> Markdown version of [/jobs/ext/293705-software-security-architect-cyber-resilience-act-cra-focus-m-f](https://www.wearedevelopers.com/jobs/ext/293705-software-security-architect-cyber-resilience-act-cra-focus-m-f). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Security Architect - Cyber Resilience Act (CRA) Focus (m/f) - **Company:** NXP Semiconductors - **Location:** Gratkorn, Austria - **Contract:** Permanent contract - **Skills:** Cyber Security, Firmware, Hardware Security Module, Software Security, U-Boot - **Published:** June 9, 2026 - **Apply:** https://at.indeed.com/viewjob?jk=1b18b18a1fcece1d ## About the Role * Strong background in Embedded systems security, Software and/or hardware security architecture * Proven experience with Threat modeling methodologies and security technologies such as secure boot, cryptography, firmware protection * Familiarity with security certification frameworks, such as: PSA, SESIP, Common Criteria * Experience with or strong interest in Cyber Resilience Act (CRA), Product security regulations and standards, Compliance-driven development and documentation * Ability to translate regulatory requirements into technical implementation * Strong analytical and system-level thinking * Excellent stakeholder management and cross-functional collaboration skills * Comfortable working in a global, matrixed organization with diverse product teams Please note: The successful candidate may/will be responsible for security related tasks. The assignment may/will be in scope of security certifications, therefore a conscious and reliable way of working is necessary. ## Description We are seeking an experienced Software Security Architect to join our Software Security Architecture team within CCC&S. In this role, you will take a leading position in driving Cyber Resilience Act (CRA) readiness across our product portfolio, ensuring compliance with upcoming mandatory regulatory requirements. This role combines strategic ownership and hands-on technical expertise at the intersection of product security architecture, regulatory compliance, and system-level threat analysis. You will support both legacy product lines and new product introductions (NPI), embedding security-by-design principles and ensuring lifecycle compliance across all development stages. Your Responsibilities: * Define and drive the CRA compliance strategy for MCU and MPU product portfolios through the central security architecture team. * Ensure alignment with upcoming mandatory CRA requirements (target: 2027) * Translate regulatory requirements into practical security controls, design principles, and architecture guidelines * Support audit readiness (compliance doczntation, security evidence generation and end to end traceability of requirements) * Define, implement, and maintain robust security architectures across Legacy products & New Product Introductions (NPI) * Ensure consistent application of security standards, methodologies, and best practices across product lines * Collaborate with cross-functional teams (engineering, product management, compliance) to embed security into development processes * Lead and conduct system-level threat modeling and threat analysis (hardware and software) * Perform security risk assessments aligned with CRA expectations and industry standards ## Related Videos - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Software Developer Salary in Austria [2023]](https://www.wearedevelopers.com/magazine/213-software-developer-salary-in-austria-2023) - [The Netherlands – Europe’s powerhouse for software development?](https://www.wearedevelopers.com/magazine/31-the-netherlands-europe-s-powerhouse-for-software-development)