- Tres Cantos - Madrid - Spanien
AI & SaaS Security Expert / Cybersecurity Professional (f/m/d)
We are seeking a highly skilled and experienced AI and SaaS Security Expert to join our team. As SaaS platforms increasingly embed AI capabilities and rely on AI-driven workflows to automate business processes, the security landscape has evolved significantly. This role is critical to securing the convergence of AI and SaaS by protecting AI models, agents, and workflows while ensuring the security of the SaaS applications that host and process Siemens data.
This role is the organization's lead expert in AI and SaaS security, combining deep technical knowledge of both domains: emerging AI security areas such as agentic AI, LLM and model security, AI runtime authorization, and AI workflows, together with strong experience securing modern SaaS environments, including SSPM, CASB, SaaS identity governance, and API security.
You will liaise with internal teams and stakeholders to help define the Siemens AI and SaaS security vision and roadmap, contribute to innovation initiatives on agentic AI security, AI model and supply-chain security, and SaaS Security Posture Management (SSPM), and act as a trusted technical advisor to leadership and business units on all AI- and SaaS-related cybersecurity matters, ensuring our environments meet the security and regulatory demands of a large organization across both human and non-human identities.
This is an expert-level role requiring deep technical expertise in both cybersecurity and artificial intelligence. A strong understanding of how Large Language Models (LLMs) and foundation models are designed, trained, fine-tuned, deployed, and operated is essential, as is expertise in AI security risks such as prompt injection, model manipulation, data poisoning, model supply-chain threats, agentic AI risks, and emerging attack techniques. You will apply this hands-on depth to the most complex AI and SaaS security challenges, supporting rather than owning the architecture and program work driven by our architects and service owners.
Key Responsibilities
- Act as Siemens' technical subject matter expert for AI, LLM, and agentic AI security, providing technical consulting, security assessments, and guidance for AI and SaaS initiatives.
- Assess AI systems end to end, including models, training, inference, RAG, and agents, against prompt injection, jailbreaks, data poisoning/leakage, model extraction, and supply-chain attacks.
- Contribute to the Siemens-wide AI and SaaS security strategy and roadmap, supporting innovation across AI agent and model security and SSPM.
- Develop AI and SaaS security standards, guardrails, and reference controls, and support governance, risk, and compliance activities including policies, audits, and regulatory alignment.
- Provide hands-on expertise for critical designs and complex AI/SaaS security issues, including agent identity and runtime authorization, model provenance, and SaaS misconfiguration remediation.
- Advise and align stakeholders across IT, Product, AI/Data Science, businesses, SaaS vendors, and AI providers, mentor security colleagues, and collaborate closely with IAM on non-human identity.
Skillset you bring:
Technical & Domain Expertise
- Deep understanding of how LLMs and foundation models are designed, trained, fine-tuned, evaluated, deployed, and operated, including transformers, embeddings, vector databases, RAG, agents, multi-agent systems, and AI orchestration frameworks.
- Expert in securing AI agents, LLMs, and ML pipelines against prompt injection, jailbreaks, data poisoning, and model extraction, with skills in supply-chain integrity, runtime authorization, agent identity, and red-teaming against OWASP LLM Top 10 and MITRE ATLAS.
- Expertise in securing AI workloads on Google Cloud Platform, AI model deployment pipelines, IAM, networking, and cloud-native security controls.
- Hands-on expertise with SSPM, CASB, and modern SaaS security control planes for misconfiguration and drift detection, third-party OAuth/integration governance, Shadow SaaS / Shadow AI discovery, and DLP across the SaaS estate.
- Deep knowledge of SaaS identity lifecycle and joiner-mover-leaver flows across multi-SaaS estates, OAuth/OIDC token governance, least-privilege enforcement, and API security (OWASP API Top 10).
- Expertise in workload identities, service accounts, AI agent identity, and machine-to-machine authentication.
- Experience with AI and SaaS security telemetry, anomaly detection, immutable audit trails for agentic actions, DLP, and integration with SOC/SIEM/XDR workflows.
Advisory, Governance & Business Capabilities
- Experience acting as the recognized expert for stakeholders and business leaders, translating security risks into business impact and supporting executive decision-making.
- Proven ability to shape and support security strategies and roadmaps that balance business and security objectives, in partnership with architects and service owners.
- Deep knowledge of AI- and SaaS-related frameworks (EU AI Act, NIST AI RMF, ISO/IEC 42001, OWASP Top 10 for LLM and Agentic Applications, MITRE ATLAS, NIS2, GDPR, DORA) with hands-on audit preparation and policy development.
- Demonstrated success influencing diverse stakeholders in complex, matrixed organizations, and a track record of evaluating and driving adoption of emerging AI and SaaS security paradigms.
How we expect you to collaborate:
- Solution-oriented thinking and working is mandatory, with a can-do, iterate-and-improve and ownership-first attitude.
- Ability to explain complex AI security topics to technical and non-technical audiences, and to collaborate with all levels of the organization up to Executive Staff, as well as with AI and SaaS vendors.
- Curiosity and technical excellence, with a willingness to challenge assumptions and continuously evaluate emerging AI technologies, threats, and defenses.
- Proficient in written and spoken English, with strong interpersonal skills, attention to detail, and the ability to adapt quickly to fast-paced, multilayered environments.
Please, include a CV in English so that it can be reviewed.
Diversity at Siemens is our source of creativity and innovation. Having different types of talent and experience makes us more competitive and better able to respond successfully to society's demands. That's why we value candidates who reflect the diversity we enjoy in our company.