Cybersecurity Governance Specialist (f/m/d) - Software Development (Agile)

Siemens

Nürnberg

On-site

EUR 90,000 - 120,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Remuneration package
Pension benefits
Share plans
30 days vacation
Flexible work schedules
Training opportunities

Job summary

Siemens Grid Software seeks an experienced Cybersecurity Governance Specialist to design, implement, and run our governance program for software development. You will translate regulatory requirements into governance for sprints, backlogs, and release cycles, and embed security gates into the SDLC.

You will collaborate with development teams and security architects, delivering policies, KPIs, and risk-based approvals.

Qualifications

  • Masters degree in computer science, cybersecurity, information technology or equivalent.
  • Strong background translating regulatory standards into practical governance for engineering teams.
  • Experience building governance programs within software development lifecycles and agile environments.

Responsibilities

  • Owns design and maintenance of a cybersecurity governance framework for the SDLC.
  • Integrates security checkpoints into engineering lifecycle with architecture review gates.
  • Delivers governance docs and runs governance forums with security architects and leads.
  • Author or maintain cybersecurity policies and standards for developers.
  • Makes governance decisions on risk acceptance and approvals; supports audits and certifications.
  • Provides governance KPIs/KRIs and reports to leadership on program effectiveness.

Skills

Cybersecurity governance
GRC
Security architecture
Agile/Scrum
SDLC understanding
Vulnerability management
Policy development
Risk management
English proficiency
Compliance standards

Education

Master's degree in Computer Science or Cybersecurity or IT

Job description

We are seeking an experienced Cybersecurity Governance Specialist (f/m/d) to design, implement, and run our cybersecurity governance program for software development, making security governance an integrated part of our software development lifecycle.

You will collaborate closely and continuously with application development teams and security architects, translating regulatory and standards requirements (ISO/IEC 27001, IEC 62443, CRA) into governance that fits seamlessly into sprints, backlogs, and release cycles. You will implement security quality gates into our development process and measure compliance.

Operating independently with minimal day-to-day guidance, you will need sufficient technical grounding in the SDLC to build immediate credibility with engineers and architects.

What We Offer You
  • An attractive remuneration package
  • Appealing Siemens pension benefits
  • Access to Siemens share plans
  • 30 days of paid vacation and a variety of flexible work schedules that allow time off for you and your family
  • Flexible training opportunities for both your professional and personal development that you can tailor to your interests

Since each of over 300,000 team members feels that other benefits are particularly important, and we cannot list our entire benefit portfolio here, you can find more information here.

The individual benefits are subject to regulatory, contractual, or corporate conditions.

You’ll make an impact by
  • Owning the design and maintenance of a cybersecurity governance framework specifically for the software development lifecycle, aligned with ISO/IEC 27001, IEC 62443, and CRA. Translating these standards into requirements that map onto Agile ceremonies and artifacts (e.g., Definition of Done, backlog refinement, sprint/release gates).
  • Being responsible for integrating security checkpoints into the engineering lifecycle — architecture review gates, story/epic classification, quality gates at phase transitions — in partnership with security architects, so governance runs alongside delivery rather than blocking it.
  • Delivering governance documentation (charters, operating models, decision frameworks) and running or supporting governance forums such as architecture review boards, where you'll work directly with security architects and engineering leads to review designs against approved security principles.
  • Authoring, reviewing, and maintaining cybersecurity policies and standards for software development, ensuring they're usable by engineering teams day-to-day, not just compliant on paper.
  • Owning governance decisions on risk acceptance and conditional approvals for development teams. Performing or supporting risk assessments for software/application systems (IT and OT contexts), and supporting audits and certifications (ISO 27001, CRA) covering the development organization.
  • Delivering and maintaining governance KPIs/KRIs (e.g., security gate compliance rates, time-to-remediate findings) and reporting on program effectiveness to leadership.
This Is How You'll Win Us Over
  • Education: You hold a master’s degree in computer science, Cybersecurity, Information Technology, or an equivalent qualification. A background combining technical expertise with governance or risk management is a strong advantage.
  • Experience & Skills:
    • Long-term experience in cybersecurity governance, GRC, or security architecture — specifically including experience in building or running a governance program for a software or application development organization.
    • Strong practical understanding of Agile/Scrum delivery (sprints, backlogs, Definition of Done) and how governance controls are embedded within them. You should be able to speak the language of an engineering team, not just that of a compliance standard.
    • Working technical understanding of application security and the SDLC (secure coding practices, vulnerability management, architecture review, SBOM/dependency management).
    • Demonstrated experience in translating regulatory or standards frameworks (e.g., ISO/IEC 27001, IEC 62443, NIS2, CRA) into policy or process requirements that are practical and usable for engineering teams.
    • Ability to operate with significant autonomy — defining your own work plan and driving deliverables to agreement with engineering stakeholders without close supervision.
    • Familiarity with OT/ICS environments and practical application of IEC 62443, especially at the intersection of IT and OT software development.
    • Relevant certifications (e.g., CISSP, CISM, ISO/IEC 27001 Lead Implementer/Auditor).
    • Experience with EU Cyber Resilience Act (CRA) implementation in a software development context (e.g., SBOM, VEX lifecycle).
  • Ways of working:
    • Strong written communication skills; you will personally author policy and governance documents.
    • Direct experience partnering with security architects on architecture review processes.
  • Languages: Fluent in English; additional languages are advantageous.

