> Markdown version of [/jobs/ext/3153504-principal-embedded-security-vulnerability-analyst](https://www.wearedevelopers.com/jobs/ext/3153504-principal-embedded-security-vulnerability-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Embedded Security Vulnerability Analyst - **Company:** Ro61 Nxp Semiconductors Romania Srl - **Location:** Austria - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** C (Programming Language), Artificial Intelligence, Static Program Analysis, Cyber Security, Software Debugging, Distributed Systems, Embedded Software, Firmware, Fuzz Testing, Systems Analysis, Joint Test Action (IEEE Standards), Program Analysis, Real-Time Operating Systems, Reverse Engineering, Reduced Instruction Set Computing, Scripting, Large Language Models, Concurrency, Bare Metal, Vulnerability Analysis - **Published:** September 17, 2026 - **Apply:** https://startup.jobs/principal-embedded-security-vulnerability-analyst-m-f-d-ro61-nxp-semiconductors-roma-8670207 ## About the Role You will drive the discovery and analysis of complex vulnerabilities in low-level firmware, boot code, and system components, and influence the security architecture of next-generation products. This role requires expert-level systems thinking, a deep understanding of attack techniques, and the ability to reason about complex execution environments., * highly experienced embedded engineers with a demonstrated transition into security, * Degree in Electrical Engineering, Computer Science, Mathematics, or related field, or equivalent practical experience * Deep understanding of low-level system behavior (memory layout, interrupts, privilege levels, concurrency) * Extensive experience in C programming; strong familiarity with ARM and/or RISC-V architectures * Strong experience with assembly-level debugging and low-level system analysis Strong differentiators: * Proven track record in vulnerability research, reverse engineering, or exploit development * Deep experience with static and dynamic analysis tools, fuzzing, or symbolic execution * Strong understanding of vulnerability classes (memory corruption, logic flaws, side channels) and exploitation techniques * Experience with debugging interfaces (e.g., JTAG, trace, GDB) in complex systems * Experience evaluating and operationalizing AI-assisted vulnerability discovery tools and workflows * Experience building scalable and automated analysis pipelines (e.g., scripting, distributed systems, agent-based approaches) * Rust experience or strong interest in memory-safe system design Your Profile * Expert-level analytical thinking and strong intuition for how systems fail under adversarial conditions * Ability to lead complex, ambiguous technical investigations end-to-end * Strong interest in combining deep technical expertise with modern AI-assisted methodologies * Ability to influence technical direction across teams and organizational levels * Clear and authoritative communication of technical risks and findings * Mentorship mindset and willingness to develop others ## Description * Lead in-depth vulnerability analysis of embedded software (bare-metal, RTOS, trusted execution environments) * Drive analysis of boot flows, privilege boundaries, and security-critical components (e.g., crypto libraries, key handling, isolation mechanisms) * Own root cause analysis and assess exploitability and systemic impact of identified weaknesses * Define and guide security evaluation strategies for certifications (e.g., PSA, SESIP, Common Criteria) * Lead analysis of PSIRT incidents and drive structural and architectural improvements * Architect and develop advanced analysis methodologies and tooling (static analysis, fuzzing, automation frameworks) * Define and scale the use of AI-assisted techniques for code analysis and vulnerability discovery (e.g., LLM-based and agentic workflows) * Design and institutionalize workflows that combine traditional analysis (static/dynamic) with AI-assisted approaches * Evaluate and introduce emerging attack techniques and incorporate them into internal methodologies * Influence product teams and architecture decisions by translating findings into systemic mitigations * Mentor and guide other engineers in vulnerability analysis and research methodologies ## Related Videos - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Single Server, Global Reach: Running a Worldwide Marketplace on Bare Metal in a Cloud-Dominated World](https://www.wearedevelopers.com/videos/1206-single-server-global-reach-running-a-worldwide-marketplace-on-bare-metal-in-a-cloud-dominated-world) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)