обновлено 11 дней назад
Software Security Architect (CRA)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Software Security Architect (CRA) (Embedded Cybersecurity): Designing and reviewing end-to-end security architectures for NXP embedded products with an accent on threat analysis, secure development, compliance, and security-by-design. Focus on building secure boot, secure update, cryptographic, device identity, and root-of-trust solutions while addressing complex system-level risks and Cyber Resilience Act requirements.
Location: Gratkorn, Austria; home office and flexible working time are provided.
Company
develops secure connectivity and edge processing solutions for embedded applications across automotive, industrial, IoT, mobile, and edge processing markets.
What you will do
- Specify, design, review, and evolve system software security architectures and implementations.
- Conduct threat analysis, attack surface analysis, and security risk assessments for embedded systems and software platforms.
- Define security requirements and maintain traceability through implementation and verification.
- Integrate security-by-design and secure development lifecycle practices throughout the product lifecycle.
- Design and review secure boot, secure update, cryptographic services, key management, device identity, firmware protection, and root-of-trust mechanisms.
- Support Cyber Resilience Act compliance through security documentation, evidence generation, risk management, and collaboration with customers, evaluation labs, and product teams.
Requirements
- Master’s degree, PhD, or equivalent experience in computer science, cybersecurity, software engineering, electronics, mathematics, or a related technical field.
- Strong cybersecurity and software security architecture background, including threat modelling, risk assessment, and secure system design.
- Extensive embedded software development experience with C, Rust, and/or assembly language.
- Strong understanding of SoC software stacks, middleware, firmware, operating systems, and applications.
- Knowledge of cybersecurity regulations, standards, certification schemes, and the Cyber Resilience Act for embedded and connected products.
- Excellent analytical, communication, stakeholder management, and cross-functional collaboration skills.
Nice to have
- Experience with automotive, industrial, or IoT product security architecture.
- Experience with Secure Development Lifecycle practices, PSA Certified, SESIP, or Common Criteria.
- Experience in vulnerability management, penetration testing, security assessments, or hardware/software security co-design.
- Experience or interest in artificial intelligence and AI security.
Culture & Benefits
- Work within a large industrial security team and a global, cross-functional environment.
- Flexible working time and home office options.
- Meal benefits and other employee benefits.
- Competitive compensation benchmarked against the Austrian electronics and semiconductor industry.
- Employment is covered by the Austrian collective bargaining agreement, with the position graded in Employment Group V after six years.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →