Senior Security System Architect

6 giorni fa

Provincia di Monza e Brianza, Lombardia, Italia STMicroelectronics Italia Tempo pieno

OUR STORY

At STMicroelectronics, we believe in the power of technology to drive innovation and make a positive impact on people, businesses, and society. As a global semiconductor company, our advanced technologies and chips form the hidden foundation of the world we live in today.

When you join ST, you will be part of a global business with more than 115 nationalities, present in 40 countries, and comprising over 50,000 diverse and dedicated creators and makers of technology around the world.

Developing technologies takes more than talent: it takes amazing people who understand collaboration and respect. People with passion and the desire to disrupt the status quo, drive innovation, and unlock their own potential.

Embark on a journey with us, where you can innovate for a future that we want to make smarter and greener, in a responsible and sustainable way. Our technology starts with you.

CONTEXT

We are looking to strengthen our MCU system architecture team lineup with an additional security architect, in consideration of the widening of its product base and of the imminent coming into effect of the european Cyber Resilience Act.

Role Summary

We are looking for a Security Architect to lead the definition, analysis, and implementation of hardware and software security features for part of our next-generation microcontroller products targeting automotive, industrial, humanoid robotics, and general purpose applications.

The ideal candidate will be a senior professional with deep expertise in security architectures, and with hands on experience in execution according to security standards (e.g. SESIP, ISO62443, ISO21434).

Key Responsibilities

  • Define security concepts and security architectures for microcontroller products.
  • Execute threat analysis activities and related risk assessments (e.g. automotive TARA), to drive the identification and definition of appropriate security features and countermeasures, and to develop guidance for proper usage of our microcontrollers.
  • Derive and document HW/SW security requirements from top-level security goals and use cases.
  • Identify and specify security features for the protection of assets and functionalities available in each product, such as:
    • intrusion protection mechanisms for debug and test interfaces
    • logical and physical isolation mechanisms
    • countermeasures against physical attacks
    • cryptographic accelerators
  • Through team alignment, ensure coherence of the security solutions deployed on our product-base, pursuing convergence whenever possible.
  • Develop and maintain security-related architectural documentation.
  • Cooperate with design, DFT, verification, validation, firmware, validation, and software teams to ensure security requirements are correctly implemented and verified.
  • Review product architecture against applicable standards and customer security requirements.
  • Support security claims and compliance arguments in internal and external audits, for the assigned products.
  • Participate in design reviews, risk assessments, and cross-functional security assessments.
  • Contribute to the definition of the roadmap for reusable security IP and architectural security guidelines.
  • Participate in Product Security Incident Response Team (PSIRT) activities for analysis of vulnerabilities on products of competence.
Required Qualifications

  • Degree in Electrical Engineering, Computer Engineering, Embedded Systems, or related field.
  • Experience in security architectures for microcontrollers, SoCs, or embedded systems.
  • Knowledge of security mechanisms and cryptographic operations.
  • Hands-on experience with security standards such as:
    • ISO21434 for automotive
    • ISO62443-4-x for industrial components
    • SESIP for IoT platforms
  • Experience in threat analysis.
  • Understanding of microcontroller architecture concepts as:
    • CPU and memory protection mechanisms
    • access control mechanisms
    • cryptographic HW accelerators