> Markdown version of [/jobs/ext/3212507-product-and-solution-security-officer](https://www.wearedevelopers.com/jobs/ext/3212507-product-and-solution-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Product and Solution Security Officer - **Company:** Siemens AG - **Location:** Nürnberg, Germany - **Contract:** Permanent contract - **Skills:** Agile Methodology, CompTIA Security+, Cyber Security, DevOps, Secure Coding, Software Engineering, Containerization, Information Technology - **Published:** September 16, 2026 - **Apply:** https://www.arbeitsagentur.de/jobsuche/jobdetail/12465-1633551-1-S ## About the Role Education: You hold a Master's degree in Computer Science, Information Technology, or a comparable background. (Cybersecurity certifications such as CISSP or CSSLP are an advantage).- Experience & Skills: - Extensive long-term experience and demonstrated expertise in cybersecurity, software development, and engineering, including in-depth knowledge of IT/Cybersecurity requirements.- Deep knowledge of IEC 62443, ISO 27000, and related standards, with years of experience in IT/Cybersecurity for product development, solution design, and OT operations.- Proven track record in implementing regulatory requirements within agile environments.- Experience in managing or supporting the release of large-scale software projects, with a strong proficiency in conducting risk assessments and implementing subsequent risk management strategies.- Active commitment to knowledge sharing, including the initiation of "Communities of Practice" and the creation of technical blueprints, templates, and building blocks.- Strong proficiency in agile development and DevOps principles, including a solid understanding of CI/CD pipelines and container technologies.- Practical experience with agile scaling frameworks such as LeSS or SAFe.- Experience working in international, multicultural agile organizations with a high degree of quality awareness.- Ability to structure and guide new security-related processes and regulations across the entire organization. - Ways of working: - Analytical thinking, strong problem-solving skills, and reliability, even in complex situations.- Proven ability to collaborate efficiently across functional and project boundaries, with the skill to effectively communicate complex content and risks to stakeholders at all organizational levels, including senior management.- A proactive mindset and the willingness to go the extra mile as part of our ambitious and multicultural SI GSW team. - Languages: Professional proficiency in English is required; German language skills are an advantage. ## Description We are looking for a visionary Product and Solution Security Officer (PSSO) to champion our PSS program within Siemens SI GSW. As a key driver of our continuous quality culture, you will ensure that cybersecurity is deeply integrated into our software development lifecycle. Acting as a 'Continuous Security Agent,' you will partner with the Agile Program Management Office (APMO) to bring state-of-the-art security innovations to our agile teams. You will build vibrant communities and guilds to promote a culture of continuous learning. As a trusted advisor, you will guide R&D and PLM leadership, collaborating closely with the SI GSW Cybersecurity Officer to provide functional guidance to our network of PSSEs. What we offer you, Defining and maintaining cybersecurity policies, strategies, and roadmaps for the business unit, ensuring alignment with international standards and attestations such as ISO/IEC 27001, IEC 62443, NIS2, and SOC2.- Steering improvement programs to integrate secure development practices - including threat and risk analysis, secure coding, and security testing - directly into the agile software development lifecycle of SI GSW.- Leading cybersecurity compliance activities and providing expert guidance on security requirements to ensure adherence to regulations like the Cyber Resilience Act (CRA) and IEC 62443.- Managing product vulnerabilities and incidents while collaborating with stakeholders to identify security risks and define clear risk acceptance criteria for our solutions.- Driving innovative IT/Cybersecurity initiatives from Proof of Concept (PoC) to productive use by partnering with PSSEs, Release Train Engineers, and agile development teams.- Guiding stakeholders and fostering a culture of continuous learning by emphasizing technological security needs to Product Managers, Owners, and Architects to ensure sustainable security expertise.- Measuring and reporting the status of adherence to PSS standards and policies, while representing the R&D department in all product and solution security matters., At Siemens, we believe that feeling valued and included is the foundation for doing great work. That's why we aim to create an inclusive workplace where everyone feels a sense of belonging, and where individual perspectives and experiences are celebrated. Our commitment to fairness and respect extends to every applicant. As an [equal opportunity employer](http://www.siemens.com/global/en/company/sustainability/social-commitments/belonging.html), we welcome applications from individuals of all backgrounds and particularly encourage applications from persons with disabilities. In the case of equal qualifications, severely disabled applicants and applicants with equivalent status will be given preference. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Shifting Stress to Progress— Understanding DevOps to do DevOps Better](https://www.wearedevelopers.com/videos/268-shifting-stress-to-progress-understanding-devops-to-do-devops-better) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) ## Related Articles - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Best Companies to Work For in Germany: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/33-best-companies-to-work-for-in-germany-top-25-companies-in-2023) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany)