Cybersecurity Supplier Assessor

Siemens Energy, Inc.

Orlando (FL)

On-site

USD 110,000 - 170,000

Full time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health and wellness benefits
Paid time off
401K with company match
Family building benefits
Parental leave

Job summary

Siemens Energy, Inc. is seeking a Cybersecurity Supplier Assessor to protect our cybersecurity posture by evaluating the controls of suppliers and partners.

You will lead risk assessments, translate requirements into practical supplier controls, and support remediation plans within procurement, legal, and security teams. You will apply ISO 27001, NIST, and other frameworks while monitoring regulatory changes and promoting robust supplier risk management across the organization.

Qualifications

  • 5+ years of experience in information security auditing, cybersecurity risk assessment, or third-party risk management.
  • Strong understanding of risk management methodologies and frameworks (ISO 27001, NIST, COBIT).
  • Knowledge of U.S. federal compliance, supply chain security, export controls, and remediation planning in supplier programs.

Responsibilities

  • Conduct comprehensive cybersecurity assessments of third‑party suppliers, evaluating controls, policies, and risk posture.
  • Collaborate with Procurement, Legal, and Information Security to develop remediation plans and monitor risks.
  • Interpret contracts to ensure cybersecurity protections and compliance obligations are included.
  • Apply security standards and regulatory requirements to assess supplier compliance and benchmarking.
  • Monitor evolving threats and regulatory developments to improve assessment methodologies.
  • Communicate assessment outcomes and risk recommendations to stakeholders, including executive management, with travel ~10%.

Skills

Information security risk management
Third-party risk assessment
Stakeholder management
Security frameworks (ISO 27001, NIST)
Cloud security considerations

Education

Bachelor's degree in Computer Science / IT / Data Science / related field

Tools

CRISC
CISA
CCSK
CCAK
CSX Practitioner
ISO 27001 Lead Auditor
PMP

Job description

A Snapshot of Your Day

As a Cybersecurity Supplier Assessor at Siemens Energy, you will play a key role in protecting the organization’s cybersecurity posture by identifying, assessing, and managing risks associated with third-party suppliers and business partners. You will evaluate the cybersecurity controls, policies, and practices of new and existing suppliers, analyze potential vulnerabilities, and provide recommendations that support informed business decisions and strengthen supplier resilience. Working closely with Procurement, Legal, Information Security, and business stakeholders, you will help translate cybersecurity requirements into practical supplier controls, remediation plans, and contractual obligations. In this role, you will contribute to the continuous improvement of Siemens Energy’s third‑party risk management framework while helping safeguard our systems, services, products, and customers in an evolving threat landscape.

How You’ll Make an Impact
  • Conduct comprehensive cybersecurity assessments of new and existing third‑party suppliers, evaluating security controls, policies, processes, and overall risk posture; analyze findings to identify vulnerabilities, control gaps, and potential business risks.
  • Collaborate with Procurement, Legal, Information Security, and business stakeholders to develop, communicate, and implement supplier remediation plans, ensuring identified risks are appropriately prioritized, documented, monitored, and resolved.
  • Interpret cybersecurity requirements, legal clauses, and security obligations within supplier contracts, supporting negotiations with Procurement and Legal to ensure appropriate cybersecurity protections and compliance requirements are incorporated into supplier agreements.
  • Apply relevant cybersecurity frameworks, industry standards, and regulatory requirements to assess supplier compliance, including ISO 27001, NIST, NIST SP 800‑171, CMMC, and applicable supply chain security and export control requirements; support benchmarking of third‑party risk management practices, tools, and services.
  • Monitor emerging cybersecurity threats, regulatory developments, and industry best practices to continuously enhance supplier assessment methodologies, strengthen risk management processes, and promote the adoption of effective security controls, including application security standards and secure coding practices where applicable.
  • Drive continuous improvement in supplier cybersecurity resilience by communicating assessment outcomes and risk recommendations to stakeholders at all organizational levels, including executive management, while promoting collaboration, accountability, and consistent third‑party risk management practices. Travel internationally as required, anticipated to be at least 10%.
What You Bring
  • University degree in Computer Science, Data Science, Information Technology, a legal discipline, Technology or Business Management, or a related field.
  • 5+ years of relevant professional experience in information security auditing, cybersecurity risk assessment, third‑party risk management, or a related cybersecurity discipline, preferably with end‑to‑end supplier assessment responsibilities.
  • Strong understanding of information security risk management methodologies, cybersecurity principles, and recognized frameworks such as ISO 27001, NIST, COBIT, and industry best practices, including security considerations for cloud environments, networks, services, products, and operations.
  • Knowledge of NIST SP 800‑171, CMMC, CTPAT, and applicable U.S. cybersecurity, supply chain security, export control, and federal compliance requirements; experience integrating security standards, secure coding practices, and application security requirements into supplier remediation plans is highly valued.
  • Exceptional analytical skills and attention to detail, combined with strong communication, presentation, and stakeholder management capabilities. Ability to translate complex technical and regulatory requirements into clear risk assessments and actionable recommendations, collaborate effectively with Procurement, Legal, and suppliers, and communicate confidently with stakeholders through executive management.
  • Fluency in English is required, along with a willingness to travel internationally at least 10% of the time.
  • Relevant certifications such as CRISC, CISA, CCSK, CCAK, CSX Practitioner, ISO 27001 Lead Auditor, Project Management, or comparable qualifications are considered an advantage.
  • Applicants must be U.S. citizens and able to satisfy all applicable government, security, or export control requirements associated with the role.
  • Applicants must be legally authorized foremployment in the United States without need for current or futureemployer-sponsored work authorization. Siemens Energy employees with currentvisa sponsorship may be eligible for internal transfers.
About the Team

