Microchip Technology

Senior Engineer II - Product Security

Microchip Technology$120K — $145K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in relevant engineering or cybersecurity field.
  • 7.5+ years experience in firmware/embedded software development or product security engineering.
  • Hands-on experience with cryptographic algorithms and hardware security modules.
  • Practical knowledge of product security standards such as IEC 62443 and ISO/SAE 21434.
  • Ability to analyze and assess security vulnerabilities using structured scoring methodologies.

Responsibilities

  • Manage triage and case management of product vulnerability reports.
  • Perform technical vulnerability assessments and apply CVSS scoring.
  • Collaborate with engineering teams on third-party component vulnerabilities.
  • Drive remediation efforts with business unit engineering teams and security champions.
  • Author security advisories and manage customer communications regarding vulnerabilities.
  • Support regulatory readiness activities related to security frameworks and standards.
  • Draft customer security responses for questionnaires and vulnerability statements.

Benefits

  • Collaborative work environment fostering innovation and growth.
  • Opportunities for continuous learning and professional development.
  • Engagement with leading security standards and regulatory frameworks.
  • Involvement in security incident response and vulnerability management processes.
Full Job Description
Job Description:

Microchip's Product Security Office (PSO) is committed to managing and addressing security vulnerabilities in Microchip products, providing customers with clear guidance on impact, severity, and mitigation, and ensuring Microchip's product portfolio meets evolving security standards and regulatory requirements.

We are looking for a Product Security Engineer to join the PSO team, working across both PSIRT (Product Security Incident Response Team) operations and security standards/regulatory enablement.

You will be responsible for triaging and supporting resolution of product-related security vulnerabilities across Microchip's semiconductor product portfolio along with development kits, firmware, software tools, and reference designs. In addition, you will contribute to security standards adoption and regulatory readiness activities that strengthen Microchip's overall product security posture

IN THIS ROLE, YOU WILL:

Vulnerability Management & PSIRT Operation
  • Manage the day-to-day intake, triage, and case management of product vulnerability reports across hardware, firmware, and
  • software products.
  • Perform technical vulnerability assessments and apply structured severity scoring (CVSS) to determine impact and
  • exploitability across Microchip's product categories.
  • Empower engineering teams in managing vulnerabilities in third-party components and open-source software integrated into
  • Microchip products, ensuring robust security posture.
  • Drive remediation coordination with Business Unit engineering teams and security champions.
  • Collaborate with external security researchers, academia, and coordination centers on vulnerability submissions and
  • coordinated disclosure activities.
  • Operate Microchip's coordinated vulnerability disclosure channel
  • Author security advisories, bulletins, and customer communications in standard publication formats (CSAF); coordinate
  • multiparty disclosure with upstream and downstream vendors.
  • Execute CVE assignment and support CNA operations under Microchip's CVE Numbering Authority membership.
  • Generate and manage PSIRT case tickets for validated vulnerabilities; maintain the case management system as the
  • operational source of truth.
  • Monitor internal and external sources (NVD, vendor pre-notifications, SBOM/VEX feeds, Black Duck) to identify security issues
  • affecting Microchip products.
  • Run SBOM- and VEX-driven analysis of third-party and open-source components; correlate upstream advisories to affected
  • products and communicate exploitability status.
  • Manage incoming third-party vendor vulnerability pre-notifications and coordinate supplier response activities.
  • Execute statutory incident reporting for actively exploited vulnerabilities under the EU Cyber Resilience Act


Security Standards & Regulatory Enablement
  • Contribute to new regulations and standardization activities that impact product security, including the EU Cyber Resilience Act
  • (CRA), IEC 62443, ISO/SAE 21434, ETSI EN 303 645, and sector-specific security frameworks.
  • Map product security standards requirements to Microchip's development workflows and product architectures, translating
  • regulatory and standards obligations into practical engineering guidance.
  • Support the development and maintenance of CRA readiness frameworks - product classification guidance, essential
  • cybersecurity requirements mapping, conformity assessment preparation, and technical documentation templates.
  • Define and develop best practices for secure development lifecycle compliance, streamline processes, and drive continuous
  • improvement initiatives aligned to IEC 62443-4-1, ASPICE, and ISO/SAE 21434.
  • Track the evolving standards and regulatory landscape (new editions, emerging frameworks, sector-specific requirements) and
  • communicate relevant updates to PSO leadership and BU security champions.
  • Work cross-functionally with internal teams (engineering, product management, quality, legal, compliance) to ensure
  • consistent standards interpretation and timely regulatory readiness.
  • Draft standard responses to customer security questionnaires, CRA requests, SBOM requests, and vulnerability statements for
  • review by customer-facing teams.
  • Coordinate with Quality (QMS integration) and Legal/Compliance (regulatory interpretation) to ensure product security
  • evidence meets both standards and regulatory expectations.


