Job
- Level
- Erfahren
- Job Feld
- IT, Security, Test/QA
- Anstellung
- Vollzeit
- Vertragsart
- Unbefristetes Dienstverhältnis
- Ort
- Gratkorn
- Arbeitsmodell
- Hybrid, Onsite
Job Zusammenfassung
In diesem Job bist du verantwortlich für die Verwaltung von Schwachstellen in Drittanbieterkomponenten, entwickelst Best Practices und führst Risikobewertungen sowie Incident-Management-Prozesse durch, um Produktsicherheit zu gewährleisten.
Job Technologien
Deine Rolle im Team
- Empower our software development community in managing vulnerabilities in Third Party Components (TPS) and Open Source Software (OSS), ensuring robust security.
- Define and develop best practices, streamline processes, and drive continuous improvement initiatives.
- Contribute to new regulations and standardization activities that may impact product security or our way of working such as the upcoming EU Cyber Resilience Act.
- Collaborate with innovators - partner with external security researchers, academia and research organizations on cutting-edge projects and vulnerability submissions.
- Be a key player in risk management by supporting and leading triage and vulnerability assessments of product vulnerabilities.
- Work cross-functionally with internal teams (engineering, product management, legal, etc.) to ensure timely resolution of incidents.
- Own the process by generating and managing PSIRT JIRA tickets for validated vulnerabilities.
- Provide updates about incident status, impact, and mitigation actions to relevant stakeholders.
- Manage incoming Third Party vendor vulnerability pre-notifications and monitor internal and external sources to identify signs of security incidents related to our products.
Unsere Erwartungen an dich
Ausbildung
- Bachelor's/master's degree in engineering - Computer Science, Electrical Engineering, Cybersecurity, or a related field.
Qualifikationen
- Familiarity in a Security Operations Center or PSIRT or similar security incident response teams.
- Familiarity with industry-standard security frameworks, standards, and regulations.
- Understanding of security in the following areas - embedded systems, hardware and software; ability to quickly learn where needed.
- Interests in security concepts, secure coding, and security best practices.
- Excellent collaboration and communication skills to work effectively with cross-functional teams.
- Ability to work independently, taking ownership of security initiatives and improving processes.
Erfahrung
- 3+ years of experience in product security incident response, investigation and vulnerability management across hardware and software products.
Unser Angebot
- The successful candidate may/will be responsible for security related tasks.
- The assignment may/will be in scope of security certifications, therefore a conscious and reliable way of working is necessary.
- For Austrian applicants: NXP provides market competitive compensation according to the benchmarking of the electronic and semiconductor industry.
- Due to the Austrian Equal Treatment Act we are obligated to state the employment group of our applicable collective bargaining agreement (CBA) "Kollektivvertrag für Angestellte Gewerbe und Handwerk und in der Dienstleistung", this position (fulltime) is graded in Employment Group V.
- Your individual experiences and expectations will be considered in the application process.
- Moreover, we provide attractive benefits to our employees like home office, flexible working time, meal benefits and more.
Benefits
Work-Life-Integration
Essen & Trinken
Mehr Netto
Gesundheit, Fitness & Fun
Themen mit denen du dich im Job beschäftigst
Job Standorte
Das ist dein Arbeitgeber
NXP Semiconductors Austria
Gratkorn
NXP Semiconductors ist ein weltweit führendes Unternehmen der Mikroelektronik mit Niederlassungen in mehr als 25 Ländern. Der Standort Gratkorn bei Graz ist die Österreichzentrale des internationalen Konzerns und das Kompetenzzentrum für sichere kontaktlose Identifikationssysteme.
Description
- Gründungsjahr
- 2006
- Sprachen
- Englisch
- Unternehmenstyp
- Etablierte Firma
- Arbeitsmodell
- Full Remote, Hybrid, Onsite
- Branche
- Industrie, Produktion
Dev Reviews
by devworkplaces.com
Gesamt
(2 Bewertungen)3.7
Culture
3.7Engineering
3.4Career Growth
3.5Workingconditions
4.2