Sovereign Cloud Product Security Specialist
About this role
We help the world run better
At SAP, we enable you to bring out your best. Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and future-focused work. We offer a highly collaborative, caring team environment with a strong focus on learning and development, recognition for your individual contributions, and a variety of benefit options for you to choose from.
The Sovereign Cloud Technology and Delivery unit is responsible for enabling and operating a multitude of SAP solutions according to global as well as local compliance and security requirements. Following a globally designed approach we help our customers to leverage the benefits of the cloud – while meeting national regulatory and customer demands around data residency, local and credentialed personnel and facilities.
Your future role
We are looking for an execution-oriented Product Security Specialist who can navigate complex threat scenarios and remain committed to decreasing the overall attack surface of SAP workloads within Sovereign Cloud Services. Vulnerability Management remains a top priority, presenting the opportunity to be in a key role, together with the support and empowerment needed to be successful. You will complete each day with a sense of pride and accomplishment, knowing that your contributions have made a positive impact on the security posture of the organization and company as a whole.
You will develop, implement, maintain, and socialize the strategic vision pertaining to your area e.g., testing, validation, post-production security operations, etc. proxying issues between Product and Regional Operations teams with additional enrichment, actionable guidance, and higher support. You will provide expertise in cross-functional team initiatives and process improvement projects. You will play a key role in operational reporting & metrics capability, ensuring all products and regions within Sovereign Cloud can adequately be measured towards compliance to the standard set for Enterprise Vulnerability Management, as well as Sovereign Cloud Security baseline requirements.
You will strengthen relationships between security and other functional teams; act as a security champion to help build a culture that sees security as an enabler. You will establish/participate in learning circles with other product(s)/application(s)/service(s) security professionals across cross line of businesses to share best practices and lessons learned.
What you bring
- Good Knowledge of Vulnerability Management processes for Infrastructure, Cloud-Native, and Product alike
- Foundational knowledge in linux, windows, and containerized systems
- Experience analyzing, triaging, and remediating common information security issues
- Proficiency with Vulnerability Management Tools (e.g. Tenable.io, Tenable Security Center, Rapid7 InsightVM)
- Ability to be an Active Listener and employ various levels of listening as required by the needs of those you coach
- Technology skills and the willingness to learn new topics quickly
- Problem-solving, presentation, communication, and interpersonal skills
- Ability to think strategically, delivering services to meet stakeholders’ demands on a timely basis
- Understanding of common attacker tactics, tools, and techniques. Ability to build trusted relationships with key stakeholders
- Persistence, self-motivation and willingness to work under pressure
- Proven ability to work in cross-functional teams
- Excellent problem-solving, investigative, and written and verbal communication skills
- Ability to speak and write in English fluently
Work experience
- Bachelor’s degree or equivalent experience
- 3-5 years of experience working in security area with relevant realm of responsibilities
- Knowledge of security frameworks and best practices
- Knowledge of development security operations principles
- Established and matured cross-company processes around vulnerability management including operating models, maturity models, Service Level Agreement (SLA)/Service Level Objectives (SLOs), discovery, managing and reporting processes, roles/responsibilities, etc.
- Coordinated resolution of cross-company issues that arose from vulnerabilities, having worked with internal and industry stakeholders to comprehensively remediate security risk
- Security Certifications like CISSP, CISM, CCSP, Security+, etc. are an asset
- Previous participation in security assessments in a regulated environment are a plus
We invite you to bring out your best with SAP. For SAP employees: Only permanent roles are eligible for the SAP Employee Referral Program, according to the eligibility rules set in the SAP Referral Policy. Specific conditions may apply for roles in Vocational Training.