Product and Solution Security Officer | Product & Solution Security Officer and CRA

Siemens AG

Nürnberg, Mittelfranken, Bayern, Deutschland
Published Apr 15, 2026
Full-time
No information

Job Summary

As a Product and Solution Security Officer (PSSO), you will be the primary driver for cybersecurity excellence within the Siemens Smart Infrastructure Grid Software Business Unit. Working within an Agile Program Management Office, you will act as a 'Continuous Security Agent,' collaborating with agile development teams to integrate state-of-the-art security practices. Your day-to-day involves defining cybersecurity policies, managing compliance with international standards like IEC 62443 and ISO 27001, and leading the implementation of the Cyber Resilience Act (CRA) requirements. You will serve as a strategic advisor to senior management and R&D leads, steering improvement programs that cover threat analysis, secure coding, and incident management. This role is unique for its focus on scaling security within modern DevOps and agile frameworks (SAFe/LeSS), offering the opportunity to shape the security culture of critical grid infrastructure software on a global scale.

Required Skills

Education

Master's degree in Computer Science, Information Technology, or a comparable field. Cybersecurity certifications such as CISSP or CSSLP are an advantage.

Experience

  • Extensive long-term experience with demonstrated expertise in cybersecurity, software development, and engineering
  • Years of experience with IT/Cybersecurity in product development, solutions design, and OT operations
  • Proven experience implementing regulatory requirements within agile environments
  • Experience in agile scaling frameworks such as LeSS or SAFe
  • Professional experience in international agile project and development organizations
  • Experience in risk assessment and management for large-scale software releases

Languages

German (Basic)English (Fluent)

Additional

  • Must be comfortable working in an international environment and communicating risks to senior management. Knowledge of NIS2, SOC2, and NIST frameworks is required.