Назад
Company hidden
5 дней назад

Technical Manager – Hardware Root of Trust & Platform Security

130 000 - 180 000CAD
Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Technical Manager – Hardware Root of Trust & Platform Security (Hardware Security/Platform Security): Leading hardware and platform security for embedded and networking products, including trusted device identity, secure provisioning, gNSI services, and mutual TLS, with an accent on hardware roots of trust, TPM-based identity, PKI, and lifecycle security. Focus on coordinating security architecture across hardware, firmware, Linux, networking, cloud, and manufacturing while designing attestation, certificate, provisioning, and testing requirements.

Location: Ottawa, Canada

Salary: CAD 130,000–180,000 per year

Company

hirify.global develops optical and photonic solutions for high-speed networks, cloud computing, data centers, telecommunications, artificial intelligence, and advanced manufacturing.

What you will do

  • Lead, mentor, and develop a team responsible for hardware and platform security.
  • Define hardware root-of-trust strategies for embedded and networking products, including TPMs, secure boot, measured boot, hardware-backed keys, attestation, and trusted execution.
  • Lead TPM-based device identity, DevID, ODevID, certificate, PKI, and mutual TLS architectures.
  • Establish secure device identity and provisioning lifecycles covering enrollment, renewal, rotation, revocation, recovery, deployment, upgrades, and retirement.
  • Coordinate security architecture across hardware, bootloaders, firmware, Linux, containers, networking services, cloud infrastructure, manufacturing, and product teams.
  • Lead threat modeling, security reviews, risk assessments, interoperability testing, penetration testing, certifications, audits, and incident investigations.

Requirements

  • Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or a related field.
  • Experience leading teams developing platform, embedded, network, or infrastructure security products.
  • Strong knowledge of hardware roots of trust, TPM 2.0, secure boot, measured boot, device identity, and remote attestation.
  • Experience designing or deploying PKI, certificate authorities, trust stores, mutual TLS, identity lifecycle management, key rotation, renewal, revocation, and compromise recovery.
  • Knowledge of gRPC, gNMI, gNOI, gNSI, TLS, authentication, authorization, policy enforcement, secure provisioning, ZTP, or SZTP.
  • Familiarity with Linux, embedded systems, networking protocols, cloud security services, technical documentation, and cross-functional leadership.

Nice to have

  • Experience with OpenConfig security services, TPM2-Tools, TSS, DevID, IDevID, ODevID, or DICE.
  • Knowledge of Intel Boot Guard, UEFI Secure Boot, PCR policies, UKIs, dm-verity, or anti-rollback mechanisms.
  • Experience with SPIFFE/SPIRE, OAuth/OIDC, LDAP, RADIUS, Kubernetes, containers, service meshes, cloud PKI, or cloud KMS.
  • Familiarity with OpenSSL, BoringSSL, wolfSSL, PKCS#11, HSMs, and cryptographic agility.
  • Experience securing SONiC, network operating systems, routers, switches, optical systems, or telecommunications equipment.

Culture & Benefits

  • Flexible time off and health and wellness benefits.
  • Tuition reimbursement and career growth support.
  • Free gym, games room, prayer room, subsidized meals, and free coffee and tea.
  • Employee stock options, incentive plans, and comprehensive total rewards.
  • Collaborative, innovative, and inclusive workplace.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →