Cybersecurity Governance Specialist - Software Development (Agile)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
You will collaborate closely and continuously with application development teams and security architects, translating regulatory and standards requirements (ISO/IEC 27001, IEC 62443, CRA) into governance that fits seamlessly into sprints, backlogs, and release cycles. You will implement security quality gates into our development process and measure compliance. Operating independently with minimal day-to-day guidance, you will need sufficient technical grounding in the SDLC to build immediate credibility with engineers and architects., * Owning the design and maintenance of a cybersecurity governance framework specifically for the software development lifecycle, aligned with ISO/IEC 27001, IEC 62443, and CRA. Translating these standards into requirements that map onto Agile ceremonies and artifacts (e.g., Definition of Done, backlog refinement, sprint/release gates).
- Being responsible for integrating security checkpoints into the engineering lifecycle - architecture review gates, story/epic classification, quality gates at phase transitions - in partnership with security architects, so governance runs alongside delivery rather than blocking it.
- Delivering governance documentation (charters, operating models, decision frameworks) and running or supporting governance forums such as architecture review boards, where you’ll work directly with security architects and engineering leads to review designs against approved security principles.
- Authoring, reviewing, and maintaining cybersecurity policies and standards for software development, ensuring they’re usable by engineering teams day-to-day, not just compliant on paper.
- Owning governance decisions on risk acceptance and conditional approvals for development teams. Performing or supporting risk assessments for software/application systems (IT and OT contexts), and supporting audits and certifications (ISO 27001, CRA) covering the development organization.
- Delivering and maintaining governance KPIs/KRIs (e.g., security gate compliance rates, time-to-remediate findings) and reporting on program effectiveness to leadership.
Requirements
- Education: You hold a master’s degree in computer science, Cybersecurity, Information Technology, or an equivalent qualification. A background combining technical expertise with governance or risk management is a strong advantage., + Long-term experience in cybersecurity governance, GRC, or security architecture - specifically including experience in building or running a governance program for a software or application development organization.
- Strong practical understanding of Agile/Scrum delivery (sprints, backlogs, Definition of Done) and how governance controls are embedded within them. You should be able to speak the language of an engineering team, not just that of a compliance standard.
- Working technical understanding of application security and the SDLC (secure coding practices, vulnerability management, architecture review, SBOM/dependency management).
- Demonstrated experience in translating regulatory or standards frameworks (e.g., ISO/IEC 27001, IEC 62443, NIS2, CRA) into policy or process requirements that are practical and usable for engineering teams.
- Ability to operate with significant autonomy - defining your own work plan and driving deliverables to agreement with engineering stakeholders without close supervision.
- Familiarity with OT/ICS environments and practical application of IEC 62443, especially at the intersection of IT and OT software development.
- Relevant certifications (e.g., CISSP, CISM, ISO/IEC 27001 Lead Implementer/Auditor).
- Experience with EU Cyber Resilience Act (CRA) implementation in a software development context (e.g., SBOM, VEX lifecycle).
-
Ways of working: *
- Strong written communication skills; you will personally author policy and governance documents.
- Direct experience partnering with security architects on architecture review processes.
- Languages: Fluent in English; additional languages are advantageous.
Benefits & conditions
- An attractive remuneration package
- Appealing Siemens pension benefits
- Access to Siemens share plans
- 30 days of paid vacation and a variety of flexible work schedules that allow time off for you and your family
- Flexible training opportunities for both your professional and personal development that you can tailor to your interests
Since each of over 300,000 team members feels that other benefits are particularly important, and we cannot list our entire benefit portfolio here, you can find more information here.
The individual benefits are subject to regulatory, contractual, or corporate conditions.
About the company
You are much more than your qualifications, and we believe in the potential of every single candidate. We look forward to getting to know you!
At Siemens, we believe that feeling valued and included is the foundation for doing great work. That’s why we aim to create an inclusive workplace where everyone feels a sense of belonging, and where individual perspectives and experiences are celebrated. Our commitment to fairness and respect extends to every applicant.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
The Most Popular IT Jobs on the Market
The Ultimate Software Engineer Career Path Guide for 2023
Top-Paying Tech Jobs (with Salaries)
IT Salaries in Germany