openqareer

Security & Compliance Engineer

Siemens Energy · תל אביב -יפו, מחוז תל אביב

# Security & Compliance Engineer **Siemens Energy** · תל אביב -יפו, מחוז תל אביב · `On-site` 🕒 **Статус:** *Опубликовано: сегодня* · *Источник: Indeed* --- ### About the Role Role Overview The regulation Expert (GRC) function serves as the definitive authority on governance, risk management, and compliance for Operational Technology (OT) and critical infrastructure environments. This role bridges the gap between highly technical cybersecurity operations and global regulatory mandates and entities. The GRC Lead will ensure that all internal industrial architectures and customer-facing solutions—from legacy DCS/SCADA systems to next-generation environments —meet Rigorous international standards and effectively manage cyber-physical risk. The ideal candidate will enjoy working in a diverse team, with excellent communication skills and a genuine passion for teamwork. Key Responsibilities 1. Regulatory Compliance & Audit Management - Framework Enforcement: Lead the implementation, mapping, and continuous monitoring of core industrial cybersecurity frameworks, with a primary focus on IEC 62443 , NIS2 , and NERC CIP. - Customer Assurance: Act as the GRC subject matter expert in customer engagements, providing verifiable assurance that Siemens Energy solutions comply with their specific regional and industry-level regulatory requirements. - Audit Readiness: Manage internal and external audits, including penetration test remediation tracking, vulnerability assessments, and compliance gap analyses for industrial environments. 2. Cyber-Physical Risk Management - Risk Assessments: Design and execute comprehensive risk assessments for critical infrastructure projects, evaluating the impact of emerging threats on plant safety, availability, and resilience. - Threat Modelling Governance: Oversee threat modelling processes (utilizing frameworks like MITRE ATT&CK for ICS) to ensure risks in the Purdue Model layers are documented, quantified, and mitigated to acceptable levels. - Third-Party & Supply Chain Risk: Evaluate and govern the security posture of third-party vendors, specialized industrial equipment suppliers, and software supply chains to prevent downstream vulnerabilities. 3. Governance & Strategic Policy - Policy Development: Author and maintain OT-specific security policies, standards, and playbooks that adapt corporate IT security directives to the unique availability and safety requirements of the plant floor. - Innovation Guardrails: Establish governance frameworks for integrating emerging technologies—such as secure remote connectivity, cloud-connected OT, and industrial AI—ensuring compliance by design. - Executive Reporting: Translate complex cyber-physical risks and compliance metrics into business-impact dashboards for senior leadership and client stakeholders. Qualifications & Expertise - Experience: 7+ years in Information Security, with at least 3+ years specifically leading GRC initiatives in OT, ICS, or the critical Infrastructure sector. - Regulatory Deep-Dive: Expert-level, practical knowledge of IEC 62443 (particularly parts 2-4, 3-2, 3-3, and 4-2) and the implications of the European NIS2 directive on energy providers. - Certifications: Strongly prefer industry-standard certifications such as CISA, CISM, CRISC, ideally paired with an OT-specific certification (e.g., GIAC GICSP). - Communication: Proven ability to negotiate and align priorities between compliance teams, plant managers, engineering leads, external auditors and regulatory entities. - Education: A bachelor’s degree (BA/BSc) in Cybersecurity, Information Technology, Engineering, Business Administration, or a related field is preferred, though equivalent extensive industry experience is highly valued. How to contribute to our vision To ensure business continuity and maintain the delivery of compliant, conformant software products, this role is critical to the Software Architects team within Siemens Energy's Technology & Innovation division. Operating in Israel, the Security & Compliance Engineer will align digital products and solutions with global cybersecurity standards and internal corporate compliance frameworks.\n\nTo address this business aim, this role focuses on secure software architecture design, regulatory compliance auditing, and proactive vulnerability management. These core areas ensure that all software products are built with robust security controls and meet the strict regulatory requirements of the energy sector.\n\nGiven the focus on software compliance and security engineering, the ideal candidate will have extensive experience in DevSecOps, threat modeling, and cybersecurity standards. Strong collaboration skills are essential to guide engineering teams in implementing secure coding practices and maintaining product integrity. What You Need To Make a Difference - 40% Security Architecture & Engineering - Design, implement, and maintain secure software architecture patterns and security controls across the digital product lifecycle. - Conduct threat modeling, vulnerability assessments, and automated code reviews to identify and mitigate security risks early in development. - Collaborate with software development teams to integrate secure coding practices and robust DevSecOps pipelines. - 40% Compliance & Regulatory Alignment - Ensure software products conform to international security standards (e.g., IEC 62443, ISO 27001) and internal Siemens Energy compliance policies. - Lead compliance audits, prepare technical security documentation, and manage certification processes for software products. - Monitor emerging regulatory requirements and translate them into actionable engineering and architectural specifications. - 20% Risk Management & Enablement - Establish risk mitigation strategies and manage the product security incident response process. - Provide guidance, training, and mentorship to engineering teams on compliance mandates and security best practices. Certifications - Certified Information Systems Security Professional (CISSP) - Certified Secure Software Lifecycle Professional (CSSLP) - Certified Cloud Security Professional (CCSP) Education - Bachelor's or Master's degree in Computer Science, Cybersecurity, Software Engineering, or a related technical discipline. - Minimum of 5-8 years of experience in software security engineering, product compliance, or secure software architecture. - Demonstrated experience working with industrial security standards such as IEC 62443 or ISO 27001 in an enterprise software environment. Skills - Cybersecurity & Threat Mitigation - Threat Modeling & Risk Assessment - Vulnerability Management & Mitigation - Secure Software Development Lifecycle (SSDLC) - DevSecOps & CI/CD Security Integration - Compliance & Standards - IEC 62443 & ISO 27001 Standards Compliance - Security Auditing & Technical Documentation - Software Bill of Materials (SBOM) & License Compliance - Software Engineering & Architecture - - Cloud Security Architecture (AWS/Azure) - Secure Coding Practices (OWASP Top 10) - Agile Software Development Methodologies #Li-Lk1 Who is Siemens Energy? At Siemens Energy, we are more than just an energy technology company. With ~100,000 dedicated employees in more than 90 countries, we develop the energy systems of the future, ensuring that the growing energy demand of the global community is met reliably and sustainably. The technologies created in our research departments and factories drive the energy transition and provide the base for one sixth of the world's electricity generation. Our global team is committed to making sustainable, reliable, and affordable energy a reality by pushing the boundaries of what is possible. We uphold a 150-year legacy of innovation that encourages our search for people who will support our focus on decarbonization, new technologies, and energy transformation. Find out how you can make a difference at Siemens Energy: https://www.siemens-energy.com/employeevideo Our Commitment to Diversity Lucky for us, we are not all the same. Through diversity we generate power. We run on inclusion and our combined creative energy is fueled by over 130 nationalities. Jobs & Careers: https://jobs.siemens-energy.com #Li-Lk1

Наблюдалась 2026-10-07, впервые 2026-10-06, источник — Indeed.

Открыть у работодателя