Cybersecurity Governance Specialist (f/m/d) - Software Development (Agile)
We are seeking an experienced Cybersecurity Governance Specialist (f/m/d) to design, implement, and run our cybersecurity governance program for software development, making security governance an integrated part of our software development lifecycle.
You will collaborate closely and continuously with application development teams and security architects, translating regulatory and standards requirements (ISO/IEC 27001, IEC 62443, CRA) into governance that fits seamlessly into sprints, backlogs, and release cycles. You will implement security quality gates into our development process and measure compliance.
Operating independently with minimal day-to-day guidance, you will need sufficient technical grounding in the SDLC to build immediate credibility with engineers and architects.
What we offer you
- An attractive remuneration package
- Appealing Siemens pension benefits
- Access to Siemens share plans
- 30 days of paid vacation and a variety of flexible work schedules that allow time off for you and your family
- Flexible training opportunities for both your professional and personal development that you can tailor to your interests
Since each of over 300,000 team members feels that other benefits are particularly important, and we cannot list our entire benefit portfolio here, you can find more information here.
The individual benefits are subject to regulatory, contractual, or corporate conditions.
You’ll make an impact by
- Owning the design and maintenance of a cybersecurity governance framework specifically for the software development lifecycle, aligned with ISO/IEC 27001, IEC 62443, and CRA. Translating these standards into requirements that map onto Agile ceremonies and artifacts (e.g., Definition of Done, backlog refinement, sprint/release gates).
- Being responsible for integrating security checkpoints into the engineering lifecycle — architecture review gates, story/epic classification, quality gates at phase transitions — in partnership with security architects, so governance runs alongside delivery rather than blocking it.
- Delivering governance documentation (charters, operating models, decision frameworks) and running or supporting governance forums such as architecture review boards, where you'll work directly with security architects and engineering leads to review designs against approved security principles.
- Authoring, reviewing, and maintaining cybersecurity policies and standards for software development, ensuring they're usable by engineering teams day-to-day, not just compliant on paper.
- Owning governance decisions on risk acceptance and conditional approvals for development teams. Performing or supporting risk assessments for software/application systems (IT and OT contexts), and supporting audits and certifications (ISO 27001, CRA) covering the development organization.
- Delivering and maintaining governance KPIs/KRIs (e.g., security gate compliance rates, time-to-remediate findings) and reporting on program effectiveness to leadership.
This is how you'll win us over
- Education: You hold a master’s degree in computer science, Cybersecurity, Information Technology, or an equivalent qualification. A background combining technical expertise with governance or risk management is a strong advantage.
- Experience & Skills:
- Long-term experience in cybersecurity governance, GRC, or security architecture — specifically including experience in building or running a governance program for a software or application development organization.
- Strong practical understanding of Agile/Scrum delivery (sprints, backlogs, Definition of Done) and how governance controls are embedded within them. You should be able to speak the language of an engineering team, not just that of a compliance standard.
- Working technical understanding of application security and the SDLC (secure coding practices, vulnerability management, architecture review, SBOM/dependency management).
- Demonstrated experience in translating regulatory or standards frameworks (e.g., ISO/IEC 27001, IEC 62443, NIS2, CRA) into policy or process requirements that are practical and usable for engineering teams.
- Ability to operate with significant autonomy — defining your own work plan and driving deliverables to agreement with engineering stakeholders without close supervision.
- Familiarity with OT/ICS environments and practical application of IEC 62443, especially at the intersection of IT and OT software development.
- Relevant certifications (e.g., CISSP, CISM, ISO/IEC 27001 Lead Implementer/Auditor).
- Experience with EU Cyber Resilience Act (CRA) implementation in a software development context (e.g., SBOM, VEX lifecycle).
- Ways of working:
- Strong written communication skills; you will personally author policy and governance documents.
- Direct experience partnering with security architects on architecture review processes.
- Languages: Fluent in English; additional languages are advantageous.
You are much more than your qualifications, and we believe in the potential of every single candidate. We look forward to getting to know you!
At Siemens, we believe that feeling valued and included is the foundation for doing great work. That’s why we aim to create an inclusive workplace where everyone feels a sense of belonging, and where individual perspectives and experiences are celebrated. Our commitment to fairness and respect extends to every applicant.
As an equal opportunity employer, we welcome applications from individuals of all backgrounds and particularly encourage applications from persons with disabilities. In the case of equal qualifications, severely disabled applicants and applicants with equivalent status will be given preference.
About us
Here at Siemens Grid Software, our mission is to accelerate and secure the energy transition in a sustainable and profitable way. And for that we need you! We are paving the way for autonomous grid management empowering grid operators to accelerate their digital transformation easier, faster, and at scale.
By leaving behind traditional ways of tackling the net zero challenge and embracing the powerful capabilities of software and digital technology, we turn the complexity of grids into competitive advantage. No matter where power comes from or where it goes, we make sure it makes its way at every step.
Find out how Siemens Grid Software is decoding the future of energy.
Join our team, get inspired, and help us re-imagine the world!
www.siemens.de/careers – if you would like to find out more about jobs & careers at Siemens.
FAQ – if you need further information on the application process.

