Information Security Officer

Siemens AG
Rotterdam, NY, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$70,000.0 - $80,000.0
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Security CompTIA Security+ Cyber Security Information Technology Audit IT Management Systems Development Life Cycle Mendix Software Engineering Systems Integration Enterprise Data Management
+3 more
Google Cloud Cloud Platform System Software Version Control

Job description

The Mendix organization at Siemens Digital Industries Software is seeking a proactive and expert Information Security Officer to join our dynamic team. In this critical role, you will be instrumental in safeguarding our information assets, ensuring compliance with evolving regulatory landscapes, and encouraging a robust security culture across the organization. This position offers a significant opportunity to contribute to the integrity and resilience of our digital infrastructure.

What you’ll be doing:

As an Information Security Officer, you will be responsible for a range of strategic and operational security initiatives, including:

  • Control design & Operating Effectiveness: Design and evaluate the effectiveness of security controls, assessing their ability to mitigate risks and recommending improvements to ensure they operate as intended and achieve desired security outcomes.

  • Compliance Monitoring & Reporting: Proactively monitor compliance against various security frameworks and regulatory requirements (e.g., NIST, ISO 27001, SOC I & II, C5, ISO 42001). Provide actionable recommendations based on standards and report on progress to relevant stakeholders.

  • Audit Support: Support internal and external audits by gathering, assessing, and providing necessary evidence to demonstrate compliance.

  • Evidence lifecycle management: Manage the entire lifecycle of security evidence, from collection and secure storage to version control and eventual archival, ensuring its integrity and availability for audits and compliance checks.

  • Policy & Standard Development: Research, establish, and maintain robust information security policies, standards, and procedures tailored to specific organizational needs and emerging threats.

  • Security Culture & Communication: Communicate effectively about information security risks, standards, and policy updates, fostering a strong security-conscious culture across the organization.

  • Control Implementation & Maintenance: Collaborate with applicable departments to ensure security controls are effectively implemented, maintained, and continuously optimized.

Requirements

  • Experience: 3-5 years of progressive experience in an Information Security, IT Audit, or Compliance role, demonstrating a solid understanding of information security principles and practices.

  • Cloud Security Expertise: Solid understanding of security operations, controls, and best practices within cloud environments (e.g., AWS, Azure, GCP). Experience with cloud security frameworks and tools is highly desirable.

  • Framework & Regulation Knowledge: In-depth knowledge and practical experience with a range of information security standards, frameworks, and regulations (e.g., ISO/IEC 27001 family, GDPR, SOC 2 Trust principles).

  • Enterprise IT Familiarity: Familiarity with enterprise data environments, system integrations, and software development lifecycles (SDLC).

  • Certifications: An independent and active information security certification (e.g., CISM, CISSP, ISO 27001 Lead Implementer, CompTIA Security+) is required.

  • Analytical & Problem-Solving: Exceptional analytical and problem-solving abilities to perform detailed gap analyses, identify root causes, and develop practical, effective security solutions.

  • Communication: Excellent written and verbal communication skills in English, with the ability to articulate complex security concepts clearly to both technical and non-technical audiences.

  • Initiative & Collaboration: High level of initiative, self-direction, and the ability to work independently while also being a strong team player and collaborating effectively across departments.

About the company

A collection of over 377,000 minds building the future, one day at a time in over 200 countries. We’re dedicated to equality, and we welcome applications that reflect the diversity of the communities we work in. All employment decisions at Siemens are based on qualifications, merit, and business need. Bring your curiosity and creativity and help us shape tomorrow.

The salary range for this position is €70,000- €80,000 and this role is eligible to earn incentive compensation. The actual compensation offered is based on the successful candidate’s job-related skills, experience, and relevant education/training. Siemens offers health and wellness benefits to employees; you can access the benefits available in your country via the link: Benefits Siemens Digital Industries Software. (https://jobs.sw.siemens.com/benefits/)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on juju.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · WWC 2025

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · WWC 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

5:00 min

Managing complex state with scope-based resource management

Bjarne Stroustrup · WWC 2022

4:42 min

Container hosting options available on Google Cloud Platform

Federico Fregosi · WWC 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all