Siemens is looking for a Product and Solution Security Expert (PSSE) to contribute to the evaluation and building of secure products and solutions for top-of-the-line rail transportation service providers in North America, ensuring the security of software solutions through cybersecurity skills.
Requirements
- Certified Secure Software Lifecycle Professional (CSSLP) preferred.
- ISO27001 foundation certification is very helpful.
- Familiarity with compliance standards like ISO 27017, ISO 27018, IEC 62443, EU-CRA, and EO-14028.
- Strong analytical and problem-solving skills.
- Needs to be specialized in at least one of six different areas: Secure Architecture & Design, Secure Implementation, Security Testing, Secure Project Integration, Secure Manufacturing or Secure Services.
- Excellent communication and documentation skills to convey security requirements and solutions effectively.
- Implement and manage security tools such as static and dynamic analysis tools, intrusion detection systems, and vulnerability scanners.
Responsibilities
- Ensure security requirements are included in the design, development, testing, and deployment stages of software projects.
- Develop and implement security protocols, guidelines, and standard process for software development.
- Support Bid to Maintenance Cybersecurity requirements and processes.
- Collaborating with development and infrastructure teams to integrate threat modeling into the design and development lifecycle.
- Coordinate penetration testing on applications, APIs, and infrastructure to uncover vulnerabilities and exploit paths.
- Analyzing vulnerabilities reported from automated tools or third parties to assess their exploitability and potential impact.
- Perform security code reviews and analyze vulnerabilities during different SDLC phases.
Other
- Bachelor’s degree in computer science, IT security, electronics or related field.
- 8-10 years of relevant experience
- Collaborative approach and ability to work effectively with multi-functional teams.
- Excellent communication and documentation skills to convey security requirements and solutions effectively.
- Reports to Product & Solution Security Officer