This role operates within the PSO governance framework, executing and providing feedback on processes and policies defined by PSO leadership.

Requirements/Qualifications:

EDUCATION (REQUIRED):
Bachelors degree in Electrical Engineering, Computer Engineering, Electrical and Computer Engineering, Computer Science, Embedded Systems, Cybersecurity, or a closely related engineering field.

EXPERIENCE (REQUIRED):
7.5+ years of experience in firmware/embedded software development, product security engineering, or vulnerability management - with demonstrable focus on security in embedded systems

REQUIRED KNOWLEDGE, SKILLS & ABILITIES:
  • Experience in a PSIRT, Security Operations, or security incident response team environment.
  • Embedded systems and firmware engineering - experience with microcontroller/microprocessor platforms.
  • Cryptography and hardware security - hands-on experience with cryptographic algorithm integration, hardware security
  • module (HSM) drivers, security abstraction layers, secure key storage, PUF (Physically Unclonable Function), or Trust Zone
  • based isolation.
  • Product security standards - practical working knowledge of one or more: IEC 62443, ISO/SAE 21434, PSA Certified, SESIP,
  • FIPS 140-3, Common Criteria, ETSI EN 303 645, NIST Cybersecurity Framework
  • Vulnerability assessment - ability to analyze security vulnerabilities in embedded products, assess exploitability, and apply
  • structured scoring methodologies (CVSS or equivalent).
  • Secure development practices - familiarity with secure coding standards (MISRA-C, CERT C), static analysis, and
  • development lifecycle standards (IEC 62443-4-1).
  • Technical documentation - ability to author clear technical security documentation, compliance evidence, vulnerability
  • assessments, and standards-aligned artifacts.
  • Communication and collaboration - strong written and verbal skills; ability to work cross-functionally with engineering, product
  • management, quality, legal, and customer-facing teams.
  • Ability to work independently, taking ownership of security initiatives and improving processes within a defined governance
  • framework.


PREFERRED QUALIFICATIONS:
  • CNA operations experience (CVE assignment).
  • SBOM/VEX program experience (CycloneDX, SPDX, Black Duck, software composition analysis).
  • Threat modeling familiarity (STRIDE, MITRE ATT&CK, EMB3D).
  • Familiarity with EU Cyber Resilience Act, RED Delegated Act, NIS2, FDA premarket cybersecurity, or UN R155/R156.
  • Hands-on coordinated vulnerability disclosure experience - working with researchers, managing embargoes, publishing
  • advisories.
  • Standards body participation or certification audit experience (IEC 62443, ISO 21434, Common Criteria, PSA Certified, FIPS evaluations).


Travel Time:

0% - 25%

Physical Attributes:

Hearing, Seeing, Talking, Works Alone, Works Around Others

Physical Requirements:

Regular business hours; 70% sitting, 15% standing, 15% walking

About Microchip Technology

Microchip Technology is an American semiconductor company headquartered in Chandler, Arizona. The company was founded in 1989 and has been providing microcontroller and analog semiconductors for over 30 years. Microchip Technology operates in over 100 locations in 70 countries and has more than 18,000 employees worldwide. The company's products include microcontrollers, memory, and other analog and mixed-signal products. Microchip Technology's mission is to provide innovative solutions for a wide range of applications, including automotive, industrial, and consumer electronics.
Learn more about Microchip Technology
Size
21,000 employees
Market Cap
$37.9 billion
Industry
Net Income
$333.3 million
Founded
1989
5 Year Trend
+14.9%
Revenue
$5.2 billion
NASDAQ

Similar Jobs

More Jobs at Microchip Technology

More Information Technology Jobs

Find similar Senior Engineer II - Product Security jobs: