Manager - Product Security
Microchip Technology Inc. · Chandler, AZ · 2 wk ago
On-siteInformation TechnologyFull-time
About the Role
Join the team that's securing the future of embedded intelligence at Microchip Technology. As a Manager, Product Security Governance in our Product Security Office (PSO), you will shape how security is embedded into silicon, firmware, and software across one of the world's leading semiconductor companies. Reporting to the Head of the Product Security Office, you will define governance frameworks, drive cross-functional adoption, and strengthen regulatory readiness on a global scale. This role offers high visibility and direct impact on Microchip's ability to ship trusted, compliant, and resilient products worldwide.
Responsibilities
- Product Security Governance, Risk & Regulatory Readiness
- Define and guide the deployment of product security governance frameworks across Business Units.
- Establish consistent methodologies for product security risk classification, threat modeling, and regulatory scoping.
- Translate evolving cybersecurity regulations, standards, and guidance into actionable internal requirements and governance expectations.
- Support company-wide readiness for the EU Cyber Resilience Act and other applicable global cybersecurity requirements.
- Align product security governance with Corporate Quality workflows, new product development processes, and product release governance.
- Define security checkpoints for new products, new features, and software releases.
- Serve as an escalation point for complex product security classifications, threat scenarios, and interpretation questions.
- Maintain product security governance dashboards, maturity metrics, and executive reporting inputs.
- Coordinate with notified bodies, certification labs, and relevant industry associations and external partners, as needed.
- PSIRT & Vulnerability Management Governance
- Define and govern product vulnerability management processes within the Product Security Office.
- Establish governance frameworks for vulnerability intake, triage, validation, severity assessment, remediation coordination, disclosure, advisory publication, and regulatory reporting.
- Guide alignment of PSIRT practices with applicable international standards for vulnerability disclosure, handling, and coordinated response.
- Support consistent vulnerability handling across company-developed products, third-party components, open-source software, and supplier-provided software or IP.
- Define escalation criteria for actively exploited vulnerabilities, critical product security incidents, supplier compromises, and customer-impacting issues.
- Support CVE assignment and CNA-related activities, where applicable.
- Establish metrics and KPIs for vulnerability handling, including intake volume, triage timeliness, remediation progress, advisory publication timelines, and overdue actions.
- Partner with Legal, Engineering, Customer Support, Field Applications, and Business Units to support coordinated handling of sensitive vulnerability cases.
- Threat Modeling & Product Risk Classification
- Define and govern the enterprise framework for threat modeling and product risk classification within the Product Security Office.
- Develop and maintain threat modeling templates, decision trees, risk libraries, and assessment criteria for use across Business Units.
- Train and enable Business Unit security champions, product architects, and engineering teams on threat modeling methodologies.
- Guide the integration of threat modeling into product lifecycle and quality processes in partnership with Business Units.
- Provide guidance on the use of applicable threat intelligence, emerging attack techniques, and relevant frameworks such as MITRE ATT&CK, EMB3D, STRIDE, OWASP, IEC 62443-4-1, and ISO 21434.
- Support product teams and security champions in complex threat modeling and product risk assessments, as needed.
- Promote consistent interpretation of product risk classifications across semiconductor product categories, including MCUs, MPUs, secure elements, firmware, software tools, development kits, and reference designs.
- Standards, Industry Engagement & External Representation
- Monitor and assess evolving cybersecurity regulations, standards, regulatory guidance, and industry expectations relevant to Microchip products.
- Participate in, and help coordinate, Microchip engagement in relevant standards development organizations, industry consortia, and working groups in collaboration with Business Units and subject matter experts.
- Support representation of Microchip's product security perspectives in relevant external cybersecurity and standards discussions.
- Translate key developments from standards and regulatory discussions into actionable insights for internal governance, product security strategy, and compliance planning.
Requirements
- Bachelor's or Master's degree in Electrical Engineering, Computer Science, Cybersecurity, Embedded Systems, or a related field.
- 12.5+ years of experience in cybersecurity, product security, embedded security, semiconductor security, or related technical disciplines.
- 5+ years of experience in product security governance, secure development lifecycle, security program management, or regulatory readiness roles.
- 3+ years in a leadership or senior role driving cross-functional security initiatives across multiple teams or Business Units.
- Strong understanding of embedded systems, semiconductor products, firmware, software, hardware security, cryptography, and product lifecycle processes.
- Experience with the EU Cyber Resilience Act, RED cybersecurity requirements, NIS2, EUCC, SESIP, Common Criteria, or related cybersecurity regulatory frameworks.
- Experience with product security governance frameworks, threat modeling, risk assessment, vulnerability management, or PSIRT processes.
- Familiarity with standards and frameworks such as IEC 62443, ISO 21434, OWASP, STRIDE, MITRE ATT&CK, EMB3D, or similar frameworks.
- Experience translating regulatory, customer, and standards requirements into practical engineering and governance processes.
- Strong stakeholder management skills across engineering, quality, legal, compliance, sales, field applications, and executive audiences.
- Ability to lead cross-functional initiatives and influence stakeholders across global Business Units without direct authority.
- Strong written and verbal communication skills, including executive reporting and customer-facing security communications.
Preferred Qualifications
- Experience in semiconductor, embedded systems, industrial automation, automotive, IoT, medical, or security certification domains.
- Experience with threat modeling tools.
- Experience with SBOM tooling, CVE processes, CNA operations, vulnerability databases, and open-source vulnerability monitoring.
- Experience participating in standards bodies, working groups, industry associations, or regulatory consultations.
- Experience working with notified bodies, cybersecurity labs, certification bodies, or external assessors.
- Program management experience, including KPI dashboards, governance cadence, cross-Business Unit execution tracking, and maturity models.
Schedule
Regular business hours; 70% sitting, 15% standing, 15% walking.
Travel
0% - 25% travel time.