About Nuvoton Israel
As a global semiconductor leader, Nuvoton Israel builds the hardware trust foundations powering modern computing - from trusted platform module (TPM) chips safeguarding millions of personal computers to complex root-of-trust architectures across cloud platforms and servers.
Security is embedded into the core of everything we design. As the global regulatory and threat landscape evolves, ensuring our products meet rigorous, gold-standard cybersecurity compliance and certifications is central to our mission and customer trust.
We are looking for a highly motivated Security Certifications & Compliance Engineer to join our team and play a key role in ensuring our products meet the highest security, compliance, and certification standards.
This position combines technical security expertise, compliance activities, product security governance, and collaboration with development teams to support industry-leading security products.
עיקרי התפקיד
Certifications: Lead and support security certification activities, including Common Criteria (CC), FIPS 140-3, CSPN, OCP SAFE, and additional certification programs.
Compliance & Frameworks: Support compliance initiatives related to the Cyber Resilience Act (CRA), Secure Development Lifecycle (SDL), NIST SSDF, and customer cybersecurity requirements.
Cross-Functional Teamwork: Work closely with engineering teams, management, customers, certification bodies, and security experts across the organization.
External Collaboration: Work closely with external laboratories and certification authorities throughout certification processes.
Security Readiness: Review development processes, project documentation, and deliverables to ensure compliance and security readiness.
Risk & Threat Assessment: Participate in threat modeling, risk assessments, security reviews, and secure development activities.
Audits & Standards: Prepare for and support internal audits, external audits, and customer security assessments.
Development Security System (DSS): Maintain, improve, and drive periodic activities for the Corporate Development Security System, including supporting security infrastructure, defining asset classifications, and driving employee awareness initiatives.
Documentation: Prepare, review, and maintain certification documentation, including Security Targets, Security Policies, certification reports, and lifecycle evidence.
דרישות
Education: B.Sc. in Computer Engineering, Electrical Engineering, Computer Science, Information Security, or a related field.
Experience: 5+ years of experience in at least one the following: Cybersecurity, Product Security, Secure Development, Security Compliance, Information Security, Security Certifications, or Security Audits
Domain Expertise: Background in the semiconductor industry.
Core Technical Knowledge: Strong understanding of some of these areas:
o Cryptography fundamentals
o Secure Development Lifecycle (SDL)
o Vulnerability management processes
o Threat Modeling and Risk Assessment
o Hardware and Embedded Security
o Firmware and Software Security
o Security Testing and Penetration Testing concepts
יתרון
Experience with Common Criteria (CC), FIPS 140-3 or other security certifications.
Familiarity with TPM technologies, Root of Trust architectures, Secure Boot and Post-Quantum Cryptography
Knowledge of Cyber Resilience Act (CRA) and NIST frameworks
Experience working with certification laboratories and regulatory bodies.
If you are passionate about silicon security and want to lead compliance for industry-defining hardware, send your CV to join our team.