Manager - Product Security
Microchip Technology Inc. · Chandler, Arizona, United States
Semiconductor Manufacturing · 10,001+ employees
About the role
The Manager of Product Security Governance will define and deploy security frameworks across business units to ensure regulatory compliance and resilient product development. This role involves leading cross-functional initiatives for vulnerability management, threat modeling, and aligning security practices with global standards.
What they look for
Requirements
Candidates must hold a Bachelor's or Master's degree in a technical field and possess over 12.5 years of experience in cybersecurity or related disciplines. Proven leadership in product security governance, regulatory readiness, and deep knowledge of embedded systems and semiconductor security are essential.
Benefits
Full description
Are you looking for a unique opportunity to be a part of something great? Want to join a 17,000-member team that works on the technology that powers the world around us? Looking for an atmosphere of trust, empowerment, respect, diversity, and communication? How about an opportunity to own a piece of a multi-billion dollar (with a B!) global organization? We offer all that and more at Microchip Technology Inc.
People come to work at Microchip because we help design the technology that runs the world. They stay because our culture supports their growth and stability. They are challenged and driven by an incredible array of products and solutions with unlimited career potential. Microchip’s nationally-recognized Leadership Passage Programs support career growth where we proudly enroll over a thousand people annually. We take pride in our commitment to employee development, values-based decision making, and strong sense of community, driven by our Vision, Mission, and 11 Guiding Values; we affectionately refer to it as the Aggregate System and it’s won us countless awards for diversity and workplace excellence.
Our company is built by dedicated team players who love to challenge the status quo; we did not achieve record revenue and over 30 years of quarterly profitability without a great team dedicated to empowering innovation. People like you.
Visit our careers page to see what exciting opportunities and company perks await!
Job Description:
Join the Team That's Securing the Future of Embedded Intelligence
At Microchip Technology, our products power the world — from automotive systems and industrial automation to aerospace, medical devices, and the Internet of Things. As cybersecurity regulations intensify globally and threats to embedded systems grow more sophisticated, Microchip is making a bold investment in product security leadership. This is your opportunity to be at the center of that transformation.
We are seeking a Manager, Product Security Governance to join our Product Security Office (PSO) — a high-visibility team shaping how security is embedded into silicon, firmware, and software across one of the world's leading semiconductor companies. Reporting to the Head of the Product Security Office, you will serve as a senior leader helping to define governance frameworks, drive cross-functional adoption, and strengthen regulatory readiness on a global scale.
You'll be shaping the foundation — establishing scalable processes, enabling engineering teams across Business Units, and driving measurable progress in threat modeling, vulnerability management, regulatory readiness, and supply chain security governance. You'll work at the intersection of cybersecurity strategy, engineering execution, and global standards — with direct impact on Microchip's ability to ship trusted, compliant, and resilient products worldwide.
Key Responsibilities
1. Product Security Governance, Risk & Regulatory Readiness
- Define and guide the deployment of product security governance frameworks across Business Units.
- Establish consistent methodologies for product security risk classification, threat modeling, and regulatory scoping.
- Translate evolving cybersecurity regulations, standards, and guidance into actionable internal requirements and governance expectations.
- Support company-wide readiness for the EU Cyber Resilience Act and other applicable global cybersecurity requirements.
- Align product security governance with Corporate Quality workflows, new product development processes and product release governance.
- Define security checkpoints for new products, new features and software releases.
- Serve as an escalation point for complex product security classifications, threat scenarios, and interpretation questions.
- Maintain product security governance dashboards, maturity metrics, and executive reporting inputs.
- Coordinate with notified bodies, certification labs, and relevant industry associations and external partners, as needed.
2. PSIRT & Vulnerability Management Governance
- Define and govern product vulnerability management processes within the Product Security Office.
- Establish governance frameworks for vulnerability intake, triage, validation, severity assessment, remediation coordination, disclosure, advisory publication, and regulatory reporting.
- Guide alignment of PSIRT practices with applicable international standards for vulnerability disclosure, handling and coordinated response.
- Support consistent vulnerability handling across company-developed products, third-party components, open-source software, and supplier-provided software or IP.
- Define escalation criteria for actively exploited vulnerabilities, critical product security incidents, supplier compromises, and customer-impacting issues.
- Support CVE assignment and CNA-related activities, where applicable.
