Manager - Product Security
Listed on 2026-08-10
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Manager, Product Security Governance
Join the team that's securing the future of embedded intelligence. At Microchip Technology, our products power the world — from automotive systems and industrial automation to aerospace, medical devices, and the Internet of Things. As cybersecurity regulations intensify globally and threats to embedded systems grow more sophisticated, Microchip is making a bold investment in product security leadership. This is your opportunity to be at the center of that transformation.
We are seeking a Manager, Product Security Governance to join our Product Security Office (PSO) — a high-visibility team shaping how security is embedded into silicon, firmware, and software across one of the world's leading semiconductor companies. Reporting to the Head of the Product Security Office, you will serve as a senior leader helping to define governance frameworks, drive cross-functional adoption, and strengthen regulatory readiness on a global scale.
You'll be shaping the foundation — establishing scalable processes, enabling engineering teams across Business Units, and driving measurable progress in threat modeling, vulnerability management, regulatory readiness, and supply chain security governance. You'll work at the intersection of cybersecurity strategy, engineering execution, and global standards — with direct impact on Microchip's ability to ship trusted, compliant, and resilient products worldwide.
Key Responsibilities- Product Security Governance, Risk & Regulatory Readiness
- PSIRT & Vulnerability Management Governance
- Threat Modeling & Product Risk Classification
- Standards, Industry Engagement & External Representation
Qualifications:
Required Qualifications
- Bachelor's or Master's degree in Electrical Engineering, Computer Science, Cybersecurity, Embedded Systems, or a related field.
- 12.5+ years of experience in cybersecurity, product security, embedded security, semiconductor security, or related technical disciplines.
- 5+ years of experience in product security governance, secure development lifecycle, security program management, or regulatory readiness roles.
- 3+ years in a leadership or senior role driving cross-functional security initiatives across multiple teams or Business Units.
- Strong understanding of embedded systems, semiconductor products, firmware, software, hardware security, cryptography, and product lifecycle processes.
- Experience with the EU Cyber Resilience Act, RED cybersecurity requirements, NIS2, EUCC, SESIP, Common Criteria, or related cybersecurity regulatory frameworks.
- Experience with product security governance frameworks, threat modeling, risk assessment, vulnerability management, or PSIRT processes.
- Familiarity with standards and frameworks such as IEC 62443, ISO 21434, OWASP, STRIDE, MITRE ATT&CK, EMB3D, or similar frameworks.
- Experience translating regulatory, customer, and standards requirements into practical engineering and governance processes.
- Strong stakeholder management skills across engineering, quality, legal, compliance, sales, field applications, and executive audiences.
- Ability to lead cross-functional initiatives and influence stakeholders across global Business Units without direct authority.
- Strong written and verbal communication skills, including executive reporting and customer-facing security communications.
Preferred Qualifications
- Experience in semiconductor, embedded systems, industrial automation, automotive, IoT, medical, or security certification domains.
- Experience with threat modeling tools.
- Experience with SBOM tooling, CVE processes, CNA operations, vulnerability databases, and open-source vulnerability monitoring.
- Experience participating in standards bodies, working groups, industry associations, or regulatory consultations.
- Experience working with notified bodies, cybersecurity labs, certification bodies, or external assessors.
- Program management experience, including KPI dashboards, governance cadence, cross-Business Unit execution tracking, and maturity models.
Travel Time:
0% - 25%
Physical Attributes:
Hearing, Seeing, Talking, Works Alone, Works Around Others
Physical Requirements:
Regular business hours; 70% sitting, 15% standing, 15% walking
Microchip Technology Inc is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. For more information on applicable equal employment regulations, please refer to the Know Your Rights:
Workplace Discrimination is Illegal Poster.
To all recruitment agencies:
Microchip Technology Inc. does not accept unsolicited agency resumes. Please do not forward resumes to our recruiting team or other Microchip employees. Microchip is not responsible for any fees related to unsolicited resumes.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).