Skip to content
Security Engineer

Security Engineer

Technology Risk & Security Manager (m/f/d)

Simon-Kucher

Munichlead

Apply on the employer's site

Role description

In Germany
- Berlin | Bonn | Cologne | Frankfurt/Main | Hamburg | Munich

This role serves as the bridge between business demand, IT architecture, cybersecurity, SOC, audit, compliance, procurement, privacy, and implementation teams - operating within the company’s Technology Demand Intake Process, which is closely connected to implementation and lifecycle governance.

This individual will focus on reviewing technical concepts, stand-alone products, services, and AI-enabled solutions that the company plans to implement or integrate into its complex global enterprise technology landscape, including SaaS, PaaS, SAP, and AI-enabled platforms.

You will be responsible for assessing and governing new technology demands, services, platforms, and AI-enabled solutions through the organization’s technology intake process. The role ensures that security, compliance, architecture, operational, and business risks are identified, clearly documented, and addressed through effective and practical mitigation measures

What Makes Us Special

  • Advance your career with exciting professional opportunities in our thriving company with a startup feel.
  • Voice your unique ideas in a corporate culture defined by openness and integrity.
  • Enjoy the opportunity to work from abroad (workation).
  • Feel at home working with our helpful, enthusiastic colleagues who have great team spirit.
  • Broaden your perspective with our extensive training curriculum and learning programs (e.g. LinkedIn Learning).
  • Speak your mind in our holistic feedback and development processes (e.g. 360-degree feedback).
  • Satisfy your need for adventure with our opportunities to live and work abroad in one of our many international offices
  • Enjoy our benefits, such as hybrid working, daycare allowance, corporate discounts, and wellbeing support (e.g. Headspace).
  • Unwind in our break areas where you can help yourself to the healthy snacks and beverages provided.
  • See another side of your coworkers at our frequent employee events and highly anticipated World Meeting and Holiday Party.

How You Will Create An Impact

  • Manage the end-to-end Technology Demand Intake and Risk Assessment process for new technologies, platforms, tools, and AI-enabled solutions.
  • Assess security, compliance, operational, vendor, and architecture risks; identify mitigation strategies and recommend risk treatment decisions.
  • Prepare executive-ready reports and present findings to IT leadership, governance boards, and risk committees.
  • Partner with Security, IT, Architecture, Procurement, Legal, Privacy, Audit, and business stakeholders to evaluate and approve technology solutions.
  • Ensure new technologies comply with security policies, controls, and integration requirements.
  • Maintain risk documentation, exception records, control evidence, and governance reporting while continuously improving intake processes.
  • Stay current on emerging technologies, AI, cybersecurity trends, regulatory requirements, and industry control frameworks.
  • Translate business requirements into security and compliance recommendations that enable timely technology decisions.
  • Communicate complex technical concepts through presentations, decision papers, and executive-facing materials.
  • Facilitate collaboration across IT architecture, infrastructure, business teams, vendors, and other stakeholders.
  • Support vendor assessments, RFPs, technical evaluations, and solution reviews.
  • Contribute to cross-functional IT projects by identifying dependencies, risks, and process improvements.
  • Work effectively in agile, global project environments with multiple priorities and tight timelines.

About You

  • Experience in a complex global environment, comparable consulting or service industries is preferred.
  • Bachelor’s Degree required – preferred in the area of Technology, MIS, Cybersecurity, etc.
  • 5+ years of experience in technology risk, cybersecurity, IT governance, GRC, IT audit, security architecture, or technology consulting.
  • Strong knowledge of cybersecurity, technology risk management, compliance, enterprise IT governance, and emerging AI-enabled technologies.
  • Experience assessing SaaS, cloud, third-party, and AI-enabled solutions, with the ability to identify risks, mitigation strategies, and implementation requirements.
  • Experience improving governance processes, workflows, standards, and risk management practices.
  • Knowledge of security and governance frameworks such as ISO 27001, SOC 2, ITIL, or similar.
  • Experience with security controls, risk assessments, compliance, audit support, and governance approval processes.
  • Ability to evaluate platform architecture, integrations, identity and access management, data flows, encryption, logging, monitoring, and operational security.
  • Understanding of enterprise architecture, cloud security, vendor risk management, and secure technology implementation.
  • Strong stakeholder management skills with experience working across IT, Security, Architecture, Compliance, Privacy, Legal, Procurement, Audit, and business teams.
  • Experience preparing executive-level presentations, risk reports, and decision-ready documentation, and presenting recommendations to senior leadership.
  • Experience evaluating third-party vendors, cloud platforms, SaaS solutions, and managed services within global IT environments.
  • Experience supporting technology onboarding, vendor risk assessments, procurement, RFPs, and cross-functional technology initiatives.
  • Ability to manage risks, remediation activities, project dependencies, and implementation progress across the technology lifecycle.
  • CISSP, CISM, CRISC, CISA, CCSP, ISO 27001 Lead Implementer/Auditor, or equivalent certification (or comparable hands-on experience).

