Chief Security Officer, Foundational Services and OSES
Charlotte, Mecklenburg County, North Carolina, 28245, USA
Listed on 2026-10-05
-
Software Development
Chief Security Officer, Foundational Services and OSES
Job
522503
Posted since
15-Sep-2026
Organization
Field of work
Research & Development
Company
Siemens Industry Software Inc.
Experienced Professional
Job type
Full-time
Hybrid (Remote/Office)
Employment type
Permanent
Location(s)
- Charlotte
- North Carolina
- United States of America
We are a leading global software company dedicated to the world of computer-aided design, 3D modeling, and simulation, helping innovative global manufacturers design better products, faster. With the resources of a large company and the energy of a software start-up, we have fun together while creating a world-class software portfolio. Our culture encourages creativity, welcomes fresh thinking, and focuses on growth, so our people, our business, and our customers can achieve their full potential.
RolePurpose:
The Foundational Services Chief Security Officer will lead security across Siemens Foundational Services and the One Software Engineering System (OSES), ensuring that security is embedded into the shared platforms, services, and engineering capabilities used to build Siemens software.
Foundational Services provides horizontal capabilities, including identity, licensing, data, AI, and developer experience, that are consumed by software businesses across Siemens. OSES is creating a common developer toolchain and developer experience to improve productivity and enable AI-native software development at scale.
This role will bring these areas together under a common security vision: protecting the foundational capabilities on which Siemens software depends while making secure software development easier, faster, and more automated for developers.
Key Responsibilities:Own the end-to-end security strategy for Foundational Services, covering architecture, product security, cloud security, data protection, AI security, software supply chain risk management (component provenance, build integrity, and SBOM), third-party and supplier risk, vulnerability management, security resilience engineering, and incident response strategy.
Serve as the senior security advisor to Foundational Services and OSES leadership, translating cybersecurity risks into clear product, architecture, investment, and engineering decisions.
Establish consistent security governance, accountability, standards, and risk management practices across shared services and the common developer toolchain.
Embed security directly into the developer experience in partnership with platform and infrastructure engineering, including:
Source code management
Development environments, including Infrastructure as Code (IaC) guardrails
AI coding tools
Hardened build pipelines, including workload and agentic IAM
Artifact and secrets management
Application runtime platforms and middleware
Recoverability capabilities, including immutable and reproducible builds, rapid rollback, and blast radius containment
Lead the creation of a secure software factory where security requirements are increasingly fulfilled through automated controls, policy as code, reusable services, secure templates, and approved engineering patterns.
Reduce developer effort required to meet security and other non-functional requirements, making the secure path the easiest and fastest option for Siemens engineering teams.
Define the trust and authorization model for AI-native software development, including least-privilege access, blast-radius-contained authority for coding assistants and autonomous agents, verifiable machine identity, and validation of AI-generated code.
Partner across Siemens cybersecurity, IT, legal, privacy, product security, and business unit organizations through clear interfaces and shared operating models, harmonizing security practices while…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).