Program Security Senior in SAP BTP Fabric Delivery & SRE - Product Lifecycle Services
Role details
Job location
Tech stack
Job description
As a Program Security Senior, you will be instrumental in securing the delivery of BTP Foundational Services on SAP Cloud Foundry and Kubernetes, ensuring they meet SAP's highest security and compliance standards while enabling teams to implement security measures effectively.
Your tasks will consist of ensuring security requirements in the programs are met, as well as supporting the teams to implement new security- and counter- measures to identified weaknesses.
You will work in close alignment with central and local security teams to continuously ensure compliance with SAP's high security standards. Additionally, you are supporting the teams to understand security requirements in close alignment with the BTP Foundation Services teams and central security experts and support their implementation and documentation.
The Role:
- Responsible to report/present founded, aggregated security status in Release Decision Meetings (RDMs) to comply with SAP security requirements and ensure secure deliveries
- Engage in the virtual area security community and act as a driver on topics
- Manage and coordinate security validations along with coordination of Hacker Simulations (pentesting)
- Drive ad-hoc security and regulatory compliance topics specific to deliveries for different world regions and scenarios
- Provide feedback/guidance/consulting to area security contacts regarding the following topics:
- Security/Compliance/Data Protection (during onboarding as well as changes)
- SAP Secure Development and Operations Lifecycle requirements (e.g., Threat Modeling, Security & Data Protection concepts, Security Risk Management, Hacker Simulation coordination etc.)
- Fulfillment of security-relevant tasks for each release (e.g. ensuring the availability of evidence to fulfil security compliance and audit expectations)
- Drive future security topics related to Cyber Security and AI
- Security Ticket handling and follow-up with development teams (e.g. hacker simulation findings, customer tickets etc.), For information on the responsible use of AI in our recruitment process, please refer to our Guidelines for Ethical Usage of AI in the Recruiting Process. Please note that any violation of these guidelines may result in disqualification from the hiring process.
Requirements
Do you have experience in Kubernetes?, Do you have a Master's degree?, * Highly interested in, curious about and very motivated to drive security and protection topics
- Bachelor's/master's degree in computer science, Information Security, a related field or similar experience/knowledge in software security
- Proven experience of at least 3 years in topics that are or influenced by information security, ideally including working directly on product security topics, security incident management, and security operations
- Strong knowledge of information security principles, practices, and technologies along with familiarity towards latest security standards and frameworks
- Fluency in English
- Strong team player with intercultural awareness
- Ability to communicate swiftly and work on multiple work streams in parallel, as well as the ability to switch context/topic quickly
Nice-to-have skills:
- Strong knowledge and understanding of SAP Business Technology Platform is of great benefit
- Proficient skills in performing Threat-modelling workshops, assessing vulnerability scans, and guiding teams to upskill their security know-how, helping them build secure SAP Products
- Ability to work on concepts that use AI to create state of the art use cases to optimize overall security status