Product Security Incident Response Manager (m/f/d)

Posted 4 Days Ago
Be an Early Applicant
4 Locations
In-Office
Senior level
Automotive • Internet of Things • Mobile • Semiconductor • Industrial
The Role
Lead product security incident response for hardware and software products: triage vulnerabilities, manage PSIRT JIRA tickets, coordinate cross-functional remediation, engage external researchers and vendors, define best practices for third-party and open-source components, and contribute to relevant regulations and standards.
Summary Generated by Built In

Join one of the world’s largest industrial security teams — and build technology that protects real devices worldwide.
At NXP’s Competence Center Crypto & Security, we design, build, and deliver end-to-end security — from early innovation to architecture to products in the field.
If you're a security engineer who wants to create real-world impact, we’d love to hear from you.

The NXP Product Security Incident Response Team (PSIRT) is committed to rapidly address security vulnerabilities in NXP products, by responding and documenting reported vulnerabilities and by providing customers with clear guidance on the impact, severity and mitigation. See also www.nxp.com/psirt.  

Our organization is growing and therefore we have this new opportunity. We’re looking for an experienced security expert to work on different initiatives and projects with the goal of improving our security posture. In addition, you will be responsible for identifying, triaging, and supporting resolution of product-related security incidents.  You’ll get the opportunity to collaborate across engineering, security teams, product managers and others with the goal of protecting our products and customers.

Your Responsibilities

  • Empower our software development community in managing vulnerabilities in Third Party Components (TPS) and Open Source Software (OSS), ensuring robust security

  • Define and develop best practices, streamline processes, and drive continuous improvement initiatives.

  • Contribute to new regulations and standardization activities that may impact product security or our way of working such as the upcoming EU Cyber Resilience Act.

  • Collaborate with innovators – partner with external security researchers, academia and research organizations on cutting-edge projects and vulnerability submissions.

  • Be a key player in risk management by supporting and leading triage and vulnerability assessments of product vulnerabilities.

  • Work cross-functionally with internal teams (engineering, product management, legal, etc.) to ensure timely resolution of incidents.

  • Own the process by generating and managing PSIRT JIRA tickets for validated vulnerabilities.

  • Provide updates about incident status, impact, and mitigation actions to relevant stakeholders.

  • Manage incoming Third Party vendor vulnerability pre-notifications andmonitor internal and external sources to identify signs of security incidents related to our products.

Your profile

  • Bachelor’s/master’s degree in engineering – Computer Science, Electrical Engineering, Cybersecurity, or a related field.

  • Experience in product security incident response, investigation and vulnerability management across hardware and software products.

  • Familiarity in a Security Operations Center or PSIRT or similar security incident response teams.
  • Familiarity with industry-standard security frameworks, standards, and regulations.

  • Understanding of security in the following areas - embedded systems, hardware and software; ability to quickly learn where needed

  • Interests in security concepts, secure coding, and security best practices

  • Excellent collaboration and communication skills to work effectively with cross-functional teams.

  • Ability to work independently, taking ownership of security initiatives and improving processes.

Please note: The successful candidate may/will be responsible for security related tasks. The assignment may/will be in scope of security certifications, therefore a conscious and reliable way of working is necessary.

For Austrian applicants: NXP provides market competitive compensation according to the benchmarking of the electronic and semiconductor industry. Due to the Austrian Equal Treatment Act we are obligated to state the employment group of our applicable collective bargaining agreement (CBA) “Kollektivvertrag für Angestellte Gewerbe und Handwerk und in der Dienstleistung“, this position (fulltime) is graded in Employment Group V. Your individual experiences and expectations will be considered in the application process. Moreover, we provide attractive benefits to our employees like home office, flexible working time, meal benefits and more.

More information about NXP in Austria...

#LI-38ff

Skills Required

  • Bachelor's or Master's degree in Computer Science, Electrical Engineering, Cybersecurity, or related field
  • Experience in product security incident response, investigation and vulnerability management across hardware and software products
  • Familiarity with Security Operations Center (SOC), PSIRT, or similar incident response teams
  • Familiarity with industry-standard security frameworks, standards, and regulations
  • Understanding of security for embedded systems, hardware and software
  • Experience generating and managing PSIRT JIRA tickets (or equivalent ticketing systems)
  • Excellent collaboration and communication skills for cross-functional engagement
  • Ability to work independently and take ownership of security initiatives and process improvements
  • Conscious and reliable way of working due to potential security certification scope
  • Interest in security concepts, secure coding, and security best practices
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Eindhoven
21,993 Employees
Year Founded: 2006

What We Do

NXP Semiconductors N.V. (NASDAQ: NXPI) enables a smarter, safer and more sustainable world through innovation. As a world leader in secure connectivity solutions for embedded applications, NXP is pushing boundaries in the automotive, industrial & IoT, mobile, and communication infrastructure markets. Built on more than 60 years of combined experience and expertise, the company has approximately 34,500 employees in more than 30 countries and posted revenue of $13.21 billion in 2022. Find out more at www.nxp.com. Privacy Policy: https://www.nxp.com/company/about-nxp/privacy-policy-for-social-media-pages:PRIVACY-POLICY-SOCIAL-MEDIA

Similar Jobs

Zscaler Logo Zscaler

Account Executive

Cloud • Information Technology • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
Belgium
8697 Employees

Lansweeper Logo Lansweeper

Technical Support

Cloud • Information Technology • Software
Hybrid
Gent, BEL
404 Employees
35K-47K Annually

Pfizer Logo Pfizer

Senior Director, Applied AI - US Commercial

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
28 Locations
121990 Employees
215K-358K Annually

Tulip Logo Tulip

Forward Deployed Engineer - EMEA

Enterprise Web • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
27 Locations
310 Employees
70K-105K Annually

Similar Companies Hiring

ARB Interactive Thumbnail
Gaming • Mobile • Software
Miami, Florida
190 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account