As the leading company in the field of software solutions for healthcare, we operate in 19 countries and employ over 9,000 dedicated staff members. You will work in a dynamic and innovative environment full of opportunities. With your commitment and passion, you have the chance to make a sustainable difference.
CGM Leverages AI: We’re looking for people who feel the power of AI in the e-health environment, who want to help shape change, and who are driven by a curious passion to see how technology can make healthcare smarter, simpler, and better.
Together, we are shaping the healthcare system of the future. Become part of our mission and make a difference – for a world where knowledge saves lives!
Are you passionate about groundbreaking products? Do you have the talent to turn ideas into real, valuable solutions—while always keeping the bigger picture in mind? Then we’d love to meet you!
Your Responsibilities:
You define and own the product security strategy for our global portfolio and establish the policy framework for secure development, security baselines, and release criteria.
You drive CRA readiness across the entire portfolio – from product classification to conformity assessment, and the build-out of SBOM and evidence processes.
You set the mandatory security tooling baseline (SAST, DAST, SCA, secrets scanning) and define security quality gates within the delivery pipeline.
You shape the governance for our AI-driven security remediation (agentic OpenCode pipeline) – including guardrails, approval criteria, and quality assurance.
You build the Security Guild and a network of Security Champions embedded in the FIRE teams, and foster lived security practice through training and coaching
Your Profile:
Several years of experience in product security, application security, or as a deputy CISO within a complex, multi-product software organisation.
Demonstrable, current expertise in the EU Cyber Resilience Act – requirements, classification logic, and conformity assessment – along with working knowledge of NIS2 and GDPR.
Strong, practical knowledge of the secure development lifecycle, threat modelling, and application security testing, together with hands-on experience with SAST, DAST, SCA, and SonarQube tooling.
Experience with SBOM generation and governance, as well as with managing supply chain risk; understanding of AI-assisted and agentic development workflows.
Strong communication and stakeholder management skills to enforce standards without direct line authority; CISSP or an equivalent certification is an advantage.
What you can expect from us:
Mobile work: Work flexibly on the move two days a week and on site three days a week.
Attractive locations: In addition to fully equipped workplaces, regular events such as summer parties and Christmas parties await you at our locations.
Development: Our in-house academy and our portfolio of external cooperation partners will support you in your further development.
Health: Health is a valuable asset for us. Our in-house canteen offers a selection of tasty and healthy dishes every day, and we welcome you to our fully equipped fitness center for weekly courses (online & offline).
More is always possible: The kindergarten on our CGM campus in Koblenz helps our employees to organize their working day even more flexibly. We also offer corporate benefits, the option of a job bike, a company pension scheme, and much more.
Diversity is part of CGM! We look forward to receiving your application regardless of disability, gender, nationality, ethnic and social background, religion, age, sexual orientation, and identity.
Convinced? Apply online now with your detailed application documents (including salary expectations and earliest possible starting date).
