Přeskočit na obsah Přeskočit na zápatí

Cybersecurity Governance Specialist — Software Development (Agile)

ID pozice
504984
Zveřejněno od
04-Kvě-2026
Organizace
Smart Infrastructure
Obor
Cybersecurity
Společnost
Siemens s.r.o.
Úroveň zkušeností
Se střední praxí v oboru
Typ pozice
Plný úvazek
Režim práce
Kombinovaně (vzdáleně/na pracovišti)
Druh smlouvy
Trvalý
Lokalita
  • Bratislava - Bratislavsky kraj - Slovensko

Salary

3 000EUR/month

From 3 000€ brutto/month + variable bonus*

*We are required by law to disclose basic wage component (minimum salary) for the advertised positions. This salary is for junior candidate. We carefully consider your professional qualifications and experience in our compensation package and/or whenoffering you other positions. Our goal is to pay our employee's fairly, with regard to the market situation and we are ready to welcome high-quality candidates in our team.

We are seeking an experienced Cybersecurity Governance Specialist to design, implement, and run our cybersecurity governance program for software development. This role makes security governance a working part of our software development lifecycle.

You will work closely and continuously with application development teams and security architects, translating regulatory and standards requirements (ISO/IEC 27001, IEC 62443, CRA) into governance that fits inside sprints, backlogs, and release cycles. You will implement security quality gates into our development process and measure compliance.

You will work independently with minimal day-to-day guidance, and you'll need enough technical grounding in the SDLC to be credible in front of engineers and architects.

Key Responsibilities

  • Governance Framework for Software Development: Own the design and maintenance of a cybersecurity governance framework specifically for the software development lifecycle, aligned with ISO/IEC 27001, IEC 62443, and CRA. Translate these standards into requirements that map onto Agile ceremonies and artifacts (e.g., Definition of Done, backlog refinement, sprint/release gates).
  • Embedding Governance in Agile Delivery: Be responsible for integrating security checkpoints into the engineering lifecycle — architecture review gates, story/epic classification, quality gates at phase transitions — in partnership with security architects, so governance runs alongside delivery rather than blocking it.
  • Documentation & Governance Forums: Deliver governance documentation (charters, operating models, decision frameworks) and run or support governance forums such as architecture review boards, where you'll work directly with security architects and engineering leads to review designs against approved security principles.
  • Policy & Standard Management: Author, review, and maintain cybersecurity policies and standards for software development, ensuring they're usable by engineering teams day-to-day, not just compliant on paper.
  • Risk Management & Compliance: Own governance decisions on risk acceptance and conditional approvals for development teams. Perform or support risk assessments for software/application systems (IT and OT contexts), and support audits and certifications (ISO 27001, CRA) covering the development organization.
  • Performance Measurement: Deliver and maintain governance KPIs/KRIs (e.g., security gate compliance rates, time-to-remediate findings) and report on program effectiveness to leadership.

Required Qualifications

  • 5+ years of experience in cybersecurity governance, GRC, or security architecture — specifically including experience building or running a governance program for a software/application development organization.
  • Practical understanding of Agile/Scrum delivery (sprints, backlogs, Definition of Done) and how governance controls get embedded into them — you should be able to speak the language of an engineering team, not just the language of a standard.
  • Working technical understanding of application security and the SDLC (secure coding practices, vulnerability management, architecture review, SBOM/dependency management).
  • Demonstrated experience translating a regulatory or standards framework (ISO/IEC 27001, IEC 62443, NIS2, CRA) into policy or process requirements usable by engineering teams.
  • Experience operating with significant autonomy — defining your own work plan and driving deliverables to agreement with engineering stakeholders without close supervision.
  • Strong written communication; you will personally author policy and governance documents.

Preferred Qualifications

  • Direct experience partnering with security architects on architecture review processes.
  • Familiarity with OT/ICS environments and IEC 62443 in practice, especially where IT and OT development overlap.
  • Relevant certifications (CISSP, CISM, ISO/IEC 27001 Lead Implementer/Auditor).
  • Experience with EU Cyber Resilience Act (CRA) implementation in a software development context (e.g., SBOM, VEX lifecycle)

We offer:

  • Home office, telework
  • Flexible working hours (9:00 – 15:00), short Fridays
  • Bridge days – 5 days/year
  • Sick days – 3 days/year
  • Additional paid leave
  • Cafeteria system - BenefitPlus = 300 points / € per year
  • Contribution to 3rd pillar pension up to 3% of gross salary (after the employment trial period)
  • Sick leave compensation and Sick Leave to Care for a Family Member compensation (up to 100% of salary, 20 days/year)
  • Childbirth bonus of 300€
  • Contribution for attending a preschool facility (200€)
  • Contribution for representative sports activities
  • MultiSport
  • 2 SIM cards with discounted employee flat rate also for family members
  • Employee referral bonus up to 2 000€
  • Opportunity to invest in the purchase of Siemens shares
  • Discounts for employees (electronics, language courses, vacation stays...)
  • Discounted employee´s loans
  • Wellbeing program, Health Day, team-building program
  • Education in various fields of your choice
  • Work anniversary present and life anniversary contribution
  • Valuable gift on the occasion of retirement

#LI-HYBRID