Have we sparked your interest? Simply click the 'Apply now' button to submit your application. Please note that, for data protection reasons, we cannot accept applications via email.

Would you like to learn more about us and our company culture? Click here to watch our recruitment video.

About Simon-Kucher
Simon-Kucher is a global consultancy with more than 2,200 employees in 30+ countries. As a trusted commercial advisor focused on unlocking better growth, we combine deep consulting expertise, growth specialization, and technology to scale lasting impact. We optimize every lever of commercial strategy – product, pricing, innovation, marketing, and sales – based on what customers want and value. With over 40 years of monetization experience, we are recognized as the world’s leading commercial growth and pricing specialist. simon-kucher.com

We believe in building a culture that embraces diversity, equity, and inclusion, creating an environment in which our people feel valued, are able to be themselves and feel their contribution matters. If we get that right, remarkable things will happen; people will grow faster, innovate, feel valued, and create better outcomes for everyone – our people, our clients and, of course, our business.

Your Personal Contact
Christina Jaup-Schwilk

recruitment.germany(at)simon-kucher.com

Please submit your application exclusively via the
“Apply now”
button!

Better growth starts here. With you.

This is a saved copy of a posting published elsewhere. Postings get taken down without notice — check the employer's site before applying. mentors.coach is not the hiring party.

Coming to this page

A resume for this role — and a ticket to the draw

We take the posting apart down to the real requirements and rewrite your resume against it — by asking, not inventing: no line appears without your confirmation. Sign in to get it first, and to enter the draw.

  • A resume for this exact role, not a universal one
  • Answers are kept: edit any one, not the whole conversation
  • All in your account — open it from any device

On the wheel

A discount on mentoring

Winners are drawn at random among entries with a confirmed email. The date and the full rules are on the draw page.

Draw rules

Security Engineer

Senior Solution Architect (Germany)

Veeam Software

Munich

Apply on the employer's site

Role description

Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world’s biggest brands.

About The Role
The ideal candidate will be naturally collaborative, articulate, extremely organized, have a solid technical understanding of Veeam products, and motivated by maximizing customer success and outcomes. Soft skills combined with technical skills are key in this role. You will partner with Customer Success Engineers (CSEs) and Account Executives (AEs) to drive customer outcomes across security-related products and use cases within the Veeam Data Platform (VDP). You’ll lead readiness checks, data modeling, and risk conversations with CISO/CIO stakeholders, while monitoring telemetry and maturity against the Veeam Data Resilience Maturity Model (DRMM) to optimize posture and identify expansion opportunities.

What You’ll Do

  • Engage customers on security-related products, architectures, and risk topics across the Veeam Data Platform (VDP).
  • Run readiness checks and lead data modeling to validate solution design and accelerate decisions.
  • Monitor attack surfaces and vulnerabilities (including DRMM scoring), track telemetry or recurring inspection signals, report trends, and capture potential health checks.
  • Validate designs to de-risk adoption and accelerate time to value.
  • Identify and articulate expansion opportunities; review consumption trends and schedule checkpoint reviews (with or without AE coordination).
  • Engage CISO/CIO stakeholders for risk, status, and opportunity discussions; synthesize inputs from account health and CSE-led QBRs.
  • Support AEs on security- and AI-driven expansion motions; influence roadmap priorities with CSE counterparts.
  • Operate as a pooled resource covering Enterprise and Commercial-Named accounts (generally $100K+ ARR), typically at a 1 Domain Engineering Specialist to 6–8 CSE coverage ratio.

