Software Security Architect - CRA (m/f/d)

NXP Semiconductors

Netherlands

On-site

EUR 110,000 - 140,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

NXP Semiconductors is seeking a Software Security Architect to drive secure architectures across embedded products. You will gather requirements, design, review, and implement security solutions for NXP products, and collaborate with product teams, security experts, and stakeholders to ensure lifecycle security and regulatory compliance.

The role emphasizes cryptographic services, root-of-trust, secure boot, and secure update mechanisms, with a strong focus on risk assessment and secure design

Qualifications

  • Master's degree, PhD, or equivalent experience in computer science, cybersecurity, software engineering, electronics, mathematics, or related field.
  • Strong background in cybersecurity and software security architecture.
  • Extensive experience in embedded software development using C, Rust, and/or assembly.
  • Knowledge of SoC software stacks, middleware, firmware, OS, and applications.
  • Experience with threat modelling, security risk assessment, and secure system design.
  • Familiarity with security technologies such as Secure Boot, cryptography, key management, device identity, root of trust, firmware protection, and secure update mechanisms.
  • Familiarity with cybersecurity regulations, standards, and certification schemes for embedded/connected products.

Responsibilities

  • Specify, design, review, and evolve system software security architectures and implementations.
  • Conduct threat analysis, attack surface analysis, and security risk assessments for embedded systems and software platforms.
  • Define security requirements and establish traceability from security objectives to implementation and verification activities.
  • Integrate security-by-design principles throughout the product lifecycle.
  • Support SDL activities, including architecture reviews, security assessments, and security verification.
  • Analyze vulnerabilities, perform root cause analysis, and define mitigations and countermeasures.
  • Define and review security mechanisms like secure boot, secure update, cryptographic services, key management, device identity, and root of trust.
  • Translate cybersecurity standards and regulations into practical engineering requirements.
  • Drive adoption of security best practices across project teams and product lines.
  • Serve as technical interface to customers, evaluation labs, compliance experts, and product teams.
  • Contribute to continuous improvement of product security methodologies, frameworks, and processes.

Skills

Cybersecurity
Software security
Embedded programming
Threat modelling
Security risk assessment
Secure design
Cryptography
Root of Trust
Communication & stakeholder mgmt

Education

Master's degree / PhD in CS or related

Tools

PSA Certified
SESIP
Common Criteria

Job description

Join one of the largest industrial security teams and build technology that protects real devices, worldwide. At NXP's Competence Center Crypto & Security, we design, build, and deliver end-to-end security - from innovation to architecture to products in the field. If you're a security engineer who wants impact, on real life security solutions, we'd love to hear from you. Our Chief Technology Office (CTO) organization drives innovation across NXP and supports Business Units with the tools, knowledge, and processes required to create secure products for our customers. The Security Architecture Team within the Competence Center Crypto & Security (CC C&S) plays a key role in enabling secure products across the Automotive, Industrial, IoT, Mobile, and Edge Processing markets.

Your Role

Join our team and support product development teams in gathering requirements, specifying, designing, reviewing, verifying, and implementing security solutions for NXP products. As a Software Security Architect, you will help ensure that security is built into products throughout their entire lifecycle. You will collaborate with product teams, security experts, and stakeholders across the company to develop robust security architectures, assess security risks, and support compliance with relevant cybersecurity standards and regulations, including the Cyber Resilience Act (CRA).