You are much more than your qualifications, and we believe in the potential of every single candidate. We look forward to getting to know you!

At Siemens, we believe that feeling valued and included is the foundation for doing great work. That’s why we aim to create an inclusive workplace where everyone feels a sense of belonging, and where individual perspectives and experiences are celebrated. Our commitment to fairness and respect extends to every applicant.

As an equal opportunity employer, we welcome applications from individuals of all backgrounds and particularly encourage applications from persons with disabilities. In the case of equal qualifications, severely disabled applicants and applicants with equivalent status will be given preference.

About Us

Here at Siemens Grid Software, our mission is to accelerate and secure the energy transition in a sustainable and profitable way. And for that we need you! We are paving the way for autonomous grid management empowering grid operators to accelerate their digital transformation easier, faster, and at scale.

By leaving behind traditional ways of tackling the net zero challenge and embracing the powerful capabilities of software and digital technology, we turn the complexity of grids into competitive advantage. No matter where power comes from or where it goes, we make sure it makes its way at every step.

Find out how Siemens Grid Software is decoding the future of energy.

Join our team, get inspired, and help us re-imagine the world!

www.siemens.de/careers – if you would like to find out more about jobs & careers at Siemens.

FAQ – if you need further information on the application process.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Product & Solution Security Officer and CRA (f/m/d)
Product & Solution Security Officer and CRA (f/m/d)

Siemens • Nürnberg

Hybrid
EUR 110,000 - 140,000
Remuneration package
Pension benefits
Siemens share plans
+3
Product & Solution Security Officer and CRA (f/m/d)
Product & Solution Security Officer and CRA (f/m/d)

Arbeitsagentur • Nürnberg

On-site
EUR 120,000 - 180,000
Siemens pension benefits
Siemens share plans
30 days of paid vacation
+2
Cybersecurity Auditor (m/f/d) - DISW
Cybersecurity Auditor (m/f/d) - DISW

Siemens Digital Industries Software • München

On-site
EUR 61,400 - 98,400
Mobile working 2–3 days/week
Share matching programs
Pension plan
+1
Senior Cybersecurity Auditor (m/f/d) - DISW - Inklusiver Job
Senior Cybersecurity Auditor (m/f/d) - DISW - Inklusiver Job

Siemens AG • Bayern

On-site
EUR 80,000 - 135,000
Mobile working 2-3 days/week
Share matching programme
Pension plan
+2
Experienced Cybersecurity Auditor (m/f/d) - DISW
Experienced Cybersecurity Auditor (m/f/d) - DISW

Siemens Digital Industries Software • München

On-site
EUR 67,000 - 116,000
Mobile working 2-3 days per week
Belonging and inclusion
30 leave days
+3
Senior Cybersecurity Auditor (m/f/d) - DISW
Senior Cybersecurity Auditor (m/f/d) - DISW

Siemens Digital Industries Software • München

On-site
EUR 80,000 - 135,000
Mobile working 2-3 days/week
Pension plan
30 leave days
+2
Senior Cybersecurity Auditor (m/f/d) - DISW
Senior Cybersecurity Auditor (m/f/d) - DISW

Siemens AG • München

On-site
EUR 79,700 - 135,400
Share‑matching programme
Pension plan
30 days leave
+2
Cybersecurity Transformation Program Lead (f/m/d)
Cybersecurity Transformation Program Lead (f/m/d)

Arbeitsagentur • Karlsruhe

Remote
EUR 110,000 - 160,000
Flexible work options
Remote-friendly policy
Competitive retirement plan
+2
Experienced Cybersecurity Auditor (m/f/d)
Experienced Cybersecurity Auditor (m/f/d)

Siemens AG • Erlangen

On-site
EUR 65,000 - 95,000
30 leave days
Share matching program
Pension plan
+1
Red Teamer / Pentester - Cybersecurity Audit (m/f/d) - DISW
Red Teamer / Pentester - Cybersecurity Audit (m/f/d) - DISW

Siemens AG • München

On-site
EUR 61,400 - 98,400
2–3 days mobile working per week
Share matching program
Pension plan
+2