1 day ago
Base Salary
$224k - $357k/yr
Responsibilities
- Own the product-security strategy and roadmap for Jetson, L4T, and JetPack from architecture through post-launch support.
- Guide secure-by-design practices across firmware, boot software, the Linux kernel, device drivers, system software, containers, and platform services.
- Lead threat analysis, vulnerability assessments, threat modeling, risk analysis, attack-surface analysis, and security architecture reviews.
- Coordinate security-finding triage and remediation with NVIDIA PSIRT and engineering teams.
- Support cybersecurity-regulation readiness, including EU CRA technical-gap analysis and evidence coordination.
- Create and maintain SBOMs, security white papers, secure-deployment guidance, vulnerability-management documentation, and customer-facing security collateral.
- Serve as the primary product-security contact for engineering, program management, PSIRT, application teams, customers, and partners.
- Develop scalable security processes, reusable mentorship, foundational standards, and operational metrics for release readiness and remediation progress.
Requirements
- Bachelor’s or Master’s degree, or equivalent experience, in Computer Science, Electrical or Computer Engineering, Cybersecurity, or a related field.
- At least 12 years of security-engineering experience, including at least 3 years in product security, platform security, security architecture, or technical leadership.
- Experience securing complex embedded, Linux, robotics, edge-computing, automotive, or system-on-chip platforms.
- Strong knowledge of secure boot, roots of trust, trusted execution, key management, cryptography, secure provisioning, debug protection, and secure software updates.
- Practical experience with threat modeling, security architecture reviews, vulnerability assessments, risk analysis, and security-requirement development.
- Experience integrating code analysis, dependency management, vulnerability scanning, SBOM generation, and remediation workflows into the software development lifecycle.
- Ability to lead and influence across organizations without direct authority in a global engineering environment.
- Strong written and verbal communication skills for explaining security risks to engineers, executives, customers, and non-security partners.
- Preferred experience with NVIDIA Jetson, Tegra, L4T, JetPack, or similar ARM-based embedded platforms.
- Preferred experience with EU CRA, NIST SSDF, IEC 62443, ISO/SAE 21434, ISO/IEC 27001, or ETSI EN 303 645.
- Preferred experience with coordinated vulnerability disclosure, CVEs, embargoed responses, software-supply-chain security, open-source dependencies, container security, signing, attestation, and build provenance.
- Preferred experience programming in C, C++, or Python for embedded systems and security analysis and producing customer-facing security documentation and threat assessments.
Benefits
- Base salary range is 224,000 USD to 356,500 USD, determined by location, experience, and comparable employee pay.
- Eligible for equity and benefits.
- Applications are accepted at least until September 14, 2026.
- NVIDIA is an equal opportunity employer with an inclusive work environment.
About Nvidia
Nvidia designs and sells GPUs and accelerated computing platforms for data centers, AI/ML, graphics, gaming, and automotive, monetizing through hardware, software platforms (CUDA, AI frameworks), and systems like DGX and networking. Customers include cloud providers, enterprises, researchers, and OEMs. Founded in 1993 and headquartered in Santa Clara, it is a public company traded on NASDAQ under NVDA.
