About this role
Req ID: 141218
Region: Americas
Country: Canada
State/Province: Ontario
City: Toronto
Summary
We are seeking an experienced Product Security Lead to join the IT Support and Enablement function supporting the Hardware Platform Solutions (HPS) organization. In this role, you will take ownership of the code signing operating model used by HPS Software Engineering teams and drive its deployment, support, governance, and scale-up across product programs and design centers.
Serving as the key security and technical liaison across Information Security, DevOps, Software Engineering, infrastructure teams, and external vendors, you will ensure that our signing infrastructure, certificates, signing packages, key management practices, and supporting processes are secure, supportable, and production-ready. You will also help engineering teams standardize approved signing methods across Linux and Windows environments while addressing operational constraints, access controls, and customer-driven product security requirements.
Detailed Description
Core Responsibilities
1. Code Signing Architecture & Governance
● Own Lifecycle Strategy: Design, roll out, and govern the HPS code signing capability, supporting a secure software chain of custody from initial build through final production release.
● Standardize Workflows: Establish and maintain approved signing standards and integration patterns across both Linux and Windows development environments.
● Develop Operational Frameworks: Formulate standard operating procedures (SOPs), governance controls, and self-service onboarding guidance for engineering teams consuming signing services across multiple product programs and global design locations.
2. Certificate and Key Management Infrastructure
● Coordinate Asset Provisioning: Manage the lifecycle, provisioning, and distribution of signing certificates, cryptographic keys, signing policies, and signing packages.
● Platform Ownership: Partner with Enterprise Information Security and external vendors to deploy, configure, and maintain AppViewX PKI+ and associated hardware security module (HSM) backed signing services.
● Traceability & Auditing: Guarantee absolute integrity, control, and traceability of signing assets and workflows to ensure HPS software releases align with corporate policy and stringent customer security requirements.
3. Security Operations, Risk, & Tool Integration
● Mitigate Operational Risks: Identify, assess, and resolve security risks associated with signing deployments, including privilege management, secure package distribution, and cryptographic verification gaps.
● Triage Tooling Gaps: Track and address limitations in unsupported or non-standard engineering tools (such as sbsign, intel-pfr-signing-utility, socsec, Windows .bin signing, and Windows OpenSSL support), defining compliant alternative paths.
● Secure Access Control: Collaborate with security architects to define support models that eliminate unnecessary elevated administrative access and align with enterprise zero-trust principles.
4. Engineering Enablement & Cross-Functional Collaboration
● Technical Liaison: Serve as the primary technical enablement lead for Software Engineering and DevOps teams, troubleshooting package integration failures, API consumption issues, and HSM-related workflow blocks.
● Drive Service Maturity: Lead proof-of-concept (POC) evaluations, transition frameworks, and operational readiness reviews to seamlessly transition capabilities from pilot status to scalable, production-grade enterprise services.
5. Future-State Security Capability & Identity Roadmaps
● Define Device Identity Roadmap: Participate in defining the long-term architecture for secure product identities, hardware attestation, and localized certificate authority (CA) infrastructures.
● Translate Stakeholder Requirements: Partner with product management and engineering leadership to translate evolving customer security needs into scalable security capabilities.
Knowledge/Skills/Competencies
Required Technical Skills
● PKI & Key Management: Deep conceptual and practical understanding of Public Key Infrastructure (PKI), certificate lifecycle management, cryptographic hashing, key escrow, and secure release governance.
● Signing Toolchains: Hands-on experience implementing and troubleshooting developer signing workflows, specifically using OpenSSL (Linux/Windows) and Microsoft Signtool.
● HSM & KMS Platforms: Direct experience with HSM-integrated signing systems, PKCS#11 API integrations, and vendor-managed signing controllers (such as AppViewX PKI+).
● Systems & Automation Environment: Working knowledge of modern CI/CD pipelines (e.g., Azure DevOps, Jenkins, GitLab), automated test environments, and package validation processes.
● Technical Documentation: Strong ability to write high-quality, clear operational playbooks, developer guides, and compliance standards.
Strongly Preferred Qualifications
● Background supporting security controls for embedded systems, firmware development (e.g., AMI BIOS/BMC toolchains), or hardware component signing.
● Familiarity with secure boot architectures and device identity frameworks (such as iDevID, IEEE 802.1AR attestation, and dedicated/subordinate CA hierarchies).
● Industry-recognized security credentials, such as CISSP, CSSLP, or vendor-specific PKI/HSM engineering certifications.
Soft Skills and Working Style
● Collaborative Communicator: Ability to build strong consensus and drive security standards across highly diverse engineering, IT, operations, and external vendor teams.
● User-Centric Pragmatism: A track record of balancing rigorous security compliance with developer usability, designing solutions that minimize friction and preserve engineering velocity.
● Sovereign Problem Solver: Comfortable navigating strict architectural constraints where automated standard enterprise agents are blocked or restricted.
Physical Demands
- Duties of this position are performed in a normal office environment.
- Duties may require extended periods of sitting and sustained visual concentration on a computer monitor or on numbers and other detailed data. Repetitive manual movements (e.g., data entry, using a computer mouse, using a calculator, etc.) are frequently required.
Typical Experience
- Minimum of 7+ years of experience in product security, application security, PKI, code signing infrastructure, platform security, or DevSecOps within active engineering or R&D environments.
- Demonstrated experience operating in complex matrix environments, effectively bridging the technical gaps between enterprise IT security policies and agile software developer workflows.
Typical Education
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Software Engineering, or a related technical field.
Notes
This job description is not intended to be an exhaustive list of all duties and responsibilities of the position. Employees are held accountable for all duties of the job. Job duties and the % of time identified for any function are subject to change at any time.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Celestica's policy on equal employment opportunity prohibits discrimination based on race, color, creed, religion, national origin, gender, sexual orientation, gender identity, age, marital status, veteran or disability status, or other characteristics protected by law.
This policy applies to hiring, promotion, discharge, pay, fringe benefits, job training, classification, referral and other aspects of employment and also states that retaliation against a person who files a charge of discrimination, participates in a discrimination proceeding, or otherwise opposes an unlawful employment practice will not be tolerated. All information will be kept confidential according to EEO guidelines.
COMPANY OVERVIEW:
Celestica (NYSE, TSX: CLS) enables the world's best brands. Through our recognized customer-centric approach, we partner with leading companies in Aerospace and Defense, Communications, Enterprise, HealthTech, Industrial, Capital Equipment and Energy to deliver solutions for their most complex challenges. As a leader in design, manufacturing, hardware platform and supply chain solutions, Celestica brings global expertise and insight at every stage of product development – from drawing board to full-scale production and after-market services for products from advanced medical devices, to highly engineered aviation systems, to next-generation hardware platform solutions for the Cloud. Headquartered in Toronto, with talented teams spanning 40+ locations in 13 countries across the Americas, Europe and Asia, we imagine, develop and deliver a better future with our customers.
Celestica would like to thank all applicants, however, only qualified applicants will be contacted.
Celestica does not accept unsolicited resumes from recruitment agencies or fee based recruitment services.
This location is a US ITAR facility and these positions will involve the release of export controlled goods either directly to employees or through the employee's movement within the facility. As such, Celestica will require necessary information from all applicants upon an applicant's acceptance of employment to determine if any export control exemptions or licenses must be filed.