Назад
Company hidden
23 часа назад

Technical Manager – Product Security, Vulnerability Management & Software Assurance

130 000 - 180 000CAD
Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Technical Manager – Product Security, Vulnerability Management & Software Assurance (Cybersecurity): Leading vulnerability management, software assurance, secure manufacturing processes, and a cloud platform for exchanging trusted device and product-security information with an accent on SBOMs, VEX reports, software signing, and supply-chain security. Focus on establishing remediation workflows, securing release and manufacturing operations, validating AI-assisted security findings, and delivering secure APIs for customer-facing data exchange.

Location: Ottawa, Canada

Salary: CAD 130,000–180,000 per year

Company

hirify.global develops optical and photonic solutions for high-speed networks, AI and cloud computing, data centers, telecommunications, and advanced manufacturing.

What you will do

  • Lead, mentor, and develop a team focused on product security, vulnerability management, software assurance, and cloud security applications.
  • Establish processes for vulnerability identification, triage, prioritization, remediation, tracking, and reporting across embedded and network products.
  • Manage Black Duck and other Software Composition Analysis tools, including scanning, policy review, reporting, and issue resolution.
  • Oversee the creation, validation, and distribution of SBOM and VEX reports and coordinate remediation with development and release teams.
  • Secure software-signing and manufacturing processes, including key management, build integrity, artifact provenance, release controls, and production access.
  • Lead development of a secure cloud application and APIs for exchanging device identity, software, vulnerability, attestation, and lifecycle information with customers.

Requirements

  • Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or a related field.
  • Experience leading software security, product security, vulnerability management, application security, or cloud security teams.
  • Strong knowledge of vulnerability management, CVE analysis, CVSS, CWE, SBOM, VEX, and software supply-chain security.
  • Experience with Black Duck, SCA tools, code scanning, software-signing processes, release security, or comparable security platforms.
  • Experience leading cloud applications, secure APIs, or customer-facing security platforms, with knowledge of identity and access management, encryption, API security, audit logging, and secure data exchange.
  • Experience with embedded Linux, networking software, or complex hardware/software products, plus strong communication and cross-functional leadership skills.

Nice to have

  • Experience with GCP, Cloud Run, API gateways, cloud databases, cloud KMS, or cloud-based certificate authorities.
  • Knowledge of REST, gRPC, OAuth 2.0, OIDC, mTLS, PKI, multi-tenant applications, and cryptographic key management.
  • Experience with SONiC, Linux, containers, firmware, networking, telecommunications products, or secure manufacturing and provisioning operations.
  • Familiarity with SPDX, CycloneDX, CSAF, VEX, SLSA, SBOM conformance, CodeQL, or Coverity.

Culture & Benefits

  • Flexible time off and health and wellness benefits.
  • Tuition reimbursement and career growth support.
  • On-site amenities including a gym, games room, prayer room, subsidized meals, and free coffee and tea.
  • Employee stock options, incentive plans, and a collaborative, innovative, and inclusive workplace.

Hiring process

  • Accommodation is available throughout the hiring process for candidates with disabilities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →