Cybersecurity Supplier Assessor
Siemens EnergyA Snapshot of Your Day As a Cybersecurity Supplier Assessor at Siemens Energy, you will play a key role in protecting the organization’s cybersecurity posture by identifying, assessing, and managing risks associated with third-party suppliers and business partners. You will evaluate the cybersecurity controls, policies, and practices of new and existing suppliers, analyze potential vulnerabilities, and provide recommendations that support informed business decisions and strengthen supplier resilience. Working closely with Procurement, Legal, Information Security, and business stakeholders, you will help translate cybersecurity requirements into practical supplier controls, remediation plans, and contractual obligations. In this role, you will contribute to the continuous improvement of Siemens Energy’s third-party risk management framework while helping safeguard our systems, services, products, and customers in an evolving threat landscape. How You’ll Make an Impact Conduct comprehensive cybersecurity assessments of new and existing third-party suppliers, evaluating security controls, policies, processes, and overall risk posture; analyze findings to identify vulnerabilities, control gaps, and potential business risks. Collaborate with Procurement, Legal, Information Security, and business stakeholders to develop, communicate, and implement supplier remediation plans, ensuring identified risks are appropriately prioritized, documented, monitored, and resolved. Interpret cybersecurity requirements, legal clauses, and security obligations within supplier contracts, supporting negotiations with Procurement and Legal to ensure appropriate cybersecurity protections and compliance requirements are incorporated into supplier agreements. Apply relevant cybersecurity frameworks, industry standards, and regulatory requirements to assess supplier compliance, including ISO 27001, NIST, NIST SP 800-171, CMMC, and applicable supply chain security and export control requirements; support benchmarking of third-party risk management practices, tools, and services. Monitor emerging cybersecurity threats, regulatory developments, and industry best practices to continuously enhance supplier assessment methodologies, strengthen risk management processes, and promote the adoption of effective security controls, including application security standards and secure coding practices where applicable. Drive continuous improvement in supplier cybersecurity resilience by communicating assessment outcomes and risk recommendations to stakeholders at all organizational levels, including executive management, while promoting collaboration, accountability, and consistent third-party risk management practices. Travel internationally as required, anticipated to be at least 10%. What You Bring University degree in Computer Science, Data Science, Information Technology, a legal discipline, Technology or Business Management, or a related field. 5+ years of relevant professional experience in information security auditing, cybersecurity risk assessment, third-party risk management, or a related cybersecurity discipline, preferably with end-to-end supplier assessment responsibilities. Strong understanding of information security risk management methodologies, cybersecurity principles, and recognized frameworks such as ISO 27001, NIST, COBIT, and industry best practices, including security considerations for cloud environments, networks, services, products, and operations. Knowledge of NIST SP 800-171, CMMC, CTPAT, and applicable U.S. cybersecurity, supply chain security, export control, and federal compliance requirements; experience integrating security standards, secure coding practices, and application security requirements into supplier remediation plans is highly valued. Exceptional analytical skills and attention to detail, combined with strong communication, presentation, and stakeholder management capabilities. Ability to translate complex …