> Markdown version of [/jobs/ext/3063992-software-security-architect-cyber-resilience-act-focus](https://www.wearedevelopers.com/jobs/ext/3063992-software-security-architect-cyber-resilience-act-focus). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Security Architect - Cyber Resilience Act Focus - **Company:** NXP Semiconductors - **Location:** Gratkorn, Austria (Remote available) - **Contract:** Permanent contract - **Skills:** Cyber Security, Firmware, Hardware Security Module, Software Security, U-Boot - **Published:** September 25, 2026 - **Apply:** https://devjobs.at/job/985ac1481ded52c28a4e5707698785e5 ## About the Role * Strong background in Embedded systems security, Software and/or hardware security architecture. * Familiarity with security certification frameworks, such as: PSA, SESIP, Common Criteria. * Ability to translate regulatory requirements into technical implementation. * Strong analytical and system-level thinking. * Excellent stakeholder management and cross-functional collaboration skills. * Comfortable working in a global, matrixed organization with diverse product teams., * Proven experience with Threat modeling methodologies and security technologies such as secure boot, cryptography, firmware protection. * Experience with or strong interest in Cyber Resilience Act (CRA), Product security regulations and standards, Compliance-driven development and documentation. ## Description * Join one of the world's largest industrial security teams - and build technology that protects real devices worldwide. * At NXP's Competence Center Crypto & Security (CC C&S), we design, build, and deliver end-to-end security - from early innovation to architecture to products in the field. * We are seeking an experienced Software Security Architect to join our Software Security Architecture team within CCC&S. * In this role, you will take a leading position in driving Cyber Resilience Act (CRA) readiness across our product portfolio, ensuring compliance with upcoming mandatory regulatory requirements. * This role combines strategic ownership and hands-on technical expertise at the intersection of product security architecture, regulatory compliance, and system-level threat analysis. * You will support both legacy product lines and new product introductions (NPI), embedding security-by-design principles and ensuring lifecycle compliance across all development stages. * Define and drive the CRA compliance strategy for MCU and MPU product portfolios through the central security architecture team. * Ensure alignment with upcoming mandatory CRA requirements (target: 2027). * Translate regulatory requirements into practical security controls, design principles, and architecture guidelines. * Support audit readiness (compliance documentation, security evidence generation and end to end traceability of requirements). * Define, implement, and maintain robust security architectures across Legacy products & New Product Introductions (NPI). * Ensure consistent application of security standards, methodologies, and best practices across product lines. * Collaborate with cross-functional teams (engineering, product management, compliance) to embed security into development processes. * Lead and conduct system-level threat modeling and threat analysis (hardware and software). * Perform security risk assessments aligned with CRA expectations and industry standards. ## Related Videos - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [Cybersecurity for Software Defined Vehicles](https://www.wearedevelopers.com/videos/725-cybersecurity-for-software-defined-vehicles) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)