×
Register Here to Apply for Jobs or Post Jobs. X

Senior Engineer II - Product Security

Job in Chandler, Maricopa County, Arizona, 85286, USA
Listing for: Microchip Technology
Full Time position
Listed on 2026-08-10
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below

Product Security Engineer

Microchip's Product Security Office (PSO) is committed to managing and addressing security vulnerabilities in Microchip products, providing customers with clear guidance on impact, severity, and mitigation, and ensuring Microchip's product portfolio meets evolving security standards and regulatory requirements.

We are looking for a Product Security Engineer to join the PSO team, working across both PSIRT (Product Security Incident Response Team) operations and security standards/regulatory enablement.

You will be responsible for triaging and supporting resolution of product-related security vulnerabilities across Microchip's semiconductor product portfolio along with development kits, firmware, software tools, and reference designs. In addition, you will contribute to security standards adoption and regulatory readiness activities that strengthen Microchip's overall product security posture.

In This Role, You Will:

  • Manage the day-to-day intake, triage, and case management of product vulnerability reports across hardware, firmware, and software products.
  • Perform technical vulnerability assessments and apply structured severity scoring (CVSS) to determine impact and exploitability across Microchip's product categories.
  • Empower engineering teams in managing vulnerabilities in third-party components and open-source software integrated into Microchip products, ensuring robust security posture.
  • Drive remediation coordination with Business Unit engineering teams and security champions.
  • Collaborate with external security researchers, academia, and coordination centers on vulnerability submissions and coordinated disclosure activities.
  • Operate Microchip's coordinated vulnerability disclosure channel.
  • Author security advisories, bulletins, and customer communications in standard publication formats (CSAF); coordinate multiparty disclosure with upstream and downstream vendors.
  • Execute CVE assignment and support CNA operations under Microchip's CVE Numbering Authority membership.
  • Generate and manage PSIRT case tickets for validated vulnerabilities; maintain the case management system as the operational source of truth.
  • Monitor internal and external sources (NVD, vendor pre-notifications, SBOM/VEX feeds, Black Duck) to identify security issues affecting Microchip products.
  • Run SBOM- and VEX-driven analysis of third-party and open-source components; correlate upstream advisories to affected products and communicate exploitability status.
  • Manage incoming third-party vendor vulnerability pre-notifications and coordinate supplier response activities.
  • Execute statutory incident reporting for actively exploited vulnerabilities under the EU Cyber Resilience Act.

Security Standards & Regulatory Enablement

  • Contribute to new regulations and standardization activities that impact product security, including the EU Cyber Resilience Act (CRA), IEC 62443, ISO/SAE 21434, ETSI EN 303 645, and sector-specific security frameworks.
  • Map product security standards requirements to Microchip's development workflows and product architectures, translating regulatory and standards obligations into practical engineering guidance.
  • Support the development and maintenance of CRA readiness frameworks — product classification guidance, essential cybersecurity requirements mapping, conformity assessment preparation, and technical documentation templates.
  • Define and develop best practices for secure development lifecycle compliance, streamline processes, and drive continuous improvement initiatives aligned to IEC 62443-4-1, ASPICE, and ISO/SAE 21434.
  • Track the evolving standards and regulatory landscape (new editions, emerging frameworks, sector-specific requirements) and communicate relevant updates to PSO leadership and BU security champions.
  • Work cross-functionally with internal teams (engineering, product management, quality, legal, compliance) to ensure consistent standards interpretation and timely regulatory readiness.
  • Draft standard responses to customer security questionnaires, CRA requests, SBOM requests, and vulnerability statements for review by customer-facing teams.
  • Coordinate with Quality (QMS integration) and…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary