Software Security Analyst (m/f/d)

Posted One Month Ago
Be an Early Applicant
2 Locations
In-Office
Senior level
Automotive • Internet of Things • Mobile • Semiconductor • Industrial
The Role
Perform deep vulnerability analysis of embedded firmware, boot code, and security-critical components (RTOS, TEEs). Assess exploitability, root cause, and impact; support certifications and PSIRT; develop tooling and AI-assisted analysis workflows; research attack techniques and collaborate with development teams to drive mitigations.
Summary Generated by Built In

We are seeking a Senior Embedded Security Vulnerability Analyst to perform deep technical analysis of embedded systems, focusing on identifying and understanding vulnerabilities at the hardware/software boundary.

You will analyze low-level firmware, boot code, and system components to uncover exploitable weaknesses and work closely with development teams to drive secure designs. The role requires a strong systems mindset, curiosity for attack techniques, and the ability to reason about complex execution environments. You will also leverage and help shape modern analysis approaches, including AI-assisted vulnerability discovery workflows, to improve both depth and scalability of analysis.

If you are already exploring how LLMs and agentic workflows can augment deep code and system analysis, this role provides an opportunity to apply and advance these approaches in a real-world embedded security setting.

We welcome both:

  • experienced security researchers

  • strong embedded engineers with a demonstrated interest in transitioning into security

Your Responsibilities

  • Perform in-depth vulnerability analysis of embedded software (bare-metal, RTOS, trusted execution environments)

  • Analyze boot flows, privilege boundaries, and security-critical components (e.g., crypto libraries, key handling, isolation mechanisms)

  • Conduct root cause analysis and assess exploitability and impact of identified weaknesses

  • Support security certifications and evaluations (e.g., PSA, SESIP, Common Criteria)

  • Analyze PSIRT incidents and derive structural improvements

  • Develop and apply analysis methodologies and tooling (static analysis, fuzzing, scripting, automation)

  • Apply and evaluate AI-assisted techniques for code analysis and vulnerability discovery (e.g., LLM-based workflows)

  • Design and refine workflows that combine traditional analysis (static and dynamic) with AI-assisted approaches

  • Research and evaluate emerging attack techniques relevant to embedded systems

  • Collaborate with development teams to translate findings into concrete mitigations

Education & Qualifications

  • Degree in Electrical Engineering, Computer Science, Mathematics, or related field

  • Strong understanding of low-level system behavior (memory layout, interrupts, privilege levels, concurrency)

  • Solid experience in C programming; familiarity with ARM and/or RISC-V architectures

  • Experience with assembly-level debugging and analysis

Strong differentiators:

  • Experience with vulnerability research, reverse engineering, or exploit development

  • Familiarity with static and dynamic analysis tools, fuzzing, or symbolic execution

  • Understanding of common vulnerability classes (memory corruption, logic flaws, side channels)

  • Experience with debugging interfaces (e.g., JTAG, trace, GDB)

  • Experience using or evaluating AI-assisted code analysis or vulnerability discovery tools

  • Experience building or integrating automated analysis workflows (e.g., scripting, pipelines, agent-based approaches)

  • Rust experience or interest in memory-safe system design

Your Profile

  • Strong analytical thinking and curiosity for how systems fail under adversarial conditions

  • Ability to work independently and drive complex technical investigations

  • Interest in combining deep technical analysis with modern AI-assisted techniques

  • Clear communication of technical findings and risks to diverse audiences

  • Collaborative mindset when working with development and architecture teams

Please note: The successful candidate may/will be responsible for security related tasks. The assignment may/will be in scope of security certifications, therefore a conscious and reliable way of working is necessary.

For applications in Gratkorn: NXP provides market competitive compensation according to the benchmarking of the electronic and semiconductor industry. Due to the Austrian Equal Treatment Act we are obligated to state the employment group of our applicable collective bargaining agreement (CBA) “Kollektivvertrag für Angestellte Gewerbe und Handwerk und in der Dienstleistung“, this position (fulltime) is graded in Employment GroupV. Your individual experiences and expectations will be considered in the application process. Moreover, we provide attractive benefits to our employees like home office, flexible working time, meal benefits and more.

More information about NXP in Austria...

#LI-a8a1

Skills Required

  • Degree in Electrical Engineering, Computer Science, Mathematics, or related field
  • Strong understanding of low-level system behavior (memory layout, interrupts, privilege levels, concurrency)
  • Solid experience in C programming
  • Familiarity with ARM and/or RISC-V architectures
  • Experience with assembly-level debugging and analysis
  • Experience with vulnerability research, reverse engineering, or exploit development
  • Familiarity with static and dynamic analysis tools, fuzzing, or symbolic execution
  • Understanding of common vulnerability classes (memory corruption, logic flaws, side channels)
  • Experience with debugging interfaces (e.g., JTAG, trace, GDB)
  • Experience using or evaluating AI-assisted code analysis or vulnerability discovery tools (LLM-based workflows)
  • Experience building or integrating automated analysis workflows (scripting, pipelines, agent-based approaches)
  • Rust experience or interest in memory-safe system design
  • Ability to work independently and drive complex technical investigations
  • Clear communication of technical findings and risks to diverse audiences
  • Collaborative mindset when working with development and architecture teams
  • Support security certifications and evaluations (e.g., PSA, SESIP, Common Criteria)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Eindhoven
21,993 Employees
Year Founded: 2006

What We Do

NXP Semiconductors N.V. (NASDAQ: NXPI) enables a smarter, safer and more sustainable world through innovation. As a world leader in secure connectivity solutions for embedded applications, NXP is pushing boundaries in the automotive, industrial & IoT, mobile, and communication infrastructure markets. Built on more than 60 years of combined experience and expertise, the company has approximately 34,500 employees in more than 30 countries and posted revenue of $13.21 billion in 2022. Find out more at www.nxp.com. Privacy Policy: https://www.nxp.com/company/about-nxp/privacy-policy-for-social-media-pages:PRIVACY-POLICY-SOCIAL-MEDIA

Similar Jobs

Lansweeper Logo Lansweeper

Director Strategic Revenue Operations

Cloud • Information Technology • Software • Cybersecurity
Hybrid
2 Locations
404 Employees
113K-183K Annually
Remote or Hybrid
2 Locations
289097 Employees

Pfizer Logo Pfizer

Senior Manager, HTA, Value and Evidence (HV&E), Genitourinary Cancer

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
30 Locations
121990 Employees
139K-232K Annually

Snap Inc. Logo Snap Inc.

Senior Manager, EU Public Policy

Artificial Intelligence • Cloud • Machine Learning • Mobile • Software • Virtual Reality • App development
Remote or Hybrid
Belgium
5000 Employees

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account