What You’ll Bring

  • 5+ years of experience in engineering architecture for cybersecurity-related products (e.g., Security Engineer/Architect, Cloud Solution Architect, MLOps/ML Engineer).
  • Bachelor’s degree in Computer Science, Electrical Engineering, or a related technical field; advanced degree is a plus.
  • Relevant certifications (e.g., CompTIA Security+, CISSP, or equivalent).
  • Expertise in data security and governance, including DSPM/DLP; familiarity with AI/ML architectures.
  • Demonstrated ability to engage CISO/CIO stakeholders on risk, resilience, and modernization roadmaps.
  • Deep expertise in cloud technologies (AWS preferred; Azure also highly relevant).
  • Hands-on experience with solution design, POCs, telemetry monitoring, and maturity modeling (DRMM familiarity is a plus).
  • Solid working knowledge of Veeam products.
  • Strong communication, stakeholder management, and cross-functional collaboration skills.
  • VMCE/VMCE+ certification (can be completed after joining)

What You'll Get
Veeam offers benefits that support your whole self:

  • 30 paid vacation days, plus 4 extra global VeeaMe Days for self-care and 24 paid volunteer hours annually through Veeam Cares
  • Statutory public health insurance with employer and employee contributions
  • Statutory pension scheme with employer and employee contributions
  • Statutory accident insurance fully funded by Veeam
  • Supplemental pension plan with employer match and salary sacrifice option
  • Supplemental accident insurance with 24/7 worldwide coverage
  • Opportunities to learn and grow through on-demand libraries (LinkedIn Learning, O’Reilly), mentoring, workshops and learning events like our annual Global Day of Learning

Please note: If an applicant is permanently located outside of Germany, Veeam reserves the right to decline the application for this position.

Veeam Software is an equal opportunity employer
and does not tolerate discrimination in any form on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state or local law. All your information will be kept confidential.

Personal data collected during the recruitment process will be processed in accordance with our Recruiting Privacy Notice, which explains how your information is collected, used, and handled in connection with hiring activities. By applying for this position, you consent to this processing.

By submitting your application, you confirm that the information provided, including any supporting documents, is complete and accurate to the best of your knowledge. Any misrepresentation, omission, or falsification may result in disqualification from consideration or, if discovered after employment begins, termination of employment.

This is a saved copy of a posting published elsewhere. Postings get taken down without notice — check the employer's site before applying. mentors.coach is not the hiring party.

Security Engineer

(Senior) Manager Identity & Access Management (m/w/d)

Deloitte

Berlin

Apply on the employer's site

Role description

Deloitte bietet führende Prüfungs- und Beratungsleistungen in Audit & Assurance, Tax & Legal, Consulting und Advisory - für nahezu 90 % der Fortune Global 500® und zahlreiche private Unternehmen. Wir liefern innovative Denkansätze, lösen komplexe Herausforderungen und fördern nachhaltiges Wachstum. Mit rund 470.000 Mitarbeitenden weltweit eröffnen wir hervorragende Karrierechancen - getragen von einem starken „Wir“ und einer Vielfalt an Perspektiven und Fähigkeiten.

Du willst im Bereich
Consulting - Cyber
zu einer sicheren digitalen Transformation beitragen? Unser globales Expert:innen-Team unterstützt Kunden mit technischer und strategischer Expertise ganzheitlich bei allen relevanten Aspekten zum Thema Cyber Security: Von der Gestaltung sicherer Geschäftsprozesse über die Verwendung innovativer Technologien bis hin zur Durchführung von Trainings und Awarenesskampagnen. Sichere unseren gemeinsamen Erfolg und mach mit uns den Unterschied: als
(Senior) Manager Identity & Access Management (m/w/d).
Standorte:
Berlin
, Düsseldorf
, Frankfurt (Main)
, Hamburg
, Köln
, München
, Nürnberg
und Stuttgart
.

Dein Impact:
Als (Senior) Manager Identity & Access Management (m/w/d) verantwortest du die Beratung internationaler Kunden im Bereich Identity & Access Management (IAM) und Privileged Access Management Tools - und trägst so zu nachhaltigen Prozessen und nachhaltiger Umsetzung von IAM-/PAM-Lösungen bei.

  • Aufgabenvielfalt: Du agierst als Projektleiter:in in allen Projektphasen, von der Akquise über die initiale Anforderungsanalyse, Konzeption und anschließender Implementierung bis hin zum Go Live und erfolgreichen Betrieb
  • Know-how: Dabei bist du als Subject Matter Expert verantwortlich für die Governance, Architektur sowie Integration und realisierst das IAM-Zielbild des Kunden-
  • Customizing: In deinen Projekten passt du die IAM-Tools erfolgreich an die Kundenerfordernisse an und fungierst als zentrale:r Ansprechpartner:in für Governance, Standards und Regulatorik.
  • Innovation: Mit deiner Expertise werden unsere Produkte und Services kontinuierlich marktorientiert weiterentwickelt und neue Kundensegmente erschlossen.
  • Führung: Mit deinem kooperativen Führungsstil und gezieltes Coaching förderst du die Weiterentwicklung Teams.

