SAP Jobs

Job Information

SAP Product Security Specialist in Bangalore, India

Bring out your best

SAP innovations help more than four hundred thousand customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evolved to become a market leader in end-to-end business application software and related services for database, analytics, intelligent technologies, and experience management. As a cloud company with two hundred million users and more than one hundred thousand employees worldwide, we are purpose-driven and future-focused, with a highly collaborative team ethic and commitment to personal development. Whether connecting global industries, people, or platforms, we help ensure every challenge gets the solution it deserves. At SAP, you can bring out your best.

Summary

SAP I&CX Cloud Operations and Trust office team increases trust of our customers into SAP products and enables the organization to apply security, data protection & privacy and compliance.

Compliance to Security is a default customer expectation for every product, and further-on in the context of the European Union (EU) General Data Protection Regulation (GDPR), there is an emphasis on Data Protection & Privacy (DPP) compliance, ISO 27001 compliance, etc now more than ever before.

The Security Expert in SAP I&CX Trust office is therefore the Product Security Specialist for the organization.

What you'll do

Deep understanding of adherence of Secure Software Development Lifecycle (Secure SDL) during design, development, testing, debugging, delivery and support phase of products.

Knowledge and experience with Data Protection & Privacy principles to be adhered (e.g. GDPR)

Collaborate with product development and solution teams proactively to manage software security risk aligned with business goals.

Support in external and internal audits and certifications of products (e.g., ISO 271001, SOC2 Type1/ Type 2 etc)

Basic understanding of OWASP top 10 and similar application security methodologies

Hands on experience in conducting penetration for web application, API, Webservices, mobile application and thick clients (both cloud and on prem)

Proven hands-on experience working with Static (Checkmarx & Fortify) and Dynamic Security Scan tools (Burp suite, WEB Inspect).

Experience on Open-Source Security code scan tools (e.g., WhiteSource and Blackduck)

Prior experience with Secure Programming principles in at least one programming language (Java, JavaScripts, C etc) will be added advantage.

Understanding of architecture and basic development experience with SAP technologies will be an added advantage.

Expectations and Tasks

S/He shall ensure that all I&CX delivered products mandatorily go through the SAP Secure Software Development Lifecycle (S2DL).

Her/His technical competencies therefore include the ability to

-Lead Security Evaluations & Estimations during the Solution Proposal phase (prior delivery).

-support the Threat Modeling Workshops and Data Protection Compliance Evaluation Workshops during the Design phase.

-perform end to end risk assessment.

-advocate the Secure Programming Guidelines to the Development team during the Build phase.

-own the DPP testcases and audit the mandatory execution of these tests during the MIT phase.

-conduct of the Security Code Scans on support bug fixes and regression tests for resolution of critical Security vulnerabilities

-conduct open-source security scan and guide projects teams to fix vulnerabilities.

Guide architecture decisions based on SAP Product Standard Security and Secure Programming principles.

Drive and ensure the compliance of all delivered projects to Security and Data Protection & Privacy guidelines.

Work closely with Solution Architects, Development Architects, Project Managers, Developers and Quality Assurance, to coordinate the delivery of secure solutions (delivery includes design, development, testing, documentation, go-live and maintenance & support activities)

Perform dynamic application security testing (manual and tool based). Remove the false positives and report issues to the development team.

Perform penetration testing for the applications.

Create and maintain network with Security Experts across SAP (both internal and external).

What you bring

5-7 years of total experience in Information Security

Security certifications like CEH, Security , CCSP, CISSP or any other security related certifications is preferable.

Good English communication skills (written and verbal)

Quick Learner, passionate, motivated, and self-managed

S/He shall ensure that all I&CX delivered products mandatorily go through the SAP Secure Software Development Lifecycle (S2DL).

Bring out your best

SAP innovations help more than four hundred thousand customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evolved to become a market leader in end-to-end business application software and related services for database, analytics, intelligent technologies, and experience management. As a cloud company with two hundred million users and more than one hundred thousand employees worldwide, we are purpose-driven and future-focused, with a highly collaborative team ethic and commitment to personal development. Whether connecting global industries, people, or platforms, we help ensure every challenge gets the solution it deserves. At SAP, you can bring out your best.

We win with inclusion

SAPs culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone regardless of background feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better and more equitable world.

SAP is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to the values of Equal Employment Opportunity and provide accessibility accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for employment with SAP and are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to Recruiting Operations Team: Careers@sap.com

For SAP employees: Only permanent roles are eligible for the SAP Employee Referral Program, according to the eligibility rules set in the SAP Referral Policy (https://one.int.sap/me@sap/jobs_at_sap#17498858-1050-415e-8d82-21f91655666b_96fc) . Specific conditions may apply for roles in Vocational Training.

EOE AA M/F/Vet/Disability:

Qualified applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity, age, gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disability.

Successful candidates might be required to undergo a background verification with an external vendor.

Requisition ID: 395133 | Work Area: Solution and Product Management | Expected Travel: 0 - 10% | Career Status: Professional | Employment Type: Regular Full Time | Additional Locations: #LI-Hybrid.

DirectEmployers