- Brasov - Brasov - Rumunsko
- Bukurešť - Bucuresti - Rumunsko
Cloud Security Engineer – SaaS Applications
Hello World, We are hiring!
We empower our people to stay resilient and relevant in a constantly changing world. We’re looking for people who are always searching for creative ways to grow and learn. People who want to make a real impact, now and in the future.
Does that sound like you? Then it seems like you’d make a great addition to our vibrant team.
Siemens Software, a business unit of the Siemens Digital Industries, is a leading global provider of software solutions to drive the digital transformation of industry, creating new opportunities for manufacturers to realize innovation.
About the role
Do you wish to contribute to the success of our cutting-edge SaaS software solutions through your cybersecurity skills? The Simcenter X Security team is expanding, and we're looking for a dedicated Cloud Security Engineer to ensure the highest quality in terms of security and compliance for our Simcenter X SaaS solution, primarily hosted on AWS. You will also play a key role in the overall security posture of the broader Simcenter X product range.
The SaaS Security Operations Team is crucial to safeguarding the security and operational efficiency of our SaaS organization. We are seeking a dynamic professional to join our international SecOps team as a Cloud Security Engineer. You will be one of the "guardians" of our software value, playing a meaningful role in identifying and addressing potential security threats through advanced threat modeling and conducting thorough penetration testing across our cloud-native systems, web applications, and APIs. This role will be pivotal in proactively safeguarding our cloud perimeter and continuously enhancing our security posture.
Proactive in your day-to-day work and engaged with multiple teams, you are a strong team player and creative problem solver who can work with multi-cultural, dispersed technical teams and contribute to the success of our solutions by:
- Performing Threat Modeling using frameworks like STRIDE to identify, prioritize, and mitigate potential security risks within our cloud architecture and SaaS applications for new implementations and safeguard Security By Design principles.
- Analyzing vulnerabilities reported from automated security tools (e.g., SAST, DAST, cloud security posture management tools) or third parties to assess their exploitability and potential impact on our cloud infrastructure and applications.
- Supporting the resolution of security incidents, including Root Cause Analysis (RCA), containment, and recovery, in collaboration with the wider security organization and incident response best practices.
Your qualifications
We would like to hear from you if you have an engineering degree or equivalent, and have successful experience in the field of cybersecurity, particularly within AWS cloud or cloud-native environments:
You have proven experience securing major cloud platforms, including AWS, Microsoft Azure, Google Cloud Platform, or cloud-native environments, with a solid understanding of cloud architecture, core services, shared responsibility models and zero trust architecture.
You have a strong background in performing STRIDE or other threat modeling methodologies, ideally applied to cloud-native architectures, microservices, APIs, and distributed SaaS environments. You can identify trust boundaries, data flows, attack paths, and abuse cases, then translate findings into prioritized security requirements, mitigation actions, and practical guidance for engineering teams throughout the design and implementation lifecycle.
You are proficient in scripting languages such as Python, PowerShell, or Bash, and have experience using Infrastructure as Code tools such as Terraform or CloudFormation to automate security tasks, scans, and policy enforcement across cloud environments.
You have a strong understanding of cloud security services and controls, including network security practices such as securing VPCs, segmentation, and virtual firewalls; Identity and Access Management (IAM) for managing user permissions and resource access; and data encryption to protect information at rest and in transit across cloud workloads.
You are familiar with common web applications and API security vulnerabilities, including OWASP Top 10 and API Security Top 10, and their exploitation and mitigation, while also bringing knowledge of regulatory frameworks such as GDPR, ISO 27001, NIS2 and CRA. You have experience conducting risk assessments, maintaining security policies, and using Cloud Security Posture Management (CSPM) practices and tools to continuously improve cloud security compliance and visibility.
You can understand complex products, solutions, and issues within a cloud context and are able to report consistently, concisely, and effectively on our SaaS Security posture to the various stakeholders, allowing for management prioritization, investment, and reporting.
Thanks to your enthusiasm, excellent English language skills, and autonomy, you build strong relationships with your interlocutors and easily integrate into a technical expert role in an international and multicultural context.
Nice-to-have certifications
- Certified Cloud Security Professional (CCSP)
- CompTIA Security+ or CompTIA Cloud+
- AWS Certified Security – Specialty
- Microsoft Certified: Azure Security Engineer Associate
- Google Professional Cloud Security Engineer
Working at Siemens Software
A collection of over 377,000 minds building the future one day at a time in over 200 countries. We're dedicated to equality, and we welcome applications that reflect the diversity of the communities we work in. All employment decisions at Siemens are based on qualifications, merit, and business need. Bring your curiosity and creativity and help us shape tomorrow.
Siemens is not the same manufacturing company as in the past. We are helping our customers get to tomorrow faster through innovation and digitalization and are transforming alongside them. We are a modern, forward-looking software company, with the opportunities of a large corporation, where your opportunities are endless. The role you apply for today is only the first step in your Siemens journey.
Compensation & Benefits
The primary location for this opportunity is Romania. The applicable salary range for these locations is:
RON 186,000 - RON 353,300
This role is eligible to earn incentive compensation. The actual compensation offered is based on the successful candidate's job-related skills, experience, and relevant education/training. Siemens offers health and wellness benefits to employees; you can access the benefits available in your country via the link: https://jobs.sw.siemens.com/benefits/
This position may also be posted in additional locations beyond those specified above. For such locations, the applicable salary ranges and benefits will be disclosed by the Talent Acquisition Partner at the time of initial contact, in accordance with local legal requirements.
Diversity & Inclusion
We value equal opportunities and welcome applications from all candidates. At Siemens, we believe people who've had real experiences dealing with being different will excel as leaders. Let's foster a culture of creativity and innovation. We will ensure that individuals with disabilities are provided with reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.
Siemens. Making real what matters
If you want to make a difference – make it with us!
#DISWSIM
#LI-Hybrid