> Markdown version of [/jobs/ext/1114142-principal-embedded-security-vulnerability-analyst](https://www.wearedevelopers.com/jobs/ext/1114142-principal-embedded-security-vulnerability-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Embedded Security Vulnerability Analyst - **Company:** NXP Semiconductors - **Location:** Gratkorn, Austria - **Contract:** Permanent contract - **Skills:** C (Programming Language), Artificial Intelligence, Static Program Analysis, Cyber Security, Software Debugging, Distributed Systems, Embedded Software, Firmware, Fuzz Testing, Systems Analysis, Joint Test Action (IEEE Standards), Program Analysis, Real-Time Operating Systems, Reverse Engineering, Reduced Instruction Set Computing, Scripting, Large Language Models, Concurrency, Information Technology, Bare Metal, Vulnerability Analysis - **Published:** July 2, 2026 - **Apply:** https://nxp.wd3.myworkdayjobs.com/careers/job/Gratkorn/Principal-Embedded-Security-Vulnerability-Analyst--m-f-d-_R-10064355 ## About the Role * highly experienced embedded engineers with a demonstrated transition into security, * Degree in Electrical Engineering, Computer Science, Mathematics, or related field, or equivalent practical experience * Deep understanding of low-level system behavior (memory layout, interrupts, privilege levels, concurrency) * Extensive experience in C programming; strong familiarity with ARM and/or RISC-V architectures * Strong experience with assembly-level debugging and low-level system analysis Strong differentiators: * Proven track record in vulnerability research, reverse engineering, or exploit development * Deep experience with static and dynamic analysis tools, fuzzing, or symbolic execution * Strong understanding of vulnerability classes (memory corruption, logic flaws, side channels) and exploitation techniques * Experience with debugging interfaces (e.g., JTAG, trace, GDB) in complex systems * Experience evaluating and operationalizing AI-assisted vulnerability discovery tools and workflows * Experience building scalable and automated analysis pipelines (e.g., scripting, distributed systems, agent-based approaches) * Rust experience or strong interest in memory-safe system design Your Profile * Expert-level analytical thinking and strong intuition for how systems fail under adversarial conditions * Ability to lead complex, ambiguous technical investigations end-to-end * Strong interest in combining deep technical expertise with modern AI-assisted methodologies * Ability to influence technical direction across teams and organizational levels * Clear and authoritative communication of technical risks and findings * Mentorship mindset and willingness to develop others ## Description We are seeking a Principal Embedded Security Vulnerability Analyst to lead deep technical analysis of embedded systems, focusing on identifying and understanding vulnerabilities at the hardware/software boundary. You will drive the discovery and analysis of complex vulnerabilities in low-level firmware, boot code, and system components, and influence the security architecture of next-generation products. This role requires expert-level systems thinking, a deep understanding of attack techniques, and the ability to reason about complex execution environments. You will also define and advance modern vulnerability analysis approaches, including the integration of AI-assisted and agentic workflows, to significantly improve the depth, scalability, and effectiveness of security assessments., * Lead in-depth vulnerability analysis of embedded software (bare-metal, RTOS, trusted execution environments) * Drive analysis of boot flows, privilege boundaries, and security-critical components (e.g., crypto libraries, key handling, isolation mechanisms) * Own root cause analysis and assess exploitability and systemic impact of identified weaknesses * Define and guide security evaluation strategies for certifications (e.g., PSA, SESIP, Common Criteria) * Lead analysis of PSIRT incidents and drive structural and architectural improvements * Architect and develop advanced analysis methodologies and tooling (static analysis, fuzzing, automation frameworks) * Define and scale the use of AI-assisted techniques for code analysis and vulnerability discovery (e.g., LLM-based and agentic workflows) * Design and institutionalize workflows that combine traditional analysis (static/dynamic) with AI-assisted approaches * Evaluate and introduce emerging attack techniques and incorporate them into internal methodologies * Influence product teams and architecture decisions by translating findings into systemic mitigations * Mentor and guide other engineers in vulnerability analysis and research methodologies ## Related Videos - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Single Server, Global Reach: Running a Worldwide Marketplace on Bare Metal in a Cloud-Dominated World](https://www.wearedevelopers.com/videos/1206-single-server-global-reach-running-a-worldwide-marketplace-on-bare-metal-in-a-cloud-dominated-world) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [A Hitchhikers Guide to Container Security - Automotive Edition 2024](https://www.wearedevelopers.com/videos/1119-a-hitchhikers-guide-to-container-security-automotive-edition-2024) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)