Lumentum Operations LLC

Technical Manager – Product Security, Vulnerability Management & Software Assurance

Lumentum Operations LLC • $130K — $180K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree in computer science, Computer Engineering, Software Engineering, Electrical Engineering, or related field
  • 5+ years embedded software experience focused on security
  • Expert in Python/Go; familiarity with C/C++
  • Hands-on experience with secure BIOS/bootloaders and cryptography (ECC/RSA, AES, SHA-2/3)
  • Experience with x86 platform security and BIOS/UEFI
  • Knowledge of secure supply chain practices and device identity at scale
  • Practical experience with TLS/mTLS and certificate lifecycle management

Responsibilities

  • Design and implement secure boot architectures
  • Implement SSD/data-at-rest encryption
  • Design and integrate gNSI security services and commands
  • Harden TLS stacks for control and management
  • Integrate hardware security primitives
  • Collaborate with hardware and manufacturing teams
  • Drive security validation and support security reviews

Benefits

  • Flexible time off
  • Health and wellness benefits
  • Tuition reimbursement and career growth support
  • Free gym and games room
  • Subsidized meals and free coffee/tea
  • Employee stock options and incentive plans
  • Collaborative, innovative, and inclusive culture
Full Job Description

We are seeking a Technical Manager to lead a team responsible for product vulnerability management, software assurance, secure manufacturing processes, and cloud-based security applications. This role will oversee the identification, assessment, remediation, and reporting of software vulnerabilities across embedded and network products.


The manager will also lead the development of a secure cloud application and supporting APIs for exchanging device information with customers. This may include certificates, device identity, software versions, security status, SBOMs, vulnerability data, VEX reports, attestation results, and lifecycle information.


The role will work closely with software engineering, product security, cloud engineering, manufacturing, and customer-facing teams.


What You’ll Be Doing

  • Lead, mentor, and develop a team responsible for software security, vulnerability management, and cloud security applications.
  • Establish processes for identifying, analyzing, prioritizing, remediating, and tracking software vulnerabilities.
  • Manage Black Duck and related Software Composition Analysis tools, including project configuration, scanning, policy review, reporting, and issue resolution.
  • Oversee the creation, validation, and distribution of SBOM and VEX reports.
  • Define vulnerability triage criteria using severity, exploitability, product exposure, reachability, and customer impact.
  • Lead the use of AI-assisted code scanning and security analysis while ensuring findings are validated by qualified engineers.
  • Develop secure software-signing processes, including key management, signing workflows, access control, auditability, and protection against unauthorized signing.
  • Secure and review software manufacturing procedures, including build integrity, artifact provenance, release controls, and production access.
  • Manage the development of a secure cloud application for exchanging device and product-security information with customers.
  • Establish mechanisms for securely ingesting and sharing device information, including device identity, software versions, SBOMs, vulnerabilities, VEX status, attestation results, and security events.
  • Coordinate vulnerability remediation with development and release teams.
  • Promote secure software development practices, threat modeling, code review, and security testing.

What We’re Looking For


Education:
Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or a related field.


Experience:

  • Experience leading software security, product security, vulnerability management, application security, or cloud security teams.
  • Strong understanding of vulnerability management, CVE analysis, CVSS, CWE, SBOM, VEX, and software supply-chain security.
  • Experience with Black Duck, SCA tools, code scanning, or comparable security platforms.
  • Experience defining and operating software-signing and release-security processes.
  • Experience leading the development of cloud applications, secure APIs, or customer-facing security platforms.
  • Knowledge of cloud security principles, identity and access management, encryption, API security, audit logging, and secure data exchange.
  • Experience working with embedded Linux, networking software, or complex hardware/software products.
  • Strong communication, project management, and cross-functional leadership skills.
  • Ability to translate complex security findings into clear engineering and business decisions.

Asset/Nice to Have

  • Experience with GCP, Cloud Run, API gateways, cloud databases, cloud KMS, or cloud-based certificate authorities.
  • Experience with REST, gRPC, OAuth 2.0, OIDC, mTLS, PKI, and multi-tenant application design.
  • Experience with SONiC, Linux, containers, firmware, networking, or telecommunications products.
  • Familiarity with SPDX, CycloneDX, CSAF, VEX, SLSA, and SBOM conformance.
  • Experience with CodeQL, Coverity, Blackduck, or similar tools.
  • Knowledge of cryptographic key management, HSMs, cloud KMS, PKI, and trusted build environments.
  • Experience securing manufacturing, provisioning, or product-release operations.

Success in This Role

Success means establishing a predictable vulnerability-remediation process, improving the quality and timeliness of SBOM and VEX reports, protecting software-signing operations, reducing software supply-chain risk, and delivering a secure cloud platform that enables customers to exchange and review trusted device and product-security information.


Perks You’ll Love

  • Flexible time off
  • Health and wellness benefits (physical and mental)
  • Tuition reimbursement and career growth support
  • A workplace built for you: free gym, games room, prayer room
  • Subsidized meals, free coffee/tea
  • Employee stock options and incentive plans
  • A collaborative, innovative, and inclusive culture

Salary Range
The salary range for this position is $130,000 - $180,000 CAD (Flexible).

Final compensation will be determined based on factors such as experience, skills, and qualifications. In line with our commitment to being a great place to work, Lumentum offers competitive total rewards which may include annual bonus, equity, and comprehensive health and welfare benefits.

About Lumentum Operations LLC

Lumentum is a leading provider of photonics products for optical networking and commercial laser customers worldwide. The company designs and manufactures innovative optical and photonic products enabling optical networking and commercial laser customers worldwide. Lumentum's optical components and subsystems are part of virtually every type of telecom, enterprise, and data center network. The company's commercial lasers enable advanced manufacturing techniques and diverse applications including next-generation 3D sensing capabilities. Lumentum is headquartered in Milpitas, California, and has R&D, manufacturing, and sales offices worldwide. The company was founded in 2015 as a spinoff from JDS Uniphase Corporation.
Learn more about Lumentum Operations LLC
Size
5,618 employees
Market Cap
$3.4 billion
Industry
Net Income
$189.1 million
Founded
2015
5 Year Trend
+11.3%
Revenue
$1.7 billion
NASDAQ

Similar Jobs

More Jobs at Lumentum Operations LLC

More Information Technology Jobs

Find similar Technical Manager – Product Security, Vulnerability Management & Software Assurance jobs: