waypointjobs

Microchip Technology Inc.

Senior Engineer II - Product Security

chandler, AZ

Check who can apply and the requirements below before continuing.

About this opportunity

Microchip Technology Inc. lists this Senior Engineer II - Product Security opportunity in chandler, Arizona. Review the employer’s description below for duties, qualifications and application requirements.

Job description

Are you looking for a unique opportunity to be a part of something great? Want to join a 17,000-member team that works on the technology that powers the world around us? Looking for an atmosphere of trust, empowerment, respect, diversity, and communication? How about an opportunity to own a piece of a multi-billion dollar (with a B!) global organization? We offer all that and more at Microchip Technology Inc.

People come to work at Microchip because we help design the technology that runs the world. They stay because our culture supports their growth and stability. They are challenged and driven by an incredible array of products and solutions with unlimited career potential. Microchip’s nationally-recognized Leadership Passage Programs support career growth where we proudly enroll over a thousand people annually. We take pride in our commitment to employee development, values-based decision making, and strong sense of community, driven by our Vision, Mission, and 11 Guiding Values; we affectionately refer to it as the Aggregate System and it’s won us countless awards for diversity and workplace excellence.

Our company is built by dedicated team players who love to challenge the status quo; we did not achieve record revenue and over 30 years of quarterly profitability without a great team dedicated to empowering innovation. People like you.

Visit our careers page to see what exciting opportunities and company perks await!

Job Description

Microchip's Product Security Office (PSO) is committed to managing and addressing security vulnerabilities in Microchip products, providing customers with clear guidance on impact, severity, and mitigation, and ensuring Microchip's product portfolio meets evolving security standards and regulatory requirements.

We are looking for a Product Security Engineer to join the PSO team, working across both PSIRT (Product Security Incident Response Team) operations and security standards/regulatory enablement.

You will be responsible for triaging and supporting resolution of product-related security vulnerabilities across Microchip's semiconductor product portfolio along with development kits, firmware, software tools, and reference designs. In addition, you will contribute to security standards adoption and regulatory readiness activities that strengthen Microchip's overall product security posture

In This Role, You Will

Vulnerability Management & PSIRT Operation

Manage the day-to-day intake, triage, and case management of product vulnerability reports across hardware, firmware, and

software products.

Perform technical vulnerability assessments and apply structured severity scoring (CVSS) to determine impact and

exploitability across Microchip's product categories.

Empower engineering teams in managing vulnerabilities in third-party components and open-source software integrated into

Microchip products, ensuring robust security posture.

Drive remediation coordination with Business Unit engineering teams and security champions.

Collaborate with external security researchers, academia, and coordination centers on vulnerability submissions and

coordinated disclosure activities.

Operate Microchip's coordinated vulnerability disclosure channel

Author security advisories, bulletins, and customer communications in standard publication formats (CSAF); coordinate

multiparty disclosure with upstream and downstream vendors.

Execute CVE assignment and support CNA operations under Microchip's CVE Numbering Authority membership.

Generate and manage PSIRT case tickets for validated vulnerabilities; maintain the case management system as the

operational source of truth.

Monitor internal and external sources (NVD, vendor pre-notifications, SBOM/VEX feeds, Black Duck) to identify security issues

affecting Microchip products.

Run SBOM- and VEX-driven analysis of third-party and open-source components; correlate upstream advisories to affected

products and communicate exploitability status.

Manage incoming third-party vendor vulnerability pre-notifications and coordinate supplier response activities.

Execute statutory incident reporting for actively exploited vulnerabilities under the EU Cyber Resilience Act

Security Standards & Regulatory Enablement

Contribute to new regulations and standardization activities that impact product security, including the EU Cyber Resilience Act

(CRA), IEC 62443, ISO/SAE 21434, ETSI EN 303 645, and sector-specific security frameworks.

Map product security standards requirements to Microchip's development workflows and product architectures, translating

regulatory and standards obligations into practical engineering guidance.

Support the development and maintenance of CRA readiness frameworks — product classification guidance, essential

cybersecurity requirements mapping, conformity assessment preparation, and technical documentation templates.

Define and develop best practices for secure development lifecycle compliance, streamline processes, and drive continuous

improvement initiatives aligned to IEC 62443-4-1, ASPICE, and ISO/SAE 21434.

Track the evolving standards and regulatory landscape (new editions, emerging frameworks, sector-specific requirements) and

communicate relevant updates to PSO leadership and BU security champions.

Work cross-functionally with internal teams (engineering, product management, quality, legal, compliance) to ensure

consistent standards interpretation and timely regulatory readiness.

Draft standard responses to customer security questionnaires, CRA requests, SBOM requests, and vulnerability statements for

review by customer-facing teams.