You will be part of a global team that provides cybersecurity support services for all Siemens Energy Divisions and Functions as well as all seven Siemens Energy hubs. You will also join our companywide cybersecurity community of more than 130 members.

Who is Siemens Energy?

At Siemens Energy, we are more than just anenergy technology company. With ~100,000 dedicated employees in more than 90countries, we develop the energy systems of the future, ensuring that thegrowing energy demand of the global community is met reliably and sustainably.The technologies created in our research departments and factories drive theenergy transition and provide the base for one sixth of the world's electricitygeneration.

Our global team is committed to makingsustainable, reliable, and affordable energy a reality by pushing theboundaries of what is possible. We uphold a 150-year legacy of innovation thatencourages our search for people who will support our focus on decarbonization,new technologies, and energy transformation.

Find out how you can make a difference atSiemens Energy: https://www.siemens-energy.com/employeevideo

Rewards
  • Career growth and development opportunities;supportive work culture
  • Company paid Health and wellness benefits
  • Paid Time Off and paid holidays
  • 401K savings plan with company match
  • Family building benefits
  • Parental leave

https://jobs.siemens-energy.com/jobs

Equal Employment Opportunity Statement

Siemens Energy is an Equal Opportunity and affirmative Action Employer encouraging diversity in the workplace. All qualified applicants will receive consideration for employment without regard to their race, color, creed, religion, national origin, citizenship status, ancestry, sex, age, physical or mental disability unrelated to ability, marital status, family responsibilities, pregnancy, genetic information, sexual orientation, gender expression, gender identity, transgender, sex stereotyping, order of protection status, protected veteran or military status, or an unfavorable discharge from military service, and other categories protected by federal, state or local

law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Supplier Quality Engineer
Supplier Quality Engineer

Siemens Gas and Power GmbH & Co. KG • Charlotte (NC)

On-site
USD 90,000 - 130,000
Opportunities to work with a global 팀
Medical benefits
Time off/Paid holidays and parental le
+2
Quality Specialist
Quality Specialist

Siemens Energy, Inc. • Orlando (FL)

On-site
USD 90,000 - 120,000
Health and wellness benefits
Paid time off
401K with company match
+2
Change Management Specialist
Change Management Specialist

Siemens Gas and Power GmbH & Co. KG • Gibsonton (FL)

On-site
USD 90,000 - 130,000
Career growth opportunities
Health and wellness benefits
Paid Time Off
+2
Technical Portfolio Lead - 3D AI Innovation
Technical Portfolio Lead - 3D AI Innovation

Siemens Gas and Power GmbH & Co. KG • Orlando (FL)

On-site
USD 140,000 - 190,000
Supplier Quality Engineer
Supplier Quality Engineer

Siemens Energy • Charlotte (NC)

On-site
USD 80,000 - 120,000
Opportunities to work with a global팀
Remote/Flexible work
Medical benefits
+3
Supplier Quality Engineer - Controls, Digitalization & Nuclear
Supplier Quality Engineer - Controls, Digitalization & Nuclear

Siemens Energy • Alpharetta (GA)

On-site
USD 90,000 - 120,000
Career growth
Health benefits
Paid time off
+2
Materials Laboratory Manager
Materials Laboratory Manager

Siemens Energy, Inc. • Orlando (FL)

On-site
USD 120,000 - 180,000
Health and wellness benefits
401K with company match
Paid time off
Project Engineering Manager
Project Engineering Manager

Siemens Gas and Power GmbH & Co. KG • Orlando (FL)

On-site
USD 140,000 - 210,000
Health benefits
401(k) match
Parental leave
Principal Technical Program Manager – Data Center Strategy & Transformation
Principal Technical Program Manager – Data Center Strategy & Transformation

Siemens Mobility • Bellevue (WA)

Remote
USD 154,000 - 278,000
Supplier Quality Engineer - Controls, Digitalization & Nuclear
Supplier Quality Engineer - Controls, Digitalization & Nuclear

Siemens Energy • Houston (TX)

On-site
USD 90,000 - 120,000
Career growth opportunities
Company paid Health benefits
Paid Time Off