Назад
Company hidden
10 часов назад

Manager - Product Security (Cybersecurity)

Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Manager - Product Security (Cybersecurity): Establishing and governing product security frameworks, vulnerability management, threat modeling, and regulatory readiness across semiconductor products with an accent on embedded systems, PSIRT processes, and global cybersecurity standards. Focus on translating regulations into engineering requirements, coordinating cross-functional security initiatives, and strengthening governance for firmware, software, hardware, and supply chain security.

Location: Chandler, Arizona, United States

Company

hirify.global is a global semiconductor company developing products for automotive, industrial automation, aerospace, medical devices, and Internet of Things applications.

What you will do

  • Define and deploy product security governance frameworks across business units.
  • Establish processes for product risk classification, threat modeling, security checkpoints, and regulatory readiness.
  • Govern PSIRT and vulnerability management, including intake, triage, remediation, disclosure, CVE processes, and reporting.
  • Develop threat modeling templates, risk libraries, assessment criteria, and enablement programs for security champions and engineering teams.
  • Monitor cybersecurity regulations and standards, including the EU Cyber Resilience Act, IEC 62443, ISO 21434, OWASP, STRIDE, MITRE ATT&CK, and EMB3D.
  • Coordinate with engineering, quality, legal, compliance, customer support, business units, standards bodies, certification labs, and external partners.

Requirements

  • Bachelor’s or master’s degree in electrical engineering, computer science, cybersecurity, embedded systems, or a related field.
  • 12.5+ years of experience in cybersecurity, product security, embedded security, semiconductor security, or related technical disciplines.
  • 5+ years of experience in product security governance, secure development lifecycle, security program management, or regulatory readiness.
  • 3+ years in a leadership or senior role driving cross-functional security initiatives across multiple teams or business units.
  • Strong understanding of embedded systems, semiconductor products, firmware, software, hardware security, cryptography, and product lifecycle processes.
  • Experience translating regulatory, customer, and standards requirements into practical engineering and governance processes.

Nice to have

  • Experience in semiconductor, embedded systems, industrial automation, automotive, IoT, medical, or security certification domains.
  • Experience with threat modeling tools, SBOM tooling, CVE processes, CNA operations, vulnerability databases, and open-source vulnerability monitoring.
  • Experience participating in standards bodies, working groups, industry associations, or regulatory consultations.
  • Experience working with notified bodies, cybersecurity labs, certification bodies, or external assessors.
  • Program management experience with KPI dashboards, governance cadences, execution tracking, and maturity models.

Culture & Benefits

  • Full-time employment within a 17,000-member global organization.
  • Regular business hours with approximately 0–25% travel.
  • Work involves collaboration across global business units and executive stakeholders.
  • Physical activities include sitting, standing, walking, working alone, and working around others.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →