Product Security Vulnerability Response Manager - Embedded & Semiconductor Security (m/f/d)

Posted One Month Ago
Be an Early Applicant
4 Locations
In-Office
Senior level
Automotive • Internet of Things • Mobile • Semiconductor • Industrial
The Role
Lead product security incident response for hardware and software products: triage vulnerabilities, manage PSIRT JIRA tickets, coordinate cross-functional remediation, engage external researchers and vendors, define best practices for third-party and open-source components, and contribute to relevant regulations and standards.
Summary Generated by Built In

Help protect technology that powers millions of devices worldwide.

As a member of NXP's Product Security Incident Response Team (PSIRT), you will play a key role in safeguarding our secure chip products after they have been deployed to customers around the globe.

Acting as the central point of coordination for product security incidents, you will work closely with engineering teams, customers, and security researchers to investigate vulnerabilities, assess risks, coordinate remediation efforts, and communicate security guidance. You will drive security issues from initial reporting through resolution and responsible disclosure, helping ensure that customers can continue to trust the products they rely on every day.

This is not a purely hands-on engineering role. Instead, it offers a unique blend of product security, incident response, stakeholder management, and technical leadership. Success in this position comes from your ability to bring together experts from different disciplines, navigate complex security challenges, and drive solutions to completion.

Our PSIRT team is dedicated to rapidly addressing security threats affecting NXP products worldwide. By investigating reported vulnerabilities, evaluating their impact, and providing timely and actionable guidance to customers, we help protect products throughout their lifecycle and maintain the trust that customers place in NXP.

If you enjoy leading security investigations, coordinating across diverse stakeholders, and making a visible impact on the security of products used by millions of people worldwide, we'd love to hear from you.

See also www.nxp.com/psirt.  

Ideally, you bring hands-on experience in product, embedded, or hardware security and possess a solid understanding of how attackers target semiconductor devices and embedded systems. You are familiar with common attack techniques and can help assess their potential impact on NXP products.

What you'll do: A snapshot of your key responsibilities and impact.

  • Lead the response and coordination of security vulnerabilities affecting NXP products, hardware and software.

  • Drive vulnerability triage, impact assessment, severity classification, and prioritization.

  • Collaborate with engineering and product teams to develop mitigation strategies and remediation plans.

  • Coordinate responsible disclosure activities with external researchers, customers, and industry partners.

  • Oversee security advisories, CVE processes, and customer communications.

  • Act as a trusted advisor to product teams on vulnerability management and product security best practices.

  • Continuously improve PSIRT processes, metrics, and operational excellence.

What you'll bring

  • Experience in Product Security, Embedded Security, Semiconductor Security, Cybersecurity, or Secure Product Development.

  • Strong understanding of vulnerability management, coordinated disclosure, incident handling, or product risk management.

  • Ability to influence cross-functional stakeholders across engineering, product management, quality, and customer-facing teams.

  • Excellent communication skills and a passion for protecting innovative technology at scale.

Understand Threats.  Protect Products. Protect Customers. Lead Response. Reduce Risk. Build Trust. Drive Security. Create Impact. Shape Tomorrow.

For Austrian applicants: NXP provides market competitive compensation according to the benchmarking of the electronic and semiconductor industry. Due to the Austrian Equal Treatment Act we are obligated to state the employment group of our applicable collective bargaining agreement (CBA) “Kollektivvertrag für Angestellte Gewerbe und Handwerk und in der Dienstleistung“, this position (fulltime) is graded in Employment Group V. Your individual experiences and expectations will be considered in the application process. Moreover, we provide attractive benefits to our employees like home office, flexible working time, meal benefits and more.

More information about NXP in Austria...

#LI-b6c8

Skills Required

  • Bachelor's or Master's degree in Computer Science, Electrical Engineering, Cybersecurity, or related field
  • Experience in product security incident response, investigation and vulnerability management across hardware and software products
  • Familiarity with Security Operations Center (SOC), PSIRT, or similar incident response teams
  • Familiarity with industry-standard security frameworks, standards, and regulations
  • Understanding of security for embedded systems, hardware and software
  • Experience generating and managing PSIRT JIRA tickets (or equivalent ticketing systems)
  • Excellent collaboration and communication skills for cross-functional engagement
  • Ability to work independently and take ownership of security initiatives and process improvements
  • Conscious and reliable way of working due to potential security certification scope
  • Interest in security concepts, secure coding, and security best practices
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Eindhoven
21,993 Employees
Year Founded: 2006

What We Do

NXP Semiconductors N.V. (NASDAQ: NXPI) enables a smarter, safer and more sustainable world through innovation. As a world leader in secure connectivity solutions for embedded applications, NXP is pushing boundaries in the automotive, industrial & IoT, mobile, and communication infrastructure markets. Built on more than 60 years of combined experience and expertise, the company has approximately 34,500 employees in more than 30 countries and posted revenue of $13.21 billion in 2022. Find out more at www.nxp.com. Privacy Policy: https://www.nxp.com/company/about-nxp/privacy-policy-for-social-media-pages:PRIVACY-POLICY-SOCIAL-MEDIA

Similar Jobs

Lansweeper Logo Lansweeper

Director Strategic Revenue Operations

Cloud • Information Technology • Software • Cybersecurity
Hybrid
2 Locations
404 Employees
113K-183K Annually
Remote or Hybrid
2 Locations
289097 Employees

Pfizer Logo Pfizer

Senior Manager, HTA, Value and Evidence (HV&E), Genitourinary Cancer

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
30 Locations
121990 Employees
139K-232K Annually

Snap Inc. Logo Snap Inc.

Senior Manager, EU Public Policy

Artificial Intelligence • Cloud • Machine Learning • Mobile • Software • Virtual Reality • App development
Remote or Hybrid
Belgium
5000 Employees

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account