> Markdown version of [/jobs/ext/3256134-cybersecurity-governance-specialist-software-development-agile](https://www.wearedevelopers.com/jobs/ext/3256134-cybersecurity-governance-specialist-software-development-agile). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Governance Specialist - Software Development (Agile) - **Company:** Siemens AG - **Location:** Nürnberg, Germany - **Contract:** Permanent contract - **Skills:** Agile Methodology, Cyber Security, Scrum Methodology, Systems Development Life Cycle, Secure Coding, Software Engineering, Software Vulnerability Management, Software Security, Information Technology - **Published:** September 18, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=476481fb30d4a802 ## About the Role * Education: You hold a master's degree in computer science, Cybersecurity, Information Technology, or an equivalent qualification. A background combining technical expertise with governance or risk management is a strong advantage., + Long-term experience in cybersecurity governance, GRC, or security architecture - specifically including experience in building or running a governance program for a software or application development organization. + Strong practical understanding of Agile/Scrum delivery (sprints, backlogs, Definition of Done) and how governance controls are embedded within them. You should be able to speak the language of an engineering team, not just that of a compliance standard. + Working technical understanding of application security and the SDLC (secure coding practices, vulnerability management, architecture review, SBOM/dependency management). + Demonstrated experience in translating regulatory or standards frameworks (e.g., ISO/IEC 27001, IEC 62443, NIS2, CRA) into policy or process requirements that are practical and usable for engineering teams. + Ability to operate with significant autonomy - defining your own work plan and driving deliverables to agreement with engineering stakeholders without close supervision. + Familiarity with OT/ICS environments and practical application of IEC 62443, especially at the intersection of IT and OT software development. + Relevant certifications (e.g., CISSP, CISM, ISO/IEC 27001 Lead Implementer/Auditor). + Experience with EU Cyber Resilience Act (CRA) implementation in a software development context (e.g., SBOM, VEX lifecycle). * Ways of working: * + Strong written communication skills; you will personally author policy and governance documents. + Direct experience partnering with security architects on architecture review processes. * Languages: Fluent in English; additional languages are advantageous. ## Description You will collaborate closely and continuously with application development teams and security architects, translating regulatory and standards requirements (ISO/IEC 27001, IEC 62443, CRA) into governance that fits seamlessly into sprints, backlogs, and release cycles. You will implement security quality gates into our development process and measure compliance. Operating independently with minimal day-to-day guidance, you will need sufficient technical grounding in the SDLC to build immediate credibility with engineers and architects., * Owning the design and maintenance of a cybersecurity governance framework specifically for the software development lifecycle, aligned with ISO/IEC 27001, IEC 62443, and CRA. Translating these standards into requirements that map onto Agile ceremonies and artifacts (e.g., Definition of Done, backlog refinement, sprint/release gates). * Being responsible for integrating security checkpoints into the engineering lifecycle - architecture review gates, story/epic classification, quality gates at phase transitions - in partnership with security architects, so governance runs alongside delivery rather than blocking it. * Delivering governance documentation (charters, operating models, decision frameworks) and running or supporting governance forums such as architecture review boards, where you'll work directly with security architects and engineering leads to review designs against approved security principles. * Authoring, reviewing, and maintaining cybersecurity policies and standards for software development, ensuring they're usable by engineering teams day-to-day, not just compliant on paper. * Owning governance decisions on risk acceptance and conditional approvals for development teams. Performing or supporting risk assessments for software/application systems (IT and OT contexts), and supporting audits and certifications (ISO 27001, CRA) covering the development organization. * Delivering and maintaining governance KPIs/KRIs (e.g., security gate compliance rates, time-to-remediate findings) and reporting on program effectiveness to leadership. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [ShapeShift: Reinventing Agile for a B2B SaaS Scale-Up](https://www.wearedevelopers.com/videos/1655-shapeshift-reinventing-agile-for-a-b2b-saas-scale-up) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [The Ultimate Software Engineer Career Path Guide for 2023](https://www.wearedevelopers.com/magazine/146-the-ultimate-software-engineer-career-path-guide-for-2023) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs)