Full Job Description
Role Purpose
The Foundational Services Chief Security Officer will lead security across Siemens
Foundational Services and the One Software Engineering System (OSES), ensuring that
security is embedded into the shared platforms, services, and engineering capabilities used to
build Siemens software.
Foundational Services provides horizontal capabilities-including identity, licensing, data, AI,
and developer experience-that are consumed by software businesses across Siemens. OSES
is creating a common developer toolchain and developer experience to improve productivity and
enable AI-native software development at scale.
The role will bring these areas together under a common security vision: protecting the
foundational capabilities on which Siemens software depends while making secure software
development easier, faster, and more automated for developers.
Key Responsibilities
• Own the end-to-end security strategy for Foundational Services, covering architecture,
product security, cloud security, data protection, AI security, software supply-chain risk
management (component provenance, build integrity, and SBOM) and
third-party/supplier risk, vulnerability management, security resilience engineering, and
incident response strategy.
• Serve as the senior security advisor to Foundational Services and OSES leadership,
translating cybersecurity risks into clear product, architecture, investment, and
engineering decisions.
• Establish consistent security governance, accountability, standards, and
risk-management practices across shared services and the common developer
toolchain.
• Embed security directly into the developer experience, in partnership with platform and
infrastructure engineering. Including:
• source-code management
• development environments (including IaaC guardrails)
• AI coding tools
• Hardened build pipelines (including workload/agentic IAM)
• Artifact and secrets management
• open-source dependencies
• deployment workflows
• Application runtime platforms/middleware
• Recoverability primitives (immutable, reproducible builds, rapid rollback, and
blast radius containment)
• Lead the creation of a secure software factory in which security requirements are
increasingly fulfilled through automated controls, policy as code, reusable services,
secure templates, and approved engineering patterns.
• Reduce developer toil in meeting security and other non-functional requirements, making
the secure path the easiest and fastest for Siemens engineering teams.
• Define the trust and authorization model for AI-native software development;
least-privilege, blast-radius-contained authority for coding assistants and autonomous
agents, verifiable machine identity, and validation of AI-generated code
• Partner across Siemens cybersecurity, IT, legal, privacy, product-security, and
business-unit organizations through clear interfaces and shared operating models,
harmonizing security practices while addressing legitimate product, regulatory, and
deployment differences.
• Build a community of security architects, engineers, and champions across Foundational
Services, OSES, and the Siemens businesses.
• Build, lead, and grow the security engineering team for OSES and Foundational
Services - recruiting, developing, and retaining the talent that owns security across the
developer enablement platform every Siemens team builds on.
• Establish measurable security and developer-experience outcomes, including risk
reduction, control automation and continuous control validation, vulnerability
remediation, platform adoption, and security that scales through platform and automation
leverage; a deliberate bias toward compounding efficiency as OSES scales.
You'll Benefit From
Siemens offers a variety of health and wellness benefits to our employees. Details regarding our benefits can be found here: https://www.benefitsquickstart.com/siemens/index.html
The pay range for this position is 212,900 - 383,300 annually with a target incentive of 25-35 of the base salary. The actual wage offered may be lower or higher depending on budget and candidate experience, knowledge, skills, qualifications, and premium geographic location.