Software Security Architect – Cyber Resilience Act (CRA) & Product Security (m/f/d)

NXP Semiconductors

Glasgow

On-site

GBP 70,000 - 90,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Home office
Flexible working time
Meal benefits

Job summary

NXP Semiconductors in Glasgow is seeking a Software Security Architect to drive Cyber Resilience Act compliance across its product portfolio. This role requires both strategic leadership and hands-on technical capabilities in security architecture and threat analysis.

The ideal candidate will have a strong background in embedded systems security and proven experience with threat modeling and security technologies. This full-time position includes competitive compensation and benefits such as flexible working hours and meal benefits.

Qualifications

  • Strong background in Embedded systems security.
  • Proven experience with threat modeling methodologies and security technologies.
  • Familiarity with security certification frameworks.

Responsibilities

  • Define and drive CRA compliance strategy for product portfolios.
  • Ensure alignment with upcoming mandatory CRA requirements.
  • Translate regulatory requirements into practical security controls.

Skills

Embedded systems security
Software security architecture
Threat modeling methodologies
Stakeholder management
Cross-functional collaboration

Tools

Secure boot
Cryptography
Firmware protection

Job description

Join one of the world’s largest industrial security teams — and build technology that protects real devices worldwide.

At NXP’s Competence Center Crypto & Security (CC C&S), we design, build, and deliver end-to-end security — from early innovation to architecture to products in the field.

If you're a security engineer who wants to create real-world impact, we’d love to hear from you.

We are seeking an experienced Software Security Architect to join our Software Security Architecture team within CCC&S. In this role, you will take a leading position in driving Cyber Resilience Act (CRA) readiness across our product portfolio, ensuring compliance with upcoming mandatory regulatory requirements.

This role combines strategic ownership and hands‑on technical expertise at the intersection of product security architecture, regulatory compliance, and system‑level threat analysis. You will support both legacy product lines and new product introductions (NPI), embedding security‑by‑design principles and ensuring lifecycle compliance across all development stages.

Your Responsibilities
  • Define and drive the CRA compliance strategy for MCU and MPU product portfolios through the central security architecture team.
  • Ensure alignment with upcoming mandatory CRA requirements (target: 2027).
  • Translate regulatory requirements into practical security controls, design principles, and architecture guidelines.
  • Support audit readiness (compliance documentation, security evidence generation, and end‑to‑end traceability of requirements).
  • Define, implement, and maintain robust security architectures across Legacy products & New Product Introductions (NPI).
  • Ensure consistent application of security standards, methodologies, and best practices across product lines.
  • Collaborate with cross‑functional teams (engineering, product management, compliance) to embed security into development processes.
  • Lead and conduct system‑level threat modeling and threat analysis (hardware and software).
  • Perform security risk assessments aligned with CRA expectations and industry standards.
Your profile
  • Strong background in Embedded systems security, Software and/or hardware security architecture.
  • Proven experience with threat modeling methodologies and security technologies such as secure boot, cryptography, firmware protection.
  • Familiarity with security certification frameworks, such as PSA, SESIP, Common Criteria.
  • Experience with or strong interest in Cyber Resilience Act (CRA), product security regulations and standards, compliance‑driven development and documentation.
  • Ability to translate regulatory requirements into technical implementation.
  • Strong analytical and system‑level thinking.
  • Excellent stakeholder management and cross‑functional collaboration skills.
  • Comfortable working in a global, matrixed organization with diverse product teams.

The successful candidate may/will be responsible for security‑related tasks. The assignment may/will be in scope of security certifications, therefore a conscious and reliable way of working is necessary.

For applications in Gratkorn: NXP provides market‑competitive compensation according to the benchmarking of the electronic and semiconductor industry. Due to the Austrian Equal Treatment Act we are obligated to state the employment group of our applicable collective bargaining agreement (CBA) “Kollektivvertrag für Angestellte Gewerbe und Handwerk und in der Dienstleistung”, this position (fulltime) is graded in Employment Group V after 6 years. Your individual experiences and expectations will be considered in the application process. Moreover, we provide attractive benefits to our employees like home office, flexible working time, meal benefits and more.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Security Architect - AI (m/f/d)
Software Security Architect - AI (m/f/d)

NXP Semiconductors • Glasgow

Hybrid
GBP 76,000 - 112,000
Home office
Flexible working hours
Meal benefits
Software Security Architect - CRA (m/f/d)
Software Security Architect - CRA (m/f/d)

NXP Semiconductors • Glasgow

On-site
GBP 76,000 - 103,000
Home office
Flexible working time
Meal benefits
Senior System Security Architect (m/f/d)
Senior System Security Architect (m/f/d)

NXP Semiconductors • Glasgow

Hybrid
GBP 76,000 - 103,000
Home office
Flexible working time
Meal benefits
Principal Embedded Crypto Software Developer (m/f/d)
Principal Embedded Crypto Software Developer (m/f/d)

NXP Semiconductors • Glasgow

On-site
GBP 70,000 - 90,000
Flexible working time
Meal benefits
Home office options
Software Security Architect (m/f/d)
Software Security Architect (m/f/d)

NXP Semiconductors • Glasgow

On-site
GBP 77,000 - 103,000
Home office
Flexible working time
Meal benefits
+1
Product Security Vulnerability Response Manager - Embedded & Semiconductor Security (m/f/d)
Product Security Vulnerability Response Manager - Embedded & Semiconductor Security (m/f/d)

NXP Semiconductors • Glasgow

On-site
GBP 70,000 - 120,000
Home office
Flexible working time
Meal benefits
Principal Product Security Certification Expert (m/f/d)
Principal Product Security Certification Expert (m/f/d)

NXP Semiconductors • Glasgow

On-site
GBP 60,000 - 80,000
Flexible working hours
Meal benefits
Embedded Software Security Architect for CRA Readiness
Embedded Software Security Architect for CRA Readiness

NXP Semiconductors • Glasgow

On-site
GBP 70,000 - 90,000
Home office
Flexible working time
Meal benefits
Senior Security Architect: Embedded Systems & AI (Home Office)
Senior Security Architect: Embedded Systems & AI (Home Office)

NXP Semiconductors • Glasgow

Hybrid
GBP 76,000 - 103,000
Home office
Flexible working time
Meal benefits
Junior Embedded AI Platform Security Engineer (m/f/d)
Junior Embedded AI Platform Security Engineer (m/f/d)

NXP Semiconductors • Glasgow

Hybrid
GBP 70,000 - 100,000