Product Security Sr Specialist - Business Data Cloud Security & Compliance
Role details
Job location
Tech stack
Job description
At SAP, we keep it simple: you bring your best to us, and we'll bring out the best in you. We're builders touching over 20 industries and 80% of global commerce, and we need your unique talents to help shape what's next. The work is challenging - but it matters. You'll find a place where you can be yourself, prioritize your wellbeing, and truly belong. What's in it for you? Constant learning, skill growth, great benefits, and a team that wants you to grow and succeed.
We are looking for someone to support the security program with emphasis on application security, security testing, privacy reviews, and compliance activities. This role works closely with engineering and compliance teams to identify risks, validate controls, and improve the security posture of products and services.
We work on defining security architecture, threat modelling, offensive security and ensuring our products are compliant with SAP security standards. You will get a chance to work on all aspects of the security and compliance, and all aspects of the secure development lifecycle. This includes supporting compliant use of AI, data protection, risk management, offensive security, and utilizing AI to gain efficiencies and further out security posture.
Responsibilities
- Perform application security assessments (SAST, DAST,) and support remediation.
- Assist with secure development lifecycle tasks, including basic threat modeling and design review support.
- Help maintain security tooling and CI/CD security integrations.
- Support privacy impact assessments, data flow mapping, and privacy-by-design activities.
- Contribute to compliance evidence collection and control documentation (SOC 2, ISO 27001, FedRAMP, etc.).
- Assist in updating security policies, procedures, and developer guidance.
Requirements
Foundational knowledge of application security principles and OWASP Top 10.
- Familiarity with common security testing tools and vulnerability management.
- Basic understanding of privacy and compliance frameworks (e.g., GDPR, ISO27001, SOC 2).