Software Security Architect - Cyber Resilience Act & Product Security

NXP Semiconductors
Gratkorn, Austria
1 day ago
Apply on devjobs.at
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Cyber Security Computer Engineering Firmware Hardware Security Module Key Management Secure Coding Software Engineering Software Security Information Technology U-Boot Industrial Software
+1 more
Vulnerability Analysis

Job description

  • Define and drive the Cyber Resilience Act (CRA) compliance strategy for NXP’s MCU and MPU product portfolios within the Security Architecture team.
  • Influence security architecture decisions across multiple product lines and business units.
  • Translate regulatory requirements into actionable security controls, architecture principles, and engineering requirements.
  • Drive security-by-design methodologies across both legacy products and new product introductions (NPI).
  • Lead system-level threat modeling, attack surface analysis, and security risk assessments for complex embedded and semiconductor-based products.
  • Establish security requirements and ensure end-to-end traceability throughout the development lifecycle.
  • Support audit readiness through security evidence generation, compliance documentation, and risk management activities.
  • Collaborate with product architects, engineering teams, product management, compliance experts, and senior stakeholders worldwide.
  • Drive adoption of security best practices, frameworks, and standards across NXP’s product portfolio.

Requirements

  • Bachelor’s, Master’s, or PhD degree in Computer Science, Cybersecurity, Information Security, Software Engineering, Electrical Engineering, Computer Engineering, Embedded Systems, or a related technical field., * Proven expertise in threat modeling, secure system design, and security risk assessment.
  • Deep understanding of security technologies such as: Secure Boot, Cryptography and Key Management, Firmware Protection, Device Identity and Root of Trust, Secure Update Mechanisms.
  • Strong analytical skills with a system-level view of security challenges.
  • Excellent stakeholder management and communication skills.
  • Ability to drive security initiatives across global and cross-functional teams., * Strong experience in embedded systems security and software and/or hardware security architecture.
  • Experience translating security requirements into practical technical architectures and implementations.
  • Experience in one or more of the following areas is highly desirable: Security architecture for embedded, IoT, automotive, or industrial systems, Security certification frameworks such as: PSA Certified, SESIP, Common Criteria, Product security regulations and compliance frameworks, Cyber Resilience Act (CRA) implementation or preparation activities, Secure development lifecycle (SDL) practices, Security assessments, penetration testing, or vulnerability analysis, Secure hardware/software co-design.

Benefits & conditions

  • NXP provides market competitive compensation according to the benchmarking of the electronic and semiconductor industry.
  • Due to the Austrian Equal Treatment Act we are obligated to state the employment group of our applicable collective bargaining agreement (CBA) “Kollektivvertrag fĂźr Angestellte Gewerbe und Handwerk und in der Dienstleistung”, this position (fulltime) is graded in Employment Group V after 6 years.
  • Your individual experiences and expectations will be considered in the application process.
  • Moreover, we provide attractive benefits to our employees like home office, flexible working time, meal benefits and more., Work-Life-Integration

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on devjobs.at
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:57 min

Following security research and continuous developer education

Martin Schmiedecker ¡ LIVE

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa ¡ LIVE

2:19 min

Orchestrating over-the-air firmware updates for vehicle modules

Denis Grahovac ¡ World Congress 2021

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca ¡ World Congress 2021

2:47 min

Securing code provenance with digital identity signatures

Marcus Ross Marcus Ross ¡ World Congress 2026 Europe

2:20 min

Utilizing custom firmware for variable torque manipulation

Daniel Meilak Daniel Meilak +1 ¡ World Congress 2026 Europe

Videos

See all

Related articles

See all