MNC InsiderMNC Insider

Software Security Architect – Cyber Resilience Act (CRA) & Product Security (m/f/d)

NXP Semiconductors

Software Security Architect – Cyber Resilience Act (CRA) & Product Security (m/f/d)

full-timePosted: Aug 6, 2026Updated: Sep 1, 2026Gratkorn

Job Description

Join one of the world's largest industrial security organizations and help define the security foundations of products used by millions of people worldwide.At NXP's Competence Center Crypto & Security (CC C&S), security is at the core of everything we do. Our experts drive innovation from advanced security research and architecture to deployment in automotive, industrial, IoT, mobile, and edge processing solutions.We are looking for an experienced Software Security Architect to join our Software Security Architecture team and lead the strategic implementation of the European Cyber Resilience Act (CRA) across NXP's product portfolio.This is a highly visible role that combines security architecture, regulatory leadership, threat analysis, and cross-functional influence. You will have the opportunity to shape how security is embedded into products throughout their entire lifecycle while working alongside recognized experts in product security and secure system design.If you are passionate about secure embedded systems, product security, and driving industry-leading security practices, we would love to hear from you.As a Software Security Architect, you will play a key role in ensuring that NXP's products meet future security expectations while maintaining the highest standards of security engineering.You will:Define and drive the Cyber Resilience Act (CRA) compliance strategy for NXP's MCU and MPU product portfolios within the Security Arcitecture team.Influence security architecture decisions across multiple product lines and business units.Translate regulatory requirements into actionable security controls, architecture principles, and engineering requirements.Drive security-by-design methodologies across both legacy products and new product introductions (NPI).Lead system-level threat modeling, attack surface analysis, and security risk assessments for complex embedded and semiconductor-based products.Establish security requirements and ensure end-to-end traceability throughout the development lifecycle.Support audit readiness through security evidence generation, compliance documentation, and risk management activities.Collaborate with product architects, engineering teams, product management, compliance experts, and senior stakeholders worldwide.Drive adoption of security best practices, frameworks, and standards across NXP's product portfolio.You have:Bachelor's, Master's, or PhD degree in Computer Science, Cybersecurity, Information Security, Software Engineering, Electrical Engineering, Computer Engineering, Embedded Systems, or a related technical field.Strong experience in embedded systems security and software and/or hardware security architecture.Proven expertise in threat modeling, secure system design, and security risk assessment.Deep understanding of security technologies such as: Secure BootCryptography and Key ManagementFirmware ProtectionDevice Identity and Root of TrustSecure Update MechanismsExperience translating security requirements into practical technical architectures and implementations.Strong analytical skills with a system-level view of security challenges.Excellent stakeholder management and communication skills.Ability to drive security initiatives across global and cross-functional teams.Experience in one or more of the following areas is highly desirable:Security architecture for embedded, IoT, automotive, or industrial systems.Security certification frameworks such as: PSA CertifiedSESIPCommon CriteriaProduct security regulations and compliance frameworks.Cyber Resilience Act (CRA) implementation or preparation activities.Secure development lifecycle (SDL) practices.Security assessments, penetration testing, or vulnerability analysis.Secure hardware/software co-design.Please note: The successful candidate may/will be responsible for security related tasks. The assignment may/will be in scope of security certifications, therefore a conscious and reliable way of working is necessary.For applications in Gratkorn: NXP provides market competitive compensation according to the benchmarking of the electronic and semiconductor industry. Due to the Austrian Equal Treatment Act we are obligated to state the employment group of our applicable collective bargaining agreement (CBA) “Kollektivvertrag für Angestellte Gewerbe und Handwerk und in der Dienstleistung“, this position (fulltime) is graded in Employment Group V after 6 years. Your individual experiences and expectations will be considered in the application process. Moreover, we provide attractive benefits to our employees like home office, flexible working time, meal benefits and more.More information about NXP in Austria...#LI-a8a1

Locations

  • Gratkorn
  • Bucharest
  • Glasgow

Skills Required

  • embedded systems securityintermediate
  • threat modelingintermediate
  • oneintermediate

