Job
- Level
- Experienced
- Job Field
- IT, Security, Test/QA
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Location
- Gratkorn
- Working Model
- Hybrid, Onsite
Job Summary
In this role, you are responsible for managing vulnerabilities in third-party components, developing best practices, and conducting risk assessments and incident management processes to ensure product security.
Job Technologies
Your role in the team
- Empower our software development community in managing vulnerabilities in Third Party Components (TPS) and Open Source Software (OSS), ensuring robust security.
- Define and develop best practices, streamline processes, and drive continuous improvement initiatives.
- Contribute to new regulations and standardization activities that may impact product security or our way of working such as the upcoming EU Cyber Resilience Act.
- Collaborate with innovators - partner with external security researchers, academia, and research organizations on cutting-edge projects and vulnerability submissions.
- Be a key player in risk management by supporting and leading triage and vulnerability assessments of product vulnerabilities.
- Work cross-functionally with internal teams (engineering, product management, legal, etc.) to ensure timely resolution of incidents.
- Own the process by generating and managing PSIRT JIRA tickets for validated vulnerabilities.
- Provide updates about incident status, impact, and mitigation actions to relevant stakeholders.
- Manage incoming Third Party vendor vulnerability pre-notifications and monitor internal and external sources to identify signs of security incidents related to our products.
This text has been machine translated. Show original
Our expectations of you
Education
- Bachelor's/master's degree in engineering - Computer Science, Electrical Engineering, Cybersecurity, or a related field.
Qualifications
- Vertrautheit mit einem Security Operations Center oder PSIRT oder ähnlichen Teams für Sicherheitsvorfallreaktionen.
- Familiarity with industry-standard security frameworks, standards, and regulations.
- Understanding of security in the following areas - embedded systems, hardware and software; ability to quickly learn where needed.
- Interests in security concepts, secure coding, and security best practices.
- Excellent collaboration and communication skills to work effectively with cross-functional teams.
- Ability to work independently, taking ownership of security initiatives and improving processes.
Experience
- 3+ years of experience in product security incident response, investigation and vulnerability management across hardware and software products.
This text has been machine translated. Show original
What we offer
- The successful candidate may/will be responsible for security related tasks.
- The assignment may/will be in scope of security certifications, therefore a conscious and reliable way of working is necessary.
- For Austrian applicants: NXP provides market competitive compensation according to the benchmarking of the electronic and semiconductor industry.
- Due to the Austrian Equal Treatment Act, we are obligated to state the employment group of our applicable collective bargaining agreement (CBA) "Kollektivvertrag für Angestellte Gewerbe und Handwerk und in der Dienstleistung." This position (full-time) is graded in Employment Group V.
- Your individual experiences and expectations will be considered in the application process.
- Moreover, we provide attractive benefits to our employees such as home office, flexible working hours, meal benefits, and more.
This text has been machine translated. Show original
Benefits
Work-Life-Integration
Food & Drink
More net
Health, Fitness & Fun
Topics that you deal with on the job
Job Locations
This is your employer
NXP Semiconductors Austria
Gratkorn
NXP Semiconductors is a global leader in microelectronics with subsidiaries in more than 25 countries. The Gratkorn site near Graz is the Austrian headquarters of the international group and the competence center for secure contactless identification systems.
Description
- Founding year
- 2006
- Language
- English
- Company Type
- Established Company
- Working Model
- Full Remote, Hybrid, Onsite
- Industry
- Industry, Production
Dev Reviews
by devworkplaces.com
Total
(2 Reviews)3.7
Culture
3.7Engineering
3.4Career Growth
3.5Workingconditions
4.2