Talent Apply
Log in
All jobs
SE

Cybersecurity Supplier Assessor

Siemens Energy AB
Orlando, Florida, United States

About this role

Siemens Energy and Siemens Gamesa are becoming Omterra. "We energize society" by supporting our customers to make the transition to a more sustainable world, based on innovative technologies and our ability to turn ideas into reality. With nearly 100,000 employees around the world, we shape the energy systems of today and tomorrow.

Learn more about Siemens Energy

About the Role

Job ID 303872

Location United States of America Florida Orlando

Company Siemens Energy, Inc.

Organization EVP Global Functions

Business Unit Cybersecurity

Full / Part time Full-time

Experience Level Professional / Experienced

A Snapshot of Your Day

As a Cybersecurity Supplier Assessor at Siemens Energy, you will play a key role in protecting the organization’s cybersecurity posture by identifying, assessing, and managing risks associated with third-party suppliers and business partners. You will evaluate the cybersecurity controls, policies, and practices of new and existing suppliers, analyze potential vulnerabilities, and provide recommendations that support informed business decisions and strengthen supplier resilience. Working closely with Procurement, Legal, Information Security, and business stakeholders, you will help translate cybersecurity requirements into practical supplier controls, remediation plans, and contractual obligations. In this role, you will contribute to the continuous improvement of Siemens Energy’s third-party risk management framework while helping safeguard our systems, services, products, and customers in an evolving threat landscape.

How You’ll Make an Impact

  • Conduct comprehensive cybersecurity assessments of new and existing third-party suppliers, evaluating security controls, policies, processes, and overall risk posture; analyze findings to identify vulnerabilities, control gaps, and potential business risks.
  • Collaborate with Procurement, Legal, Information Security, and business stakeholders to develop, communicate, and implement supplier remediation plans, ensuring identified risks are appropriately prioritized, documented, monitored, and resolved.
  • Interpret cybersecurity requirements, legal clauses, and security obligations within supplier contracts, supporting negotiations with Procurement and Legal to ensure appropriate cybersecurity protections and compliance requirements are incorporated into supplier agreements.
  • Apply relevant cybersecurity frameworks, industry standards, and regulatory requirements to assess supplier compliance, including ISO 27001, NIST, NIST SP 800-171, CMMC, and applicable supply chain security and export control requirements; support benchmarking of third-party risk management practices, tools, and services.
  • Monitor emerging cybersecurity threats, regulatory developments, and industry best practices to continuously enhance supplier assessment methodologies, strengthen risk management processes, and promote the adoption of effective security controls, including application security standards and secure coding practices where applicable.
  • Drive continuous improvement in supplier cybersecurity resilience by communicating assessment outcomes and risk recommendations to stakeholders at all organizational levels, including executive management, while promoting collaboration, accountability, and consistent third-party risk management practices. Travel internationally as required, anticipated to be at least 10%.

What You Bring

  • University degree in Computer Science, Data Science, Information Technology, a legal discipline, Technology or Business Management, or a related field.
  • 5+ years of relevant professional experience in information security auditing, cybersecurity risk assessment, third-party risk management, or a related cybersecurity discipline, preferably with end-to-end supplier assessment responsibilities.
  • Strong understanding of information security risk management methodologies, cybersecurity principles, and recognized frameworks such as ISO 27001, NIST, COBIT, and industry best practices, including security considerations for cloud environments, networks, services, products, and operations.
  • Knowledge of NIST SP 800-171, CMMC, CTPAT, and applicable U.S. cybersecurity, supply chain security, export control, and federal compliance requirements; experience integrating security standards, secure coding practices, and application security requirements into supplier remediation plans is highly valued.
  • Exceptional analytical skills and attention to detail, combined with strong communication, presentation, and stakeholder management capabilities. Ability to translate complex technical and regulatory requirements into clear risk assessments and actionable recommendations, collaborate effectively with Procurement, Legal, and suppliers, and communicate confidently with stakeholders through executive management.
  • Fluency in English is required, along with a willingness to travel internationally at least 10% of the time.
  • Relevant certifications such as CRISC, CISA, CCSK, CCAK, CSX Practitioner, ISO 27001 Lead Auditor, Project Management, or comparable qualifications are considered an advantage.
  • Applicants must be U.S. citizens and able to satisfy all applicable government, security, or export control requirements associated with the role.
  • Applicants must be legally authorized for employment in the United States without need for current or future employer-sponsored work authorization. Siemens Energy employees with current visa sponsorship may be eligible for internal transfers.

About the Team

You will be part of a global team that provides cybersecurity support services for all Siemens Energy Divisions and Functions as well as all seven Siemens Energy hubs. You will also join our companywide cybersecurity community of more than 130 members.

Who is Siemens Energy?

At Siemens Energy, we are more than just an energy technology company. With ~100,000 dedicated employees in more than 90 countries, we develop the energy systems of the future, ensuring that the growing energy demand of the global community is met reliably and sustainably. The technologies created in our research departments and factories drive the energy transition and provide the base for one sixth of the world's electricity generation.

Our global team is committed to making sustainable, reliable, and affordable energy a reality by pushing the boundaries of what is possible. We uphold a 150-year legacy of innovation that encourages our search for people who will support our focus on decarbonization, new technologies, and energy transformation.

Find out how you can make a difference at Siemens Energy: https://www.siemens-energy.com/employeevideo

Rewards

  • Career growth and development opportunities; supportive work culture
  • Company paid Health and wellness benefits
  • Paid Time Off and paid holidays
  • 401K savings plan with company match
  • Family building benefits
  • Parental leave

Equal Employment Opportunity Statement

Siemens Energy and Siemens Gamesa Renewable Energy is an Equal Opportunity and Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to their race, color, creed, religion, national origin, citizenship status, ancestry, sex, age, physical or mental disability unrelated to ability, marital status, family responsibilities, pregnancy, genetic information, sexual orientation, gender expression, gender identity, transgender, sex stereotyping, order of protection status, protected veteran or military status, or an unfavorable discharge from military service, and other categories protected by federal, state or local law.

California Privacy Notice California residents have the right to receive additional notices about their personal information. Click here to read more.

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →