Negotiable
Outside
Remote
USA
Summary: The SAP DevSecOps Engineer role is focused on integrating SAP security with DevSecOps practices to ensure secure development and operation of SAP systems. The position is critical for supporting a large IT transformation initiative aimed at migrating the SAP platform to the cloud while maintaining compliance and enhancing security. The ideal candidate will possess extensive experience in SAP security and cybersecurity platforms. This role is remote, allowing flexibility in work arrangements.
Key Responsibilities:
- Integrate SAP security with DevSecOps practices to ensure secure development and operation of SAP systems.
- Support the IT transformation initiative Propel for migrating SAP platforms to the cloud.
- Maintain compliance and enhance security postures within the SAP ecosystem.
- Collaborate with cross-functional teams to align on security priorities.
- Articulate security concepts to diverse audiences, including engineers and executives.
Key Skills:
- Bachelor's degree in computer science, Information Security, or a related field.
- 5+ years of experience in IT security, with at least 3 years focused on SAP security engineering.
- Proven expertise in SAP platforms, including SAP HANA, BOBJ, BW, GRC, and NetWeaver Gateway.
- Strong understanding of DevSecOps principles and CI/CD pipeline security.
- Familiarity with cloud environments (AWS, Azure, Google Cloud Platform) and hybrid SAP deployments.
- Experience with SOX compliance and auditing processes in SAP environments.
- Hands-on knowledge of SAP security modules and SSO implementation.
- Relevant certifications such as SAP Certified Technology Associate Security, CISSP, or CISM.
- Strong analytical and problem-solving skills.
- Excellent communication and teamwork abilities.
Salary (Rate): undetermined
City: undetermined
Country: USA
Working Arrangements: remote
IR35 Status: outside IR35
Seniority Level: undetermined
Industry: IT
- Bachelor's degree in computer science, Information Security, or a related field (or equivalent experience).
- 5+ years of experience in IT security, with at least 3 years focused on SAP security engineering.
- Proven expertise in SAP platforms, including SAP HANA, BOBJ, BW, GRC, and NetWeaver Gateway.
- Strong understanding of DevSecOps principles, including CI/CD pipeline security and automation tools (e.g., Jenkins, Git, Ansible, or similar).
- Familiarity with the shared responsibility model in cloud environments (AWS, Azure, Google Cloud Platform) and hybrid SAP deployments.
- Familiarity with SAP Cloud ALM (Application Lifecycle Management), clean core a plus.
- Experience with SOX compliance and auditing processes in SAP environments.
- Hands-on knowledge of SAP security modules, role administration, and SSO implementation (e.g., SAML, OAuth, Kerberos).
- Experience with SAP RISE or other SAP cloud transformation initiatives is highly desirable.
- Relevant certifications such as SAP Certified Technology Associate Security, CISSP, CISM, or DevSecOps-specific credentials are a plus.
- Strong analytical and problem-solving skills with excellent communication and teamwork abilities.
- Experience with scripting languages (e.g., Python, PowerShell) for automation of security tasks.
- Knowledge of container security (Docker, Kubernetes) in SAP environments.
- Familiarity with secure software development lifecycle (SDLC) practices.
- Understanding of identity and access management (IAM) tools integrated with SAP systems.
- Excellent Communication Skills: Ability to clearly articulate security concepts to diverse audiences, including engineers, product managers, and executives.
- Collaboration & Influence: Proven ability to work cross-functionally with teams to align on security priorities and influence roadmaps.