Product Security Vulnerability Response Manager - Embedded & Semiconductor Security (m/f/d)
Help protect technology that powers millions of devices worldwide.
As a member of NXP's Product Security Incident Response Team (PSIRT), you will play a key role in safeguarding our secure chip products after they have been deployed to customers around the globe.
Acting as the central point of coordination for product security incidents, you will work closely with engineering teams, customers, and security researchers to investigate vulnerabilities, assess risks, coordinate remediation efforts, and communicate security guidance. You will drive security issues from initial reporting through resolution and responsible disclosure, helping ensure that customers can continue to trust the products they rely on every day.
This is not a purely hands-on engineering role. Instead, it offers a unique blend of product security, incident response, stakeholder management, and technical leadership. Success in this position comes from your ability to bring together experts from different disciplines, navigate complex security challenges, and drive solutions to completion.
Our PSIRT team is dedicated to rapidly addressing security threats affecting NXP products worldwide. By investigating reported vulnerabilities, evaluating their impact, and providing timely and actionable guidance to customers, we help protect products throughout their lifecycle and maintain the trust that customers place in NXP.
If you enjoy leading security investigations, coordinating across diverse stakeholders, and making a visible impact on the security of products used by millions of people worldwide, we'd love to hear from you.
See also www.nxp.com/psirt.
Ideally, you bring hands-on experience in product, embedded, or hardware security and possess a solid understanding of how attackers target semiconductor devices and embedded systems. You are familiar with common attack techniques and can help assess their potential impact on NXP products.
What you'll do: A snapshot of your key responsibilities and impact.
Lead the response and coordination of security vulnerabilities affecting NXP products, hardware and software.
Drive vulnerability triage, impact assessment, severity classification, and prioritization.
Collaborate with engineering and product teams to develop mitigation strategies and remediation plans.
Coordinate responsible disclosure activities with external researchers, customers, and industry partners.
Oversee security advisories, CVE processes, and customer communications.
Act as a trusted advisor to product teams on vulnerability management and product security best practices.
Continuously improve PSIRT processes, metrics, and operational excellence.
What you'll bring
Experience in Product Security, Embedded Security, Semiconductor Security, Cybersecurity, or Secure Product Development.
Strong understanding of vulnerability management, coordinated disclosure, incident handling, or product risk management.
Ability to influence cross-functional stakeholders across engineering, product management, quality, and customer-facing teams.
Excellent communication skills and a passion for protecting innovative technology at scale.
Understand Threats. Protect Products. Protect Customers. Lead Response. Reduce Risk. Build Trust. Drive Security. Create Impact. Shape Tomorrow.
For Austrian applicants: NXP provides market competitive compensation according to the benchmarking of the electronic and semiconductor industry. Due to the Austrian Equal Treatment Act we are obligated to state the employment group of our applicable collective bargaining agreement (CBA) “Kollektivvertrag für Angestellte Gewerbe und Handwerk und in der Dienstleistung“, this position (fulltime) is graded in Employment Group V. Your individual experiences and expectations will be considered in the application process. Moreover, we provide attractive benefits to our employees like home office, flexible working time, meal benefits and more.
#LI-b6c8