- Establish metrics and KPIs for vulnerability handling, including intake volume, triage timeliness, remediation progress, advisory publication timelines, and overdue actions.
- Partner with Legal, Engineering, Customer Support, Field Applications, and Business Units to support coordinated handling of sensitive vulnerability cases.
3. Threat Modeling & Product Risk Classification
- Define and govern the enterprise framework for threat modeling and product risk classification within the Product Security Office.
- Develop and maintain threat modeling templates, decision trees, risk libraries, and assessment criteria for use across Business Units.
- Train and enable Business Unit security champions, product architects, and engineering teams on threat modeling methodologies.
- Guide the integration of threat modeling into product lifecycle and quality processes in partnership with Business Units.
- Provide guidance on the use of applicable threat intelligence, emerging attack techniques, and relevant frameworks such as MITRE ATT&CK, EMB3D, STRIDE, OWASP, IEC 62443-4-1, and ISO 21434.
- Support product teams and security champions in complex threat modeling and product risk assessments, as needed.
- Promote consistent interpretation of product risk classifications across semiconductor product categories, including MCUs, MPUs, secure elements, firmware, software tools, development kits, and reference designs.
4. Standards, Industry Engagement & External Representation
- Monitor and assess evolving cybersecurity regulations, standards, regulatory guidance, and industry expectations relevant to Microchip products.
- Participate in, and help coordinate, Microchip engagement in relevant standards development organizations, industry consortia, and working groups in collaboration with Business Units and subject matter experts.
- Support representation of Microchip's product security perspectives in relevant external cybersecurity and standards discussions.
- Translate key developments from standards and regulatory discussions into actionable insights for internal governance, product security strategy, and compliance planning.
Requirements/Qualifications:
Required Qualifications
- Bachelor's or Master's degree in Electrical Engineering, Computer Science, Cybersecurity, Embedded Systems, or a related field.
- 12.5+ years of experience in cybersecurity, product security, embedded security, semiconductor security, or related technical disciplines.
- 5+ years of experience in product security governance, secure development lifecycle, security program management, or regulatory readiness roles.
- 3+ years in a leadership or senior role driving cross-functional security initiatives across multiple teams or Business Units.
- Strong understanding of embedded systems, semiconductor products, firmware, software, hardware security, cryptography, and product lifecycle processes.
- Experience with the EU Cyber Resilience Act, RED cybersecurity requirements, NIS2, EUCC, SESIP, Common Criteria, or related cybersecurity regulatory frameworks.
- Experience with product security governance frameworks, threat modeling, risk assessment, vulnerability management, or PSIRT processes.
- Familiarity with standards and frameworks such as IEC 62443, ISO 21434, OWASP, STRIDE, MITRE ATT&CK, EMB3D, or similar frameworks.
- Experience translating regulatory, customer, and standards requirements into practical engineering and governance processes.
- Strong stakeholder management skills across engineering, quality, legal, compliance, sales, field applications, and executive audiences.
- Ability to lead cross-functional initiatives and influence stakeholders across global Business Units without direct authority.
- Strong written and verbal communication skills, including executive reporting and customer-facing security communications.
Preferred Qualifications
- Experience in semiconductor, embedded systems, industrial automation, automotive, IoT, medical, or security certification domains.
- Experience with threat modeling tools.
- Experience with SBOM tooling, CVE processes, CNA operations, vulnerability databases, and open-source vulnerability monitoring.
- Experience participating in standards bodies, working groups, industry associations, or regulatory consultations.
- Experience working with notified bodies, cybersecurity labs, certification bodies, or external assessors.
- Program management experience, including KPI dashboards, governance cadence, cross-Business Unit execution tracking, and maturity models.
Travel Time:
0% - 25%
Physical Attributes:
Hearing, Seeing, Talking, Works Alone, Works Around Others
Physical Requirements:
Regular business hours; 70% sitting, 15% standing, 15% walking
Microchip Technology Inc is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.
For more information on applicable equal employment regulations, please refer to the Know Your Rights: Workplace Discrimination is Illegal Poster.
To all recruitment agencies: Microchip Technology Inc. does not accept unsolicited agency resumes. Please do not forward resumes to our recruiting team or other Microchip employees. Microchip is not responsible for any fees related to unsolicited resumes.