> Markdown version of [/jobs/ext/3611318-software-security-analyst](https://www.wearedevelopers.com/jobs/ext/3611318-software-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Security Analyst - **Company:** Nxp - **Location:** Wien, Austria - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** C (Programming Language), Artificial Intelligence, Static Program Analysis, Software Debugging, Embedded Software, Firmware, Fuzz Testing, Joint Test Action (IEEE Standards), Program Analysis, Real-Time Operating Systems, Reverse Engineering, Reduced Instruction Set Computing, Scripting, Large Language Models, Concurrency, Software Security, Information Technology, Bare Metal, Vulnerability Analysis - **Published:** October 8, 2026 - **Apply:** https://www.studentjob.at/stellenangebote/8883179-software-security-analyst-m-f-d ## About the Role We welcome both:experienced security researchersstrong embedded engineers with a demonstrated interest in transitioning into securityYour ResponsibilitiesPerform in-depth vulnerability analysis of embedded software (bare-metal, RTOS, trusted execution environments)Analyze boot flows, privilege boundaries, and security-critical components (e.g., crypto libraries, key handling, isolation mechanisms)Conduct root cause analysis and assess exploitability and impact of identified weaknessesSupport security certifications and evaluations (e.g., PSA, SESIP, Common Criteria)Analyze PSIRT incidents and derive structural improvementsDevelop and apply analysis methodologies and tooling (static analysis, fuzzing, scripting, automation)Apply and evaluate AI-assisted techniques for code analysis and vulnerability discovery (e.g., LLM-based workflows)Design and refine workflows that combine traditional analysis (static and dynamic) with AI-assisted approachesResearch and evaluate emerging attack techniques relevant to embedded systemsCollaborate with development teams to translate findings into concrete mitigationsEducation & QualificationsDegree in Electrical Engineering, Computer Science, Mathematics, or related fieldStrong understanding of low-level system behavior (memory layout, interrupts, privilege levels, concurrency)Solid experience in C programming; familiarity with ARM and/or RISC-V architecturesExperience with assembly-level debugging and analysisStrong differentiators: Experience with vulnerability research, reverse engineering, or exploit developmentFamiliarity with static and dynamic analysis tools, fuzzing, or symbolic executionUnderstanding of common vulnerability classes (memory corruption, logic flaws, side channels)Experience with debugging interfaces (e.g., JTAG, trace, GDB)Experience using or evaluating AI-assisted code analysis or vulnerability discovery toolsExperience building or integrating automated analysis workflows (e.g., scripting, pipelines, agent-based approaches)Rust experience or interest in memory-safe system designYour ProfileStrong analytical thinking and curiosity for how systems fail under adversarial conditionsAbility to work independently and drive complex technical investigationsInterest in combining deep technical analysis with modern AI-assisted techniquesClear communication of technical findings and risks to diverse audiencesCollaborative mindset when working with development and architecture teamsPlease note: The successful candidate may/will be responsible for security related tasks. The assignment may/will be in scope of security certifications, therefore a conscious and reliable way of working is necessary. ## Description We are seeking a Senior Embedded Security Vulnerability Analyst to perform deep technical analysis of embedded systems, focusing on identifying and understanding vulnerabilities at the hardware/software boundary. You will analyze low-level firmware, boot code, and system components to uncover exploitable weaknesses and work closely with development teams to drive secure designs. The role requires a strong systems mindset, curiosity for attack techniques, and the ability to reason about complex execution environments. You will also leverage and help shape modern analysis approaches, including AI-assisted vulnerability discovery workflows, to improve both depth and scalability of analysis.