Software Security Architect - AI
Glasgow, Scotland, United Kingdom · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 6 days ago
- Work mode
- In office
- Education
- Master's degree or equivalent
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
Join one of the largest teams specializing in industrial security to help develop technology that safeguards real-world devices globally. At NXP's Competence Center for Crypto & Security, the focus is on designing and delivering comprehensive security solutions, from innovation through architecture to deployed products.
If you are a security engineer seeking impactful work on practical security challenges, this role is an excellent opportunity.
About the Team
The Chief Technology Office (CTO) at NXP fosters innovation company-wide and supports business units by providing tools, knowledge, and procedures for building secure products. The Security Architecture Team within the Competence Center Crypto & Security (CC C&S) plays a crucial role in delivering secure solutions across diverse markets including Automotive, Industrial, IoT, Mobile, and Edge Processing.
Key Responsibilities
- Develop, specify, review, and refine system software security architectures and their implementations.
- Perform threat modeling, attack surface analyses, and evaluate security risks for embedded systems and software platforms.
- Define clear security requirements and ensure their traceability from goals through to implementation and validation.
- Embed security-by-design principles into each phase of the product development lifecycle.
- Engage in Secure Development Lifecycle (SDL) processes such as architecture reviews, security audits, and verifications.
- Identify, analyze, and mitigate security vulnerabilities, performing root cause investigations and determining effective countermeasures.
- Design and validate security mechanisms including secure boot, secure update, cryptographic services, key management, device identity solutions, and root-of-trust implementations.
- Translate cybersecurity standards and regulations, like the Cyber Resilience Act (CRA), into executable engineering requirements and architectures.
- Support regulatory compliance through generating security documentation, evidence collection, and active risk management.
- Promote widespread adoption of security best practices across different product teams and lines.
- Act as a technical liaison with customers, evaluation laboratories, compliance experts, and internal development teams.
- Contribute to continuous enhancements of NXP's security methodologies, frameworks, and procedural processes.
Candidate Profile
- A Master's degree, PhD, or equivalent experience in Computer Science, Cybersecurity, Software Engineering, Electronics, Mathematics, or a closely related technical domain.
- Demonstrable expertise in cybersecurity and software security architecture.
- Broad experience in embedded software development using languages such as C, Rust, and assembly.
- Essential experience in AI security.
- Comprehensive understanding of SoC software layers including middleware, firmware, operating systems, and applications.
- Skilled in threat modeling, security assessment methodologies, and secure system design.
- Proficiency with security technology concepts including Secure Boot, Cryptography and Key Management, Device Identity and Root of Trust, Firmware Protection, and Secure Update mechanisms.
- Familiarity with cybersecurity legislation, standards, and certification relevant to embedded and connected devices.
- Strong analytical capabilities for resolving intricate, system-level security problems.
- Ability to work independently while remaining open to learning and adaptability.
- Excellent communication skills and effectiveness in stakeholder engagement.
- Capability to function well within global, cross-functional teams.
Preferred Additional Qualifications
- Experience securing automotive, industrial, or IoT solutions through architectural design.
- Knowledge of product security regulations and compliance frameworks including the Cyber Resilience Act (CRA).
- Experience applying Secure Development Lifecycle (SDL) standards.
- Familiarity with certification frameworks such as PSA Certified, SESIP, or Common Criteria.
- Background in vulnerability management, security testing, or assessment efforts.
- Expertise in hardware/software co-design for security.
- Further experience in Artificial Intelligence and AI security domains.
Additional Information
NXP Semiconductors strives to create safer, sustainable, and secure connectivity and processing solutions for embedded systems worldwide. The role involves responsibility for security tasks possibly tied to security certifications, necessitating a conscientious and dependable approach to work.
For roles based in Gratkorn, Austria, compensation is competitive within the electronic and semiconductor industry standards. Employment falls under the Austrian Collective Bargaining Agreement “Kollektivvertrag für Angestellte Gewerbe und Handwerk und in der Dienstleistung” and is graded in Employment Group V after six years. Benefits include options for home office, flexible hours, meal vouchers, and more.
Minimum education
Master's Degree
Industry
Semiconductors