Product Security Vulnerability Response Manager - Embedded & Semiconductor Security (m/f/d)

NXP Semiconductors

Glasgow

On-site

GBP 70,000 - 120,000

Full time

36 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Home office
Flexible working time
Meal benefits

Job summary

NXP Semiconductors in the United Kingdom is seeking a Product Security Incident Response professional to lead end-to-end vulnerability management for deployed products. You will coordinate triage, risk assessment, and remediation with engineering, product teams and external researchers.

You will influence cross-functional partners, communicate advisories, and drive best practices to protect customers and maintain trust throughout the product lifecycle.

Qualifications

  • Experience in Product Security, Embedded Security, Semiconductor Security, Cybersecurity, or Secure Product Development.
  • Strong understanding of vulnerability management, coordinated disclosure, incident handling, or product risk management.
  • Ability to influence cross-functional stakeholders across engineering, product management, quality, and customer-facing teams.

Responsibilities

  • Lead the response and coordination of security vulnerabilities affecting NXP products, hardware and software.
  • Drive vulnerability triage, impact assessment, severity classification, and prioritization.
  • Collaborate with engineering and product teams to develop mitigation strategies and remediation plans.
  • Coordinate responsible disclosure activities with external researchers, customers, and industry partners.
  • Oversee security advisories, CVE processes, and customer communications.
  • Act as a trusted advisor to product teams on vulnerability management and product security best practices.
  • Continuously improve PSIRT processes, metrics, and operational excellence.

Skills

Product Security
Embedded Security
Semiconductor Security
Cybersecurity
Secure Product Development

Job description

This role is about ensuring the resilience NXP products (Secure Chips rather then IT Systems) who are are embedded in millions of automotive, industrial, IoT, mobile, and edge devices.

In this role, you will help protect products already deployed in the field, leading the response to security vulnerabilities, coordinating mitigation strategies, and strengthening customer trust throughout the post-production product lifecycle.

Working at the intersection of Product Security, Engineering, R&D, Customers, and External Security Researchers, you will drive the end-to-end lifecycle of vulnerability management, from initial disclosure through risk assessment, mitigation, and customer communication.

As a key member of NXP's Product Security Incident Response Team (PSIRT), you will lead the end-to-end response to security issues affecting NXP products already deployed worldwide. Partnering with engineering teams, customers, and security researchers, you will assess risk, coordinate remediation efforts, manage responsible disclosure, and help safeguard customer trust throughout the product lifecycle.

Our PSIRT is committed to rapidly addressing security threats in NXP products by investigating reported issues, evaluating their potential impact, and providing customers with timely and actionable guidance.

See also www.nxp.com/psirt.

Ideally, you bring hands-on experience in product, embedded, or hardware security and possess a solid understanding of how attackers target semiconductor devices and embedded systems. You are familiar with common attack techniques and can help assess their potential impact on NXP products.

What you'll do:

A snapshot of your key responsibilities and impact.

  • Lead the response and coordination of security vulnerabilities affecting NXP products, hardware and software.
  • Drive vulnerability triage, impact assessment, severity classification, and prioritization.
  • Collaborate with engineering and product teams to develop mitigation strategies and remediation plans.
  • Coordinate responsible disclosure activities with external researchers, customers, and industry partners.
  • Oversee security advisories, CVE processes, and customer communications.
  • Act as a trusted advisor to product teams on vulnerability management and product security best practices.
  • Continuously improve PSIRT processes, metrics, and operational excellence.
What You'll Bring
  • Experience in Product Security, Embedded Security, Semiconductor Security, Cybersecurity, or Secure Product Development.
  • Strong understanding of vulnerability management, coordinated disclosure, incident handling, or product risk management.
  • Ability to influence cross-functional stakeholders across engineering, product management, quality, and customer-facing teams.
  • Excellent communication skills and a passion for protecting innovative technology at scale.

Understand Threats. Protect Products. Protect Customers. Lead Response. Reduce Risk. Build Trust. Drive Security. Create Impact. Shape Tomorrow.

For Austrian applicants: NXP provides market competitive compensation according to the benchmarking of the electronic and semiconductor industry. Due to the Austrian Equal Treatment Act we are obligated to state the employment group of our applicable collective bargaining agreement (CBA) "Kollektivvertrag für Angestellte Gewerbe und Handwerk und in der Dienstleistung", this position (fulltime) is graded in Employment Group V. Your individual experiences and expectations will be considered in the application process. Moreover, we provide attractive benefits to our employees like home office, flexible working time, meal benefits and more.

More information about NXP in Austria...

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Security Architect - AI (m/f/d)
Software Security Architect - AI (m/f/d)

NXP Semiconductors • Glasgow

Hybrid
GBP 76,000 - 112,000
Home office
Flexible working hours
Meal benefits
Senior System Security Architect (m/f/d)
Senior System Security Architect (m/f/d)

NXP Semiconductors • Glasgow

Hybrid
GBP 76,000 - 103,000
Home office
Flexible working time
Meal benefits
Principal Embedded Crypto Software Developer (m/f/d)
Principal Embedded Crypto Software Developer (m/f/d)

NXP Semiconductors • Glasgow

On-site
GBP 70,000 - 90,000
Flexible working time
Meal benefits
Home office options
Software Security Architect – Cyber Resilience Act (CRA) & Product Security (m/f/d)
Software Security Architect – Cyber Resilience Act (CRA) & Product Security (m/f/d)

NXP Semiconductors • Glasgow

On-site
GBP 70,000 - 90,000
Home office
Flexible working time
Meal benefits
Software Security Architect - CRA (m/f/d)
Software Security Architect - CRA (m/f/d)

NXP Semiconductors • Glasgow

On-site
GBP 76,000 - 103,000
Home office
Flexible working time
Meal benefits
Principal Product Security Certification Expert (m/f/d)
Principal Product Security Certification Expert (m/f/d)

NXP Semiconductors • Glasgow

On-site
GBP 60,000 - 80,000
Flexible working hours
Meal benefits
Junior Embedded AI Platform Security Engineer (m/f/d)
Junior Embedded AI Platform Security Engineer (m/f/d)

NXP Semiconductors • Glasgow

Hybrid
GBP 70,000 - 100,000
PSIRT Vulnerability Response Lead for Embedded Security
PSIRT Vulnerability Response Lead for Embedded Security

NXP Semiconductors • Glasgow

On-site
GBP 70,000 - 120,000
Home office
Flexible working time
Meal benefits
Global Product Marketing Manager - Automotive MCUs
Global Product Marketing Manager - Automotive MCUs

NXP Semiconductors • Glasgow

On-site
GBP 90,000 - 120,000
Senior Security Architect: Embedded Systems & AI (Home Office)
Senior Security Architect: Embedded Systems & AI (Home Office)

NXP Semiconductors • Glasgow

Hybrid
GBP 76,000 - 103,000
Home office
Flexible working time
Meal benefits