ForgeApply · Job listing
Manager - Product Security
Microchip Technology
Tailor your resume to this posting in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Microchip Technology's site. Free trial, no card required.
About this role
Are you looking for a unique opportunity to be a part of something great? Want to join a 17,000-member team that works on the technology that powers the world around us? Looking for an atmosphere of trust, empowerment, respect, diversity, and communication? How about an opportunity to own a piece of a multi-billion dollar (with a B!) global organization? We offer all that and more at Microchip Technology Inc.
People come to work at Microchip because we help design the technology that runs the world. They stay because our culture supports their growth and stability. They are challenged and driven by an incredible array of products and solutions with unlimited career potential. Microchip’s nationally-recognized Leadership Passage Programs support career growth where we proudly enroll over a thousand people annually. We take pride in our commitment to employee development, values-based decision making, and strong sense of community, driven by our Vision, Mission, and 11 Guiding Values ; we affectionately refer to it as the Aggregate System and it’s won us countless awards for diversity and workplace excellence.
Our company is built by dedicated team players who love to challenge the status quo; we did not achieve record revenue and over 30 years of quarterly profitability without a great team dedicated to empowering innovation. People like you.
Visit our careers page to see what exciting opportunities and company perks await!
Job Description:
Join the Team That's Securing the Future of Embedded Intelligence At Microchip Technology, our products power the world — from automotive systems and industrial automation to aerospace, medical devices, and the Internet of Things. As cybersecurity regulations intensify globally and threats to embedded systems grow more sophisticated, Microchip is making a bold investment in product security leadership. This is your opportunity to be at the center of that transformation.
We are seeking a Manager, Product Security Governance to join our Product Security Office (PSO) — a high-visibility team shaping how security is embedded into silicon, firmware, and software across one of the world's leading semiconductor companies. Reporting to the Head of the Product Security Office, you will serve as a senior leader helping to define governance frameworks, drive cross-functional adoption, and strengthen regulatory readiness on a global scale.
You'll be shaping the foundation — establishing scalable processes, enabling engineering teams across Business Units, and driving measurable progress in threat modeling, vulnerability management, regulatory readiness, and supply chain security governance. You'll work at the intersection of cybersecurity strategy, engineering execution, and global standards — with direct impact on Microchip's ability to ship trusted, compliant, and resilient products worldwide.
Key Responsibilities 1. Product Security Governance, Risk & Regulatory Readiness • Define and guide the deployment of product security governance frameworks across Business Units. • Establish consistent methodologies for product security risk classification, threat modeling, and regulatory scoping. • Translate evolving cybersecurity regulations, standards, and guidance into actionable internal requirements and governance expectations. • Support company-wide readiness for the EU Cyber Resilience Act and other applicable global cybersecurity requirements. • Align product security governance with Corporate Quality workflows, new product development processes and product release governance. • Define security checkpoints for new products, new features and software releases. • Serve as an escalation point for complex product security classifications, threat scenarios, and interpretation questions. • Maintain product security governance dashboards, maturity metrics, and executive reporting inputs. • Coordinate with notified bodies, certification labs, and relevant industry associations and external partners, as needed.
2. PSIRT & Vulnerability Management Governance • Define and govern product vulnerability management processes within the Product Security Office. • Establish governance frameworks for vulnerability intake, triage, validation, severity assessment, remediation coordination, disclosure, advisory publication, and regulatory reporting. • Guide alignment of PSIRT practices with applicable international standards for vulnerability disclosure, handling and coordinated response. • Support consistent vulnerability handling across company-developed products, third-party components, open-source software, and supplier-provided software or IP. • Define escalation criteria for actively exploited vulnerabilities, critical product security incidents, supplier compromises, and customer-impacting issues. • Support CVE assignment and CNA-related activities, where applicable. • Establish metrics and KPIs for vulnerability handling, including intake volume, triage timeliness, remediation progress, advisory publication timelines, and overdue actions. • Partner with Legal, Engineering, Customer Support, Field Applications, and Business Units to support coordinated handling of sensitive vulnerability cases.
3. Threat Modeling & Product Risk Classification • Define and govern the enterprise framework for threat modeling and product risk classification within the Product Security Office. • Develop and maintain threat modeling templates, decision trees, risk libraries, and assessment criteria for use across Business Units. • Train and enable Business Unit security champions, product architects, and engineering teams on threat modeling methodologies. • Guide the integration of threat modeling into product lifecycle and quality processes in partnership with Business Units. • Provide guidance on the use of applicable threat intelligence, emerging attack techniques, and relevant frameworks such as MITRE ATT&CK, EMB3D, STRIDE, OWASP, IEC 62443-4-1, and ISO 21434. • Support product team
Ready to apply to Microchip Technology?
Tailor my resume for this roleSimilar jobs
- Manager, Product Security Engineering — Dragos · Remote
- Manager, Product Security Foundations — Andurilindustries · Costa Mesa, California, United States
- Senior Engineering Manager, Product Security — Monarchmoney · Remote
- Senior Security Engineering Manager, Product Security — Upstart · Remote
- Staff Product Manager - Security — Lambda · Bellevue Office
- Head of Product Security — Harvey · San Francisco
- Head of Product Security — Harvey · New York
- Staff Product Manager, Security Products — Digitalocean98 · Seattle
More like this: More jobs at Microchip Technology · Browse all jobs