> Markdown version of [/jobs/ext/3060875-software-security-architect-cyber-resilience-act-product-security](https://www.wearedevelopers.com/jobs/ext/3060875-software-security-architect-cyber-resilience-act-product-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Security Architect - Cyber Resilience Act & Product Security - **Company:** NXP Semiconductors - **Location:** Gratkorn, Austria (Remote available) - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Computer Engineering, Firmware, Hardware Security Module, Key Management, Secure Coding, Software Engineering, Software Security, Information Technology, U-Boot, Industrial Software, Vulnerability Analysis - **Published:** September 25, 2026 - **Apply:** https://devjobs.at/job/43756de95fc0db59a587e8d9ab929967 ## About the Role * Bachelor's, Master's, or PhD degree in Computer Science, Cybersecurity, Information Security, Software Engineering, Electrical Engineering, Computer Engineering, Embedded Systems, or a related technical field., * Proven expertise in threat modeling, secure system design, and security risk assessment. * Deep understanding of security technologies such as: Secure Boot, Cryptography and Key Management, Firmware Protection, Device Identity and Root of Trust, Secure Update Mechanisms. * Strong analytical skills with a system-level view of security challenges. * Excellent stakeholder management and communication skills. * Ability to drive security initiatives across global and cross-functional teams., * Strong experience in embedded systems security and software and/or hardware security architecture. * Experience translating security requirements into practical technical architectures and implementations. * Experience in one or more of the following areas is highly desirable: Security architecture for embedded, IoT, automotive, or industrial systems, Security certification frameworks such as: PSA Certified, SESIP, Common Criteria, Product security regulations and compliance frameworks, Cyber Resilience Act (CRA) implementation or preparation activities, Secure development lifecycle (SDL) practices, Security assessments, penetration testing, or vulnerability analysis, Secure hardware/software co-design. ## Description * Define and drive the Cyber Resilience Act (CRA) compliance strategy for NXP's MCU and MPU product portfolios within the Security Architecture team. * Influence security architecture decisions across multiple product lines and business units. * Translate regulatory requirements into actionable security controls, architecture principles, and engineering requirements. * Drive security-by-design methodologies across both legacy products and new product introductions (NPI). * Lead system-level threat modeling, attack surface analysis, and security risk assessments for complex embedded and semiconductor-based products. * Establish security requirements and ensure end-to-end traceability throughout the development lifecycle. * Support audit readiness through security evidence generation, compliance documentation, and risk management activities. * Collaborate with product architects, engineering teams, product management, compliance experts, and senior stakeholders worldwide. * Drive adoption of security best practices, frameworks, and standards across NXP's product portfolio. ## Related Videos - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) ## Related Articles - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The Ultimate Software Engineer Career Path Guide for 2023](https://www.wearedevelopers.com/magazine/146-the-ultimate-software-engineer-career-path-guide-for-2023) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)