Reporting to the SAP Security Senior Manager, responsible for securing the SAP systems that comprise the Enterprise Digital Core program
Responsible for gathering SAP vulnerability management requirements, technical configurations in Onapsis and SAP, and integrations with Mars tools for enhanced monitoring, alerting, and reporting capabilities
Running SAP application layer vulnerability scans to identify security configuration/access vulnerabilities, missing patches/notes, and code vulnerabilities
Support the Transformation Anchor Plan by running scans and working with project stakeholders and system owners throughout the project lifecycle to identify and remediate vulnerabilities
Grow SAP vulnerability capabilities by integrating additional systems, finetuning alerts, and conducting proofs of concept on additional capabilities and integrations
Responsible for transitioning the vulnerability management work at each go-live to the managed service team
Requirements
Minimum 3-5 years of technical experience in the areas of SAP application security, vulnerability scanning, patch management, code security, and security incident response
In-depth knowledge of core SAP application security concepts – role-based access control, IT controls, sensitive access and segregation of duties
Hands-on experience working with SAP cybersecurity, vulnerability management, and code scanning tools (e.g., SAP Enterprise Threat Detection, Onapsis)
Experience with data protection tools (e.g., SAP UI Masking) is a plus
SIEM tools and ServiceNow Vulnerability Response module experience is a plus
Benefits
Best-in-class learning and development support from day one, including access to our in-house Mars University
An industry competitive salary and benefits package, including company bonus
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
SAP application securityvulnerability scanningpatch managementcode securitysecurity incident responserole-based access controlIT controlssensitive accesssegregation of dutiescybersecurity