Product Security Vulnerability Response Manager - Embedded & Semiconductor Security (m/f/d)

NXP Semiconductors · Gratkorn · Bucharest · Leuven · Glasgow

onsitefull-time6-10 years

posted 1d

Sign in to apply

This role is about ensuring the resilience NXP products (Secure Chips rather then IT Systems) who are are embedded in millions of automotive, industrial, IoT, mobile, and edge devices. In this role, you will help protect products already deployed in the field, leading the response to security vulnerabilities, coordinating mitigation strategies, and strengthening customer trust throughout the post-production product lifecycle . Working at the intersection of Product Security, Engineering, R&D, Customers, and External Security Researchers, you will drive the end-to-end lifecycle of vulnerability management, from initial disclosure through risk assessment, mitigation, and customer communication. As a key member of NXP's Product Security Incident Response Team (PSIRT), you will lead the end-to-end response to security issues affecting NXP products already deployed worldwide. Partnering with engineering teams, customers, and security researchers, you will assess risk, coordinate remediation efforts, manage responsible disclosure, and help safeguard customer trust throughout the product lifecycle. Our PSIRT is committed to rapidly addressing security threats in NXP products by investigating reported issues, evaluating their potential impact, and providing customers with timely and actionable guidance. See also www.nxp.com/psirt . Ideally, you bring hands-on experience in product, embedded, or hardware security and possess a solid understanding of how attackers target semiconductor devices and embedded systems. You are familiar with common attack techniques and can help assess their potential impact on NXP products. What you'll do: A snapshot of your key responsibilities and impact. Lead the response and coordination of security vulnerabilities affecting NXP products, hardware and software. Drive vulnerability triage, impact assessment, severity classification, and prioritization. Collaborate with engineering and product teams to develop mitigation strategies and remediation plans. Coordinate responsible disclosure activities with external researchers, customers, and industry partners. Oversee security advisories, CVE processes, and customer communications. Act as a trusted advisor to product teams on vulnerability management and product security best practices. Continuously improve PSIRT processes, metrics, and operational excellence. What you'll bring Experience in Product Security, Embedded Security, Semiconductor Security, Cybersecurity, or Secure Product Development. Strong understanding of vulnerability management, coordinated disclosure, incident handling, or product risk management. Ability to influence cross-functional stakeholders across engineering, product management, quality, and customer-facing teams. Excellent communication skills and a passion for protecting innovative technology at scale. Understand Threats. Protect Products. Protect Customers. Lead Response. Reduce Risk. Build Trust. Drive Security. Create Impact. Shape Tomorrow. For Austrian applicants: NXP provides market competitive compensation according to the benchmarking of the electronic and semiconductor industry. Due to the Austrian Equal Treatment Act we are obligated to state the employment group of our applicable collective bargaining agreement (CBA) “Kollektivvertrag für Angestellte Gewerbe und Handwerk und in der Dienstleistung“, this position (fulltime) is graded in Employment Group V. Your individual experiences and expectations will be considered in the application process. Moreover, we provide attractive benefits to our employees like home office, flexible working time, meal benefits and more. More information about NXP in Austria... #LI-b6c8

Product Security Vulnerability Response Manager - Embedded & Semiconductor Security (m/f/d) at NXP Semiconductors — TalentDesi