Your Responsibilities
  • Specify, design, review, and evolve system software security architectures and implementations.
  • Conduct threat analysis, attack surface analysis, and security risk assessments for embedded systems and software platforms.
  • Define security requirements and establish traceability from security objectives to implementation and verification activities.
  • Integrate security-by-design principles throughout the complete product lifecycle.
  • Support secure development lifecycle (SDL) activities, including architecture reviews, security assessments, and security verification.
  • Analyze security vulnerabilities and defects, perform root cause analysis, and define appropriate mitigations and countermeasures.
  • Define and review security mechanisms such as secure boot, secure update, cryptographic services, key management, device identity, and root-of-trust solutions.
  • Translate cybersecurity standards, regulatory requirements, and industry best practices into practical engineering requirements and architectures.
  • Support compliance activities related to product security regulations and standards, including the Cyber Resilience Act (CRA), through security documentation, evidence generation, and risk management activities.
  • Drive adoption of security best practices across project teams and product lines.
  • Serve as a technical interface to customers, evaluation labs, compliance experts, and product development teams.
  • Contribute to the continuous improvement of NXP's product security methodologies, frameworks, and processes.
Your Profile
  • Master's degree, PhD, or equivalent experience in Computer Science, Cybersecurity, Software Engineering, Electronics, Mathematics, or a related technical field.
  • Strong background in cybersecurity and software security architecture.
  • Extensive experience in embedded software development using C, Rust, and/or assembly language.
  • Strong understanding of SoC software stacks, middleware, firmware, operating systems, and applications.
  • Experience with threat modelling, security risk assessment, and secure system design.
  • Familiarity with security technologies such as: Secure Boot
  • Cryptography and Key Management
  • Device Identity and Root of Trust
  • Firmware Protection
  • Secure Update Mechanisms
  • Familiarity with cybersecurity regulations, standards, and certification schemes applicable to embedded and connected products.
  • Strong analytical skills and ability to address complex system-level security challenges.
  • Experience or interest in AI security is a plus.
  • Independent working style with a willingness to listen, learn, and adapt.
  • Excellent communication and stakeholder management skills.
  • Strong team player with the ability to work effectively in global and cross-functional environments.
Preferred Qualifications

Experience in one or more of the following areas is highly desirable:

  • Security architecture for automotive, industrial, or IoT products.
  • Product security regulations and compliance frameworks, including the Cyber Resilience Act (CRA).
  • Secure Development Lifecycle (SDL) practices.
  • Security certification frameworks such as PSA Certified, SESIP, or Common Criteria.
  • Vulnerability management, penetration testing, or security assessments.
  • Hardware/software security co-design.
  • Artificial Intelligence and AI security.
  • Creating Secure Connections and Infrastructure for a Smarter World

NXP Semiconductors N.V. (NASDAQ: NXPI) makes products and environments safer, more sustainable, and more secure with innovative connectivity and edge processing solutions for a smarter world.

We are in the business of better. Not just better technologies, but bet

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Security Architect - AI (m/f/d)
Software Security Architect - AI (m/f/d)

NXP Semiconductors • Netherlands

On-site
EUR 90,000 - 150,000
Senior Embedded Security Architect — Crypto & IoT
Senior Embedded Security Architect — Crypto & IoT

NXP Semiconductors • Netherlands

On-site
EUR 110,000 - 140,000
Embedded Security Architect: AI & Crypto for Safe Devices
Embedded Security Architect: AI & Crypto for Safe Devices

NXP Semiconductors • Netherlands

On-site
EUR 90,000 - 150,000
Senior System Security Architect (m/f/d)
Senior System Security Architect (m/f/d)

NXP Semiconductors • Netherlands

Hybrid
EUR 90,000 - 130,000
Home office
Flexible working hours
Meal benefits
End-to-End Embedded Security Architect for Industrial AI
End-to-End Embedded Security Architect for Industrial AI

NXP Semiconductors • Netherlands

Hybrid
EUR 90,000 - 130,000
Home office
Flexible working hours
Meal benefits
Systems Engineer (Architect)
Systems Engineer (Architect)

Synopsys Inc • Eindhoven

On-site
EUR 70,000 - 90,000
Comprehensive health benefits
Wellness programs
Financial incentives
Embedded Security Engineer & Vulnerability Researcher
Embedded Security Engineer & Vulnerability Researcher

NXP Semiconductors • Netherlands

On-site
EUR 70,000 - 90,000
System Engineer (RF and SerDes)
System Engineer (RF and SerDes)

NXP Semiconductors • Eindhoven

Hybrid
EUR 120,000 - 180,000
Junior System Engineer
Junior System Engineer

NXP Semiconductors • Eindhoven

On-site
EUR 60,000 - 90,000
Software Cybersecurity Architect – High-Tech Systems
Software Cybersecurity Architect – High-Tech Systems

Sioux • Eindhoven

Hybrid
EUR 95,000 - 135,000
Flexible hours 32-40 per week
Work from home option
Training budget €6000 per year
+1