Product Security Incident Response Manager (m/f/d)
Core
Manage and resolve security vulnerabilities in NXP hardware and software products, including third-party components and open-source software, while defining security best practices and supporting incident response.
Role type
Product Security Incident Response Manager
Builds
Security posture improvements, vulnerability mitigation strategies, and incident response processes for industrial security products
Domain
Semiconductor industry, embedded systems, hardware and software security
Deliverable
client delivery
Required skills
Product security incident response, vulnerability management, security operations center (SOC) experience, security frameworks and regulations, embedded systems security, secure coding, cross-functional collaboration
Preferred skills
Experience with EU Cyber Resilience Act, academic or research collaboration, risk management
Technologies
JIRA, third-party component management tools, open-source software platforms
Responsibilities
Empower software development community in managing vulnerabilities in Third Party Components and Open Source Software, Define and develop best practices and streamline security processes, Contribute to new regulations and standardization activities, Collaborate with external security researchers and academia, Lead triage and vulnerability assessments of product vulnerabilities, Manage incoming Third Party vendor vulnerability pre-notifications and monitor security incident sources, Provide updates about incident status and mitigation actions to stakeholders
Seniority
Senior, hands-on IC with process ownership