Product Security Vulnerability Response Manager - Embedded & Semiconductor Security

Nxp Semiconductors Netherlands B.v.
Belgium
1 day ago
Apply on www.nieuwejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Cyber Security Hardware Security Module Software Vulnerability Management Software Security Information Technology

Job description

This role is about ensuring the resilience NXP products (Secure Chips rather then IT Systems) who are are embedded in millions of automotive, industrial, IoT, mobile, and edge devices.

In this role, you will help protect products already deployed in the field, leading the response to security vulnerabilities, coordinating mitigation strategies, and strengthening customer trust throughout the post-production product lifecycle.

Working at the intersection of Product Security, Engineering, R&D, Customers, and External Security Researchers, you will drive the end-to-end lifecycle of vulnerability management, from initial disclosure through risk assessment, mitigation, and customer communication.

As a key member of NXP’s Product Security Incident Response Team (PSIRT), you will lead the end-to-end response to security issues affecting NXP products already deployed worldwide. Partnering with engineering teams, customers, and security researchers, you will assess risk, coordinate remediation efforts, manage responsible disclosure, and help safeguard customer trust throughout the product lifecycle.

Our PSIRT is committed to rapidly addressing security threats in NXP products by investigating reported issues, evaluating their potential impact, and providing customers with timely and actionable guidance.

See also www.nxp.com/psirt.

A snapshot of your key responsibilities and impact.

  • Lead the response and coordination of security vulnerabilities affecting NXP products, hardware and software.
  • Drive vulnerability triage, impact assessment, severity classification, and prioritization.
  • Collaborate with engineering and product teams to develop mitigation strategies and remediation plans.
  • Coordinate responsible disclosure activities with external researchers, customers, and industry partners.
  • Oversee security advisories, CVE processes, and customer communications.
  • Act as a trusted advisor to product teams on vulnerability management and product security best practices.
  • Continuously improve PSIRT processes, metrics, and operational excellence.

Requirements

Ideally, you bring hands-on experience in product, embedded, or hardware security and possess a solid understanding of how attackers target semiconductor devices and embedded systems. You are familiar with common attack techniques and can help assess their potential impact on NXP products.

  • Experience in Product Security, Embedded Security, Semiconductor Security, Cybersecurity, or Secure Product Development.
  • Strong understanding of vulnerability management, coordinated disclosure, incident handling, or product risk management.
  • Ability to influence cross-functional stakeholders across engineering, product management, quality, and customer-facing teams.
  • Excellent communication skills and a passion for protecting innovative technology at scale.

Understand Threats. Protect Products. Protect Customers. Lead Response. Reduce Risk. Build Trust. Drive Security. Create Impact. Shape Tomorrow.

Benefits & conditions

NXP provides market competitive compensation according to the benchmarking of the electronic and semiconductor industry. Due to the Austrian Equal Treatment Act we are obligated to state the employment group of our applicable collective bargaining agreement (CBA) “Kollektivvertrag für Angestellte Gewerbe und Handwerk und in der Dienstleistung”, this position (fulltime) is graded in Employment Group V. Your individual experiences and expectations will be considered in the application process. Moreover, we provide attractive benefits to our employees like home office, flexible working time, meal benefits and more.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.nieuwejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 ¡ World Congress 2025

2:12 min

Preparing engineering organizations for rapid vulnerability response and remediation

Milin Desai Milin Desai +3 ¡ World Congress 2026 Europe

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon ¡ LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman ¡ World Congress 2022

1:57 min

Following security research and continuous developer education

Martin Schmiedecker ¡ LIVE

2:46 min

Missing equipment retrieval processes for departing employees

Jasmin Azemović Jasmin Azemović · World Congress 2026 Europe

Videos

See all

Related articles

See all