security events.* Coordinate vulnerability remediation with development and release teams.* Promote secure software development practices, threat modeling, code review, and security testing.**What We’re Looking For** **Education:** Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or a related field. **Experience:*** Experience leading software security, product security, vulnerability management, application security, or cloud security teams.* Strong understanding of vulnerability management, CVE analysis, CVSS, CWE, SBOM, VEX, and software supply-chain security.* Experience with Black Duck, SCA tools, code scanning, or comparable security platforms.* Experience defining and operating software-signing and release-security processes.* Experience leading the development of cloud applications, secure APIs, or customer-facing security platforms.* Knowledge of cloud security principles, identity and access management, encryption, API security, audit logging, and secure data exchange.* Experience working with embedded Linux, networking software, or complex hardware/software products.* Strong communication, project management, and cross-functional leadership skills.* Ability to translate complex security findings into clear engineering and business decisions. **Asset/Nice to Have*** Experience with GCP, Cloud Run, API gateways, cloud databases, cloud KMS, or cloud-based certificate authorities.* Experience with REST, gRPC, OAuth 2.0, OIDC, mTLS, PKI, and multi-tenant application design.* Experience with SONiC, Linux, containers, firmware, networking, or telecommunications products.* Familiarity with SPDX, CycloneDX, CSAF, VEX, SLSA, and SBOM conformance.* Experience with CodeQL, Coverity, Blackduck, or similar tools.* Knowledge of cryptographic key management, HSMs, cloud KMS, PKI, and trusted build environments.* Experience securing manufacturing, provisioning, or product-release operations. **Success in This Role**Success means establishing a predictable vulnerability-remediation process, improving the quality and timeliness of SBOM and VEX reports, protecting software-signing operations, reducing software supply-chain risk, and delivering a secure cloud platform that enables customers to exchange and review trusted device and product-security information. **Perks You’ll Love*** Flexible time off* Health and wellness benefits (physical and mental)* Tuition reimbursement and career growth support* A workplace built for you: free gym, games room, prayer room* Subsidized meals, free coffee/tea* Employee stock options and incentive plans* A collaborative, innovative, and inclusive culture **Salary Range** The salary range for this position is $130,000 - $180,000 CAD (Flexible).Final compensation will be determined based on factors such as experience, skills, and qualifications. In line with our commitment to being a great place to work, Lumentum offers competitive total rewards which may include annual bonus, equity, and comprehensive health and welfare benefits.
#J-18808-Ljbffr