Required Qualifications

  • Bachelor's, Master's, or PhD degree in Computer Science, Cybersecurity, Information Security, Software Engineering, Electrical Engineering, Computer Engineering, Embedded Systems, or a related technical field. (degree in phd degree in computer science)
  • Strong experience in embedded systems security and software and/or hardware security architecture. (experience)
  • Proven expertise in threat modeling, secure system design, and security risk assessment. (experience)
  • Deep understanding of security technologies such as: Secure BootCryptography and Key ManagementFirmware ProtectionDevice Identity and Root of TrustSecure Update Mechanisms (experience)
  • Experience translating security requirements into practical technical architectures and implementations. (experience)
  • Strong analytical skills with a system-level view of security challenges. (experience)
  • Excellent stakeholder management and communication skills. (experience)
  • Ability to drive security initiatives across global and cross-functional teams. (experience)
  • Bachelor's, Master's, or PhD degree in Computer Science, Cybersecurity, Information Security, Software Engineering, Electrical Engineering, Computer Engineering, Embedded Systems, or a related technical field. (degree in phd degree in computer science)
  • Strong experience in embedded systems security and software and/or hardware security architecture. (experience)
  • Proven expertise in threat modeling, secure system design, and security risk assessment. (experience)
  • Deep understanding of security technologies such as: (experience)
  • Cryptography and Key Management (experience)
  • Firmware Protection (experience)
  • Device Identity and Root of Trust (experience)
  • Secure Update Mechanisms (experience)
  • Experience translating security requirements into practical technical architectures and implementations. (experience)
  • Strong analytical skills with a system-level view of security challenges. (experience)
  • Excellent stakeholder management and communication skills. (experience)
  • Ability to drive security initiatives across global and cross-functional teams. (experience)
  • Experience in one or more of the following areas is highly desirable: (experience)
  • Security architecture for embedded, IoT, automotive, or industrial systems. (experience)
  • Security certification frameworks such as: PSA CertifiedSESIPCommon Criteria (certification)
  • Product security regulations and compliance frameworks. (experience)
  • Cyber Resilience Act (CRA) implementation or preparation activities. (experience)
  • Secure development lifecycle (SDL) practices. (experience)
  • Security assessments, penetration testing, or vulnerability analysis. (experience)
  • Secure hardware/software co-design. (experience)
  • Security architecture for embedded, IoT, automotive, or industrial systems. (experience)
  • Security certification frameworks such as: (certification)
  • Product security regulations and compliance frameworks. (experience)
  • Cyber Resilience Act (CRA) implementation or preparation activities. (experience)
  • Secure development lifecycle (SDL) practices. (experience)
  • Security assessments, penetration testing, or vulnerability analysis. (experience)
  • Secure hardware/software co-design. (experience)
  • Please note: The successful candidate may/will be responsible for security related tasks. The assignment may/will be in scope of security certifications, therefore a conscious and reliable way of working is necessary. (certification)
  • More information about NXP in Austria... (experience)

Responsibilities

  • Define and drive the Cyber Resilience Act (CRA) compliance strategy for NXP's MCU and MPU product portfolios within the Security Arcitecture team.
  • Influence security architecture decisions across multiple product lines and business units.
  • Translate regulatory requirements into actionable security controls, architecture principles, and engineering requirements.
  • Drive security-by-design methodologies across both legacy products and new product introductions (NPI).
  • Lead system-level threat modeling, attack surface analysis, and security risk assessments for complex embedded and semiconductor-based products.
  • Establish security requirements and ensure end-to-end traceability throughout the development lifecycle.
  • Support audit readiness through security evidence generation, compliance documentation, and risk management activities.
  • Collaborate with product architects, engineering teams, product management, compliance experts, and senior stakeholders worldwide.
  • Drive adoption of security best practices, frameworks, and standards across NXP's product portfolio.
  • Define and drive the Cyber Resilience Act (CRA) compliance strategy for NXP's MCU and MPU product portfolios within the Security Arcitecture team.
  • Influence security architecture decisions across multiple product lines and business units.
  • Translate regulatory requirements into actionable security controls, architecture principles, and engineering requirements.
  • Drive security-by-design methodologies across both legacy products and new product introductions (NPI).
  • Lead system-level threat modeling, attack surface analysis, and security risk assessments for complex embedded and semiconductor-based products.
  • Establish security requirements and ensure end-to-end traceability throughout the development lifecycle.
  • Support audit readiness through security evidence generation, compliance documentation, and risk management activities.
  • Collaborate with product architects, engineering teams, product management, compliance experts, and senior stakeholders worldwide.
  • Drive adoption of security best practices, frameworks, and standards across NXP's product portfolio.

Target Your Resume for "Software Security Architect – Cyber Resilience Act (CRA) & Product Security (m/f/d)" , NXP Semiconductors

Get personalized recommendations to optimize your resume specifically for Software Security Architect – Cyber Resilience Act (CRA) & Product Security (m/f/d). Takes only 15 seconds!

AI-powered keyword optimization
Skills matching & gap analysis
Experience alignment suggestions

Check Your ATS Score for "Software Security Architect – Cyber Resilience Act (CRA) & Product Security (m/f/d)" , NXP Semiconductors

Find out how well your resume matches this job's requirements. Get comprehensive analysis including ATS compatibility, keyword matching, skill gaps, and personalized recommendations.

ATS compatibility check
Keyword optimization analysis
Skill matching & gap identification
Format & readability score

Tags & Categories

GeneralGeneral

Answer 10 quick questions to check your fit for Software Security Architect – Cyber Resilience Act (CRA) & Product Security (m/f/d) @ NXP Semiconductors.

Quiz Challenge
10 Questions
~2 Minutes
Instant Score

Related Books and Jobs

No related jobs found at the moment.