Cybersecurity Governance Specialist - Software Development (Agile)

Siemens AG
Nürnberg, Germany
14 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Agile Methodology Cyber Security Scrum Methodology Systems Development Life Cycle Secure Coding Software Engineering Software Vulnerability Management Software Security Information Technology

Job description

You will collaborate closely and continuously with application development teams and security architects, translating regulatory and standards requirements (ISO/IEC 27001, IEC 62443, CRA) into governance that fits seamlessly into sprints, backlogs, and release cycles. You will implement security quality gates into our development process and measure compliance. Operating independently with minimal day-to-day guidance, you will need sufficient technical grounding in the SDLC to build immediate credibility with engineers and architects., * Owning the design and maintenance of a cybersecurity governance framework specifically for the software development lifecycle, aligned with ISO/IEC 27001, IEC 62443, and CRA. Translating these standards into requirements that map onto Agile ceremonies and artifacts (e.g., Definition of Done, backlog refinement, sprint/release gates).

  • Being responsible for integrating security checkpoints into the engineering lifecycle - architecture review gates, story/epic classification, quality gates at phase transitions - in partnership with security architects, so governance runs alongside delivery rather than blocking it.
  • Delivering governance documentation (charters, operating models, decision frameworks) and running or supporting governance forums such as architecture review boards, where you’ll work directly with security architects and engineering leads to review designs against approved security principles.
  • Authoring, reviewing, and maintaining cybersecurity policies and standards for software development, ensuring they’re usable by engineering teams day-to-day, not just compliant on paper.
  • Owning governance decisions on risk acceptance and conditional approvals for development teams. Performing or supporting risk assessments for software/application systems (IT and OT contexts), and supporting audits and certifications (ISO 27001, CRA) covering the development organization.
  • Delivering and maintaining governance KPIs/KRIs (e.g., security gate compliance rates, time-to-remediate findings) and reporting on program effectiveness to leadership.

Requirements

  • Education: You hold a master’s degree in computer science, Cybersecurity, Information Technology, or an equivalent qualification. A background combining technical expertise with governance or risk management is a strong advantage., + Long-term experience in cybersecurity governance, GRC, or security architecture - specifically including experience in building or running a governance program for a software or application development organization.
  • Strong practical understanding of Agile/Scrum delivery (sprints, backlogs, Definition of Done) and how governance controls are embedded within them. You should be able to speak the language of an engineering team, not just that of a compliance standard.
  • Working technical understanding of application security and the SDLC (secure coding practices, vulnerability management, architecture review, SBOM/dependency management).
  • Demonstrated experience in translating regulatory or standards frameworks (e.g., ISO/IEC 27001, IEC 62443, NIS2, CRA) into policy or process requirements that are practical and usable for engineering teams.
  • Ability to operate with significant autonomy - defining your own work plan and driving deliverables to agreement with engineering stakeholders without close supervision.
  • Familiarity with OT/ICS environments and practical application of IEC 62443, especially at the intersection of IT and OT software development.
  • Relevant certifications (e.g., CISSP, CISM, ISO/IEC 27001 Lead Implementer/Auditor).
  • Experience with EU Cyber Resilience Act (CRA) implementation in a software development context (e.g., SBOM, VEX lifecycle).
  • Ways of working: *

  • Strong written communication skills; you will personally author policy and governance documents.
  • Direct experience partnering with security architects on architecture review processes.
  • Languages: Fluent in English; additional languages are advantageous.

Benefits & conditions

  • An attractive remuneration package
  • Appealing Siemens pension benefits
  • Access to Siemens share plans
  • 30 days of paid vacation and a variety of flexible work schedules that allow time off for you and your family
  • Flexible training opportunities for both your professional and personal development that you can tailor to your interests

Since each of over 300,000 team members feels that other benefits are particularly important, and we cannot list our entire benefit portfolio here, you can find more information here.

The individual benefits are subject to regulatory, contractual, or corporate conditions.

About the company

You are much more than your qualifications, and we believe in the potential of every single candidate. We look forward to getting to know you!

At Siemens, we believe that feeling valued and included is the foundation for doing great work. That’s why we aim to create an inclusive workplace where everyone feels a sense of belonging, and where individual perspectives and experiences are celebrated. Our commitment to fairness and respect extends to every applicant.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:24 min

Connecting effective communication frameworks with agile methodology

Alexandre Borges · World Congress 2022

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

2:47 min

Securing code provenance with digital identity signatures

Marcus Ross Marcus Ross · World Congress 2026 Europe

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all