Software Security Architect – Cyber Resilience Act (CRA) & Product Security (m/f/d)

Posted 5 Days Ago
Be an Early Applicant
3 Locations
In-Office
Senior level
Automotive • Internet of Things • Mobile • Semiconductor • Industrial
The Role
Lead CRA compliance strategy and influence security architecture across MCU/MPU product lines. Translate regulations into security controls, perform system-level threat modeling and risk assessments, ensure traceability and audit readiness, and drive security-by-design across legacy and new products while collaborating with global stakeholders.
Summary Generated by Built In

Join one of the world's largest industrial security organizations and help define the security foundations of products used by millions of people worldwide.

At NXP's Competence Center Crypto & Security (CC C&S), security is at the core of everything we do. Our experts drive innovation from advanced security research and architecture to deployment in automotive, industrial, IoT, mobile, and edge processing solutions.

We are looking for an experienced Software Security Architect to join our Software Security Architecture team and lead the strategic implementation of the European Cyber Resilience Act (CRA) across NXP's product portfolio.

This is a highly visible role that combines security architecture, regulatory leadership, threat analysis, and cross-functional influence. You will have the opportunity to shape how security is embedded into products throughout their entire lifecycle while working alongside recognized experts in product security and secure system design.

If you are passionate about secure embedded systems, product security, and driving industry-leading security practices, we would love to hear from you.

As a Software Security Architect, you will play a key role in ensuring that NXP's products meet future security expectations while maintaining the highest standards of security engineering.

You will:

  • Define and drive the Cyber Resilience Act (CRA) compliance strategy for NXP's MCU and MPU product portfolios within the Security Arcitecture team.

  • Influence security architecture decisions across multiple product lines and business units.

  • Translate regulatory requirements into actionable security controls, architecture principles, and engineering requirements.

  • Drive security-by-design methodologies across both legacy products and new product introductions (NPI).

  • Lead system-level threat modeling, attack surface analysis, and security risk assessments for complex embedded and semiconductor-based products.

  • Establish security requirements and ensure end-to-end traceability throughout the development lifecycle.

  • Support audit readiness through security evidence generation, compliance documentation, and risk management activities.

  • Collaborate with product architects, engineering teams, product management, compliance experts, and senior stakeholders worldwide.

  • Drive adoption of security best practices, frameworks, and standards across NXP's product portfolio.

You have:

  • Bachelor's, Master's, or PhD degree in Computer Science, Cybersecurity, Information Security, Software Engineering, Electrical Engineering, Computer Engineering, Embedded Systems, or a related technical field.

  • Strong experience in embedded systems security and software and/or hardware security architecture.

  • Proven expertise in threat modeling, secure system design, and security risk assessment.

  • Deep understanding of security technologies such as:

    • Secure Boot

    • Cryptography and Key Management

    • Firmware Protection

    • Device Identity and Root of Trust

    • Secure Update Mechanisms

  • Experience translating security requirements into practical technical architectures and implementations.

  • Strong analytical skills with a system-level view of security challenges.

  • Excellent stakeholder management and communication skills.

  • Ability to drive security initiatives across global and cross-functional teams.

Experience in one or more of the following areas is highly desirable:

  • Security architecture for embedded, IoT, automotive, or industrial systems.

  • Security certification frameworks such as:

    • PSA Certified

    • SESIP

    • Common Criteria

  • Product security regulations and compliance frameworks.

  • Cyber Resilience Act (CRA) implementation or preparation activities.

  • Secure development lifecycle (SDL) practices.

  • Security assessments, penetration testing, or vulnerability analysis.

  • Secure hardware/software co-design.

Please note: The successful candidate may/will be responsible for security related tasks. The assignment may/will be in scope of security certifications, therefore a conscious and reliable way of working is necessary.

For applications in Gratkorn: NXP provides market competitive compensation according to the benchmarking of the electronic and semiconductor industry. Due to the Austrian Equal Treatment Act we are obligated to state the employment group of our applicable collective bargaining agreement (CBA) “Kollektivvertrag für Angestellte Gewerbe und Handwerk und in der Dienstleistung“, this position (fulltime) is graded in Employment Group V after 6 years. Your individual experiences and expectations will be considered in the application process. Moreover, we provide attractive benefits to our employees like home office, flexible working time, meal benefits and more.

More information about NXP in Austria...

#LI-a8a1

Skills Required

  • Bachelor's, Master's, or PhD in Computer Science, Cybersecurity, Software/Electrical/Computer/Embedded Engineering or related field
  • Strong experience in embedded systems security and software and/or hardware security architecture
  • Proven expertise in threat modeling, secure system design, and security risk assessment
  • Deep understanding of Secure Boot, Cryptography and Key Management, Firmware Protection, Device Identity and Root of Trust, Secure Update Mechanisms
  • Experience translating regulatory/security requirements into technical architectures and implementations
  • Ability to drive security initiatives across global and cross-functional teams; strong stakeholder management and communication skills
  • Experience with security architecture for embedded, IoT, automotive, or industrial systems
  • Familiarity with security certification frameworks (PSA Certified, SESIP, Common Criteria)
  • Experience with product security regulations/compliance frameworks and Cyber Resilience Act (CRA) implementation
  • Knowledge of secure development lifecycle (SDL) practices
  • Experience in security assessments, penetration testing, or vulnerability analysis
  • Experience with secure hardware/software co-design
  • Conscious and reliable way of working due to security-related tasks and certifications
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Eindhoven
21,993 Employees
Year Founded: 2006

What We Do

NXP Semiconductors N.V. (NASDAQ: NXPI) enables a smarter, safer and more sustainable world through innovation. As a world leader in secure connectivity solutions for embedded applications, NXP is pushing boundaries in the automotive, industrial & IoT, mobile, and communication infrastructure markets. Built on more than 60 years of combined experience and expertise, the company has approximately 34,500 employees in more than 30 countries and posted revenue of $13.21 billion in 2022. Find out more at www.nxp.com. Privacy Policy: https://www.nxp.com/company/about-nxp/privacy-policy-for-social-media-pages:PRIVACY-POLICY-SOCIAL-MEDIA

Similar Jobs

CrowdStrike Logo CrowdStrike

Senior Software Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Hybrid
Bucharest, București, ROU
11000 Employees

CrowdStrike Logo CrowdStrike

Threat Researcher I (Remote, ROU)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
România
11000 Employees

Pfizer Logo Pfizer

Senior Director, Applied AI - US Commercial

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
28 Locations
121990 Employees
215K-358K Annually

Tulip Logo Tulip

Forward Deployed Engineer - EMEA

Enterprise Web • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
27 Locations
310 Employees
70K-105K Annually

Similar Companies Hiring

ARB Interactive Thumbnail
Gaming • Mobile • Software
Miami, Florida
190 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account