Software Security Architect - CRA (m/f/d) in Glasgow

Software Security Architect - CRA (m/f/d) in Glasgow

Glasgow Full-Time 70000 - 90000 £ / year (est.) Home office (partial)
NXP Semiconductors

At a Glance

  • Tasks: Design and implement security solutions for innovative tech products.
  • Company: Join NXP, a leader in secure connectivity and processing solutions.
  • Benefits: Enjoy flexible working hours, home office options, and competitive compensation.
  • Other info: Collaborative environment with opportunities for continuous learning and growth.
  • Why this job: Make a real impact on global security solutions and technology.
  • Qualifications: Master's degree or equivalent experience in relevant technical fields.

The predicted salary is between 70000 - 90000 £ per year.

Join one of the largest industrial security teams and build technology that protects real devices, worldwide. At NXP’s Competence Center Crypto & Security, we design, build, and deliver end-to-end security — from innovation to architecture to products in the field. If you’re a security engineer who wants impact on real life security solutions, we’d love to hear from you.

Our Chief Technology Office (CTO) organization drives innovation across NXP and supports Business Units with the tools, knowledge, and processes required to create secure products for our customers. The Security Architecture Team within the Competence Center Crypto & Security (CC C&S) plays a key role in enabling secure products across the Automotive, Industrial, IoT, Mobile, and Edge Processing markets.

Your Role

Join our team and support product development teams in gathering requirements, specifying, designing, reviewing, verifying, and implementing security solutions for NXP products. As a Software Security Architect, you will help ensure that security is built into products throughout their entire lifecycle. You will collaborate with product teams, security experts, and stakeholders across the company to develop robust security architectures, assess security risks, and support compliance with relevant cybersecurity standards and regulations, including the Cyber Resilience Act (CRA).

Your Responsibilities
  • Specify, design, review, and evolve system software security architectures and implementations.
  • Conduct threat analysis, attack surface analysis, and security risk assessments for embedded systems and software platforms.
  • Define security requirements and establish traceability from security objectives to implementation and verification activities.
  • Integrate security-by-design principles throughout the complete product lifecycle.
  • Support secure development lifecycle (SDL) activities, including architecture reviews, security assessments, and security verification.
  • Analyze security vulnerabilities and defects, perform root cause analysis, and define appropriate mitigations and countermeasures.
  • Define and review security mechanisms such as secure boot, secure update, cryptographic services, key management, device identity, and root-of-trust solutions.
  • Translate cybersecurity standards, regulatory requirements, and industry best practices into practical engineering requirements and architectures.
  • Support compliance activities related to product security regulations and standards, including the Cyber Resilience Act (CRA), through security documentation, evidence generation, and risk management activities.
  • Drive adoption of security best practices across project teams and product lines.
  • Serve as a technical interface to customers, evaluation labs, compliance experts, and product development teams.
  • Contribute to the continuous improvement of NXP's product security methodologies, frameworks, and processes.
Your Profile
  • Master's degree, PhD, or equivalent experience in Computer Science, Cybersecurity, Software Engineering, Electronics, Mathematics, or a related technical field.
  • Strong background in cybersecurity and software security architecture.
  • Extensive experience in embedded software development using C, Rust, and/or assembly language.
  • Strong understanding of SoC software stacks, middleware, firmware, operating systems, and applications.
  • Experience with threat modelling, security risk assessment, and secure system design.
  • Familiarity with security technologies such as Secure Boot, Cryptography and Key Management, Device Identity and Root of Trust, Firmware Protection, Secure Update Mechanisms.
  • Familiarity with cybersecurity regulations, standards, and certification schemes applicable to embedded and connected products.
  • Strong analytical skills and ability to address complex system-level security challenges.
  • Experience or interest in AI security is a plus.
  • Independent working style with a willingness to listen, learn, and adapt.
  • Excellent communication and stakeholder management skills.
  • Strong team player with the ability to work effectively in global and cross-functional environments.
Preferred Qualifications

Experience in one or more of the following areas is highly desirable:

  • Security architecture for automotive, industrial, or IoT products.
  • Product security regulations and compliance frameworks, including the Cyber Resilience Act (CRA).
  • Secure Development Lifecycle (SDL) practices.
  • Security certification frameworks such as PSA Certified, SESIP, or Common Criteria.
  • Vulnerability management, penetration testing, or security assessments.
  • Hardware/software security co-design.
  • Artificial Intelligence and AI security.

NXP Semiconductors N.V. (NASDAQ: NXPI) makes products and environments safer, more sustainable, and more secure with innovative connectivity and edge processing solutions for a smarter world. We are in the business of better. Not just better technologies, but better innovations to improve society. As the world leader in secure connectivity and processing solutions for embedded applications, NXP is solving the world’s most complex technology challenges to accelerate business innovation, enhance how we work, and advance how we live.

Please note: The successful candidate may/will be responsible for security related tasks. The assignment may/will be in scope of security certifications, therefore a conscious and reliable way of working is necessary.

For applications in Gratkorn: NXP provides market competitive compensation according to the benchmarking of the electronic and semiconductor industry. Due to the Austrian Equal Treatment Act we are obligated to state the employment group of our applicable collective bargaining agreement (CBA) “Kollektivvertrag für Angestellte Gewerbe und Handwerk und in der Dienstleistung“, this position (fulltime) is graded in Employment Group V after 6 years. Your individual experiences and expectations will be considered in the application process. Moreover, we provide attractive benefits to our employees like home office, flexible working time, meal benefits and more.

Software Security Architect - CRA (m/f/d) in Glasgow employer: NXP Semiconductors

NXP Semiconductors is an exceptional employer, offering a dynamic and collaborative work culture in the heart of Glasgow. Employees benefit from continuous professional development opportunities and are encouraged to innovate within the rapidly evolving semiconductor industry, making it a rewarding place for those passionate about security solutions.

NXP Semiconductors

Contact Details:

NXP Semiconductors Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Software Security Architect - CRA (m/f/d) in Glasgow

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including NXP Semiconductors, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through NXP Semiconductors

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at NXP Semiconductors. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Software Security Architect - CRA (m/f/d) in Glasgow

Cybersecurity
Software Security Architecture
Embedded Software Development
C Programming
Rust Programming
Assembly Language
Threat Modelling

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at NXP Semiconductors insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to NXP Semiconductors that you’re committed to staying ahead in the game.

How to prepare for a job interview at NXP Semiconductors

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at NXP Semiconductors to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at NXP Semiconductors.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.