Product Security Vulnerability Response Manager - Embedded & Semiconductor Security
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
This role is about ensuring the resilience NXP products (Secure Chips rather then IT Systems) who are are embedded in millions of automotive, industrial, IoT, mobile, and edge devices.
In this role, you will help protect products already deployed in the field, leading the response to security vulnerabilities, coordinating mitigation strategies, and strengthening customer trust throughout the post-production product lifecycle.
Working at the intersection of Product Security, Engineering, R&D, Customers, and External Security Researchers, you will drive the end-to-end lifecycle of vulnerability management, from initial disclosure through risk assessment, mitigation, and customer communication.
As a key member of NXPâs Product Security Incident Response Team (PSIRT), you will lead the end-to-end response to security issues affecting NXP products already deployed worldwide. Partnering with engineering teams, customers, and security researchers, you will assess risk, coordinate remediation efforts, manage responsible disclosure, and help safeguard customer trust throughout the product lifecycle.
Our PSIRT is committed to rapidly addressing security threats in NXP products by investigating reported issues, evaluating their potential impact, and providing customers with timely and actionable guidance.
See also www.nxp.com/psirt.
A snapshot of your key responsibilities and impact.
- Lead the response and coordination of security vulnerabilities affecting NXP products, hardware and software.
- Drive vulnerability triage, impact assessment, severity classification, and prioritization.
- Collaborate with engineering and product teams to develop mitigation strategies and remediation plans.
- Coordinate responsible disclosure activities with external researchers, customers, and industry partners.
- Oversee security advisories, CVE processes, and customer communications.
- Act as a trusted advisor to product teams on vulnerability management and product security best practices.
- Continuously improve PSIRT processes, metrics, and operational excellence.
Requirements
Ideally, you bring hands-on experience in product, embedded, or hardware security and possess a solid understanding of how attackers target semiconductor devices and embedded systems. You are familiar with common attack techniques and can help assess their potential impact on NXP products.
- Experience in Product Security, Embedded Security, Semiconductor Security, Cybersecurity, or Secure Product Development.
- Strong understanding of vulnerability management, coordinated disclosure, incident handling, or product risk management.
- Ability to influence cross-functional stakeholders across engineering, product management, quality, and customer-facing teams.
- Excellent communication skills and a passion for protecting innovative technology at scale.
Understand Threats. Protect Products. Protect Customers. Lead Response. Reduce Risk. Build Trust. Drive Security. Create Impact. Shape Tomorrow.
Benefits & conditions
NXP provides market competitive compensation according to the benchmarking of the electronic and semiconductor industry. Due to the Austrian Equal Treatment Act we are obligated to state the employment group of our applicable collective bargaining agreement (CBA) âKollektivvertrag fĂźr Angestellte Gewerbe und Handwerk und in der Dienstleistungâ, this position (fulltime) is graded in Employment Group V. Your individual experiences and expectations will be considered in the application process. Moreover, we provide attractive benefits to our employees like home office, flexible working time, meal benefits and more.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Walking Into The Era of Supply Chain Risks
Understanding and Mitigating Common Web Vulnerabilities
Best Companies in the Netherlands: Top 25 Companies in 2023Â
The Netherlands â Europeâs powerhouse for software development?