Software Security Architect - CRA (m/f/d)
Summary
Designs and reviews secure software architectures for embedded systems at NXP, ensuring compliance with cybersecurity standards like the Cyber Resilience Act while collaborating with global teams.
Join one of the largest industrial security teams and build technology that protects real devices, worldwide.
At NXP’s Competence Center Crypto & Security, we design, build, and deliver end-to-end security — from innovation to architecture to products in the field.
If you’re a security engineer who wants impact, on real life security solutions, we’d love to hear from you.
Our Chief Technology Office (CTO) organization drives innovation across NXP and supports Business Units with the tools, knowledge, and processes required to create secure products for our customers. The Security Architecture Team within the Competence Center Crypto & Security (CC C&S) plays a key role in enabling secure products across the Automotive, Industrial, IoT, Mobile, and Edge Processing markets.
Your Role
Join our team and support product development teams in gathering requirements, specifying, designing, reviewing, verifying, and implementing security solutions for NXP products.
As a Software Security Architect, you will help ensure that security is built into products throughout their entire lifecycle. You will collaborate with product teams, security experts, and stakeholders across the company to develop robust security architectures, assess security risks, and support compliance with relevant cybersecurity standards and regulations, including the Cyber Resilience Act (CRA).
Your Responsibilities
- Specify, design, review, and evolve system software security architectures and implementations.
- Conduct threat analysis, attack surface analysis, and security risk assessments for embedded systems and software platforms.
- Define security requirements and establish traceability from security objectives to implementation and verification activities.
- Integrate security-by-design principles throughout the complete product lifecycle.
- Support secure development lifecycle (SDL) activities, including architecture reviews, security assessments, and security verification.
- Analyze security vulnerabilities and defects, perform root cause analysis, and define appropriate mitigations and countermeasures.
- Define and review security mechanisms such as secure boot, secure update, cryptographic services, key management, device identity, and root-of-trust solutions.
- Translate cybersecurity standards, regulatory requirements, and industry best practices into practical engineering requirements and architectures.
- Support compliance activities related to product security regulations and standards, including the Cyber Resilience Act (CRA), through security documentation, evidence generation, and risk management activities.
- Drive adoption of security best practices across project teams and product lines.
- Serve as a technical interface to customers, evaluation labs, compliance experts, and product development teams.
- Contribute to the continuous improvement of NXP's product security methodologies, frameworks, and processes.
Your Profile
- Master's degree, PhD, or equivalent experience in Computer Science, Cybersecurity, Software Engineering, Electronics, Mathematics, or a related technical field.
- Strong background in cybersecurity and software security architecture.
- Extensive experience in embedded software development using C, Rust, and/or assembly language.
- Strong understanding of SoC software stacks, middleware, firmware, operating systems, and applications.
- Experience with threat modelling, security risk assessment, and secure system design.
- Familiarity with security technologies such as:
- Secure Boot
- Cryptography and Key Management
- Device Identity and Root of Trust
- Firmware Protection
- Secure Update Mechanisms
- Familiarity with cybersecurity regulations, standards, and certification schemes applicable to embedded and connected products.
- Strong analytical skills and ability to address complex system-level security challenges.
- Experience or interest in AI security is a plus.
- Independent working style with a willingness to listen, learn, and adapt.
- Excellent communication and stakeholder management skills.
- Strong team player with the ability to work effectively in global and cross-functional environments.
Preferred Qualifications
Experience in one or more of the following areas is highly desirable:
- Security architecture for automotive, industrial, or IoT products.
- Product security regulations and compliance frameworks, including the Cyber Resilience Act (CRA).
- Secure Development Lifecycle (SDL) practices.
- Security certification frameworks such as PSA Certified, SESIP, or Common Criteria.
- Vulnerability management, penetration testing, or security assessments.
- Hardware/software security co-design.
- Artificial Intelligence and AI security.
Creating Secure Connections and Infrastructure for a Smarter World
NXP Semiconductors N.V. (NASDAQ: NXPI) makes products and environments safer, more sustainable, and more secure with innovative connectivity and edge processing solutions for a smarter world.
We are in the business of better. Not just better technologies, but better innovations to improve society. As the world leader in secure connectivity and processing solutions for embedded applications, NXP is solving the world’s most complex technology challenges to accelerate business innovation, enhance how we work, and advance how we live.
Ready to create a smarter world? Visit our career website and follow us on social: LinkedIn, Facebook, and X.
To learn more bout our products visit our showroom here.
Please note: The successful candidate may/will be responsible for security related tasks. The assignment may/will be in scope of security certifications, therefore a conscious and reliable way of working is necessary.
For applications in Gratkorn: NXP provides market competitive compensation according to the benchmarking of the electronic and semiconductor industry. Due to the Austrian Equal Treatment Act we are obligated to state the employment group of our applicable collective bargaining agreement (CBA) “Kollektivvertrag für Angestellte Gewerbe und Handwerk und in der Dienstleistung“, this position (fulltime) is graded in Employment Group V after 6 years. Your individual experiences and expectations will be considered in the application process. Moreover, we provide attractive benefits to our employees like home office, flexible working time, meal benefits and more.
#LI-a8a1