Coordinate with Quality (QMS integration) and Legal/Compliance (regulatory interpretation) to ensure product security

evidence meets both standards and regulatory expectations.

Requirements/Qualifications

EDUCATION (REQUIRED)

Bachelors degree in Electrical Engineering, Computer Engineering, Electrical and Computer Engineering, Computer Science, Embedded Systems, Cybersecurity, or a closely related engineering field.

Experience (required)

7.5+ years of experience in firmware/embedded software development, product security engineering, or vulnerability management — with demonstrable focus on security in embedded systems

Required Knowledge, Skills & Abilities

Experience in a PSIRT, Security Operations, or security incident response team environment.

Embedded systems and firmware engineering — experience with microcontroller/microprocessor platforms.

Cryptography and hardware security — hands‑on experience with cryptographic algorithm integration, hardware security

module (HSM) drivers, security abstraction layers, secure key storage, PUF (Physically Unclonable Function), or Trust Zone

based isolation.

Product security standards — practical working knowledge of one or more: IEC 62443, ISO/SAE 21434, PSA Certified, SESIP,

FIPS 140-3, Common Criteria, ETSI EN 303 645, NIST Cybersecurity Framework

Vulnerability assessment — ability to analyze security vulnerabilities in embedded products, assess exploitability, and apply

structured scoring methodologies (CVSS or equivalent).

Secure development practices — familiarity with secure coding standards (MISRA-C, CERT C), static analysis, and

development lifecycle standards (IEC 62443-4-1).

Technical documentation — ability to author clear technical security documentation, compliance evidence, vulnerability

assessments, and standards-aligned artifacts.

Communication and collaboration — strong written and verbal skills; ability to work cross-functionally with engineering, product

management, quality, legal, and customer-facing teams.

Ability to work independently, taking ownership of security initiatives and improving processes within a defined governance

framework.

Preferred Qualifications

CNA operations experience (CVE assignment).

SBOM/VEX program experience (CycloneDX, SPDX, Black Duck, software composition analysis).

Threat modeling familiarity (STRIDE, MITRE ATT&CK, EMB3D).

Familiarity with EU Cyber Resilience Act, RED Delegated Act, NIS2, FDA premarket cybersecurity, or UN R155/R156.

Hands‑on coordinated vulnerability disclosure experience — working with researchers, managing embargoes, publishing

advisories.

Standards body participation or certification audit experience (IEC 62443, ISO 21434, Common Criteria, PSA Certified, FIPS evaluations).

Travel Time

0% - 25%

Physical Attributes

Hearing, Seeing, Talking, Works Alone, Works Around Others

Physical Requirements

Regular business hours; 70% sitting, 15% standing, 15% walking

Microchip Technology Inc is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.

For more information on applicable equal employment regulations, please refer to the Know Your Rights: Workplace Discrimination is Illegal Poster.

#J-18808-Ljbffr

Worksite address

chandler, AZ, 85249, US

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Ready for your next step?Apply on the official website
Apply on WhatJobs ↗

Explore related searches

Current related jobs

Hobbs Brook Real Estate

WhatJobs

Commercial Facilities Engineer

waltham, MA

$30.88 to $38.61 per hour

Job Description: Hobbs Brook Real Estate LLC is an innovative commercial real estate leader with a portfolio of forward-thinking, sustainable pro…

Last received from source 2026-10-08View job

Hobbs Brook Real Estate

WhatJobs

Chief Engineer, Class A Office Portfolio

waltham, MA

$121,000 to $173,000 annually

Job Description: Hobbs Brook Real Estate LLC is an innovative commercial real estate leader with a portfolio of forward-thinking, sustainable pro…

Last received from source 2026-10-08View job

Marriott International, Inc

WhatJobs

Chief Engineer

lahaina, HI

Pay Range: $92,000-$122,000 annually

Additional Information Job Number Job Category Engineering & Facilities Location 2365 Kaanapali Parkway, Lahaina HI 96761, United StatesVIEW O…

Last received from source 2026-10-08View job

GXO Logistics

WhatJobs

Senior Industrial Engineer

columbus, OH

Salary not specified

Logistics at full potential.  At GXO, we’re constantly looking for talented individuals at all levels who can deliver the caliber of service…

Last received from source 2026-10-08View job

GXO Logistics

WhatJobs

Senior Industrial Engineer

columbus, OH

Salary not specified

Logistics at full potential.  At GXO, we’re constantly looking for talented individuals at all levels who can deliver the caliber of service…

Last received from source 2026-10-08View job

GXO Logistics

WhatJobs

Senior Industrial Engineer

columbus, OH

Salary not specified

Logistics at full potential.  At GXO, we’re constantly looking for talented individuals at all levels who can deliver the caliber of service…

Last received from source 2026-10-08View job