Dein Skillset:

  • Erfolgreich abgeschlossenes Studium in Informationssicherheit, Ingenieurwissenschaften, (Wirtschafts-) Informatik oder vergleichbar, mind. 5 Jahre Berufserfahrung im Bereich IAM, CISSP/CISM oder vergleichbare Zertifizierungen von Vorteil
  • Fundierte Erfahrung mit fachlichen Anforderungen (regulatorische Anforderungen MaRisk, BAIT/VAIT) im Zusammenhang mit der Implementierung von relevanten IAM-Lösungen wie One Identity und SailPoint sowie in deren Customizing / Konfiguration
  • Differenziertes Wissen im Bereich der IAM-Prozesse, vom Design bis hin zur Implementierung, um diese entlang der Kundenanforderungen auszurollen
  • Sehr gute Kenntnisse unterschiedlicher IT-Sicherheitsstandards (bspw. ISO27X, NIST), IAM-Anforderungen und -Architekturen
  • Hohes Engagement, Freude an der Führung internationaler interdisziplinärer Teams, souveräne Kommunikation auf allen Hierarchieebenen
  • Reisebereitschaft sowie verhandlungssichere Deutsch- und Englischkenntnisse

Deine Chance:

  • Best-in-class Weiterbildung an der Deloitte University sowie im Rahmen individueller Qualifikationsangebote und Trainings
  • Umfassende Entwicklungschancen durch strukturierte Karriereplanung, Inclusive Leadership, Entsendungsprogramme, projektbasierte Job-Rotation sowie Förderung sozialen Engagements und Corporate Volunteering
  • Vereinbarkeit von Beruf & Familie dank Mobile Working & Teilzeit, Sabbaticals und Familienservice, z. B. zur Unterstützung für pflegende Angehörige, Elternzeit-Beratung und vielem mehr
  • Gesundheit & Fitness im Fokus durch regelmäßige Gesundheitstage, Kooperationen mit Fitness-Anbietern und die Unterstützung von Sport- und Teamevents
  • Attraktive Arbeitgeberleistungen inklusive Bike- und Pkw-Leasing, Firmen-Smartphone zur privaten Nutzung sowie flexiblen Arbeitsmodellen wie z. B. Vertrauensarbeitszeit und EU Remote Working
  • Vielfältige Gestaltungsräume und aktive Förderung einer inklusiven Unternehmenskultur - u. a. durch unsere Diversity & Inclusion Mitarbeiter:innen-Netzwerke

Bist du bereit? Mach mit uns den Unterschied!
Unser Recruiting-Team freut sich auf deine Bewerbungsunterlagen (CV sowie Abitur-, Hochschul- und Arbeitszeugnisse) über unser Online-Formular. Ein Anschreiben und ein Bewerbungsfoto sind bei uns nicht erforderlich.

Gleiche Chancen für alle:
Wir freuen uns über Bewerbungen von Menschen, die so vielfältig sind wie wir – unabhängig von Alter, Behinderung, ethnischer Herkunft und Nationalität, Geschlecht, Religion, sexueller Orientierung oder sozialer Herkunft.
Noch Fragen?
Alle Infos zu unserem Bewerbungsprozess findest du in unseren
Bewerbungs-FAQs
.

Dein Kontakt bei Fragen rund um Karrierethemen
Unser Team Talent Acquisition – Aleksandra, Anja, Julia, Lea, Lisa, Silja und ihre Teams – unterstützt dich gerne bei allen Fragen rund um deine Karriere bei Deloitte. Du erreichst uns per E-Mail unter career@deloitte.de oder telefonisch unter +49 211 87724111.

Job-ID: 48880

This is a saved copy of a posting published elsewhere. Postings get taken down without notice — check the employer's site before applying. mentors.coach is not the hiring party.

Security Engineer

(Senior) Information Security & Compliance Expert (m/w/d)

caralegal

Berlin

Apply on the employer's site

Role description

Werde Teil unseres Teams!

Du möchtest an der Schnittstelle zwischen Informationssicherheit, Technologie und Produktentwicklung arbeiten und mitgestalten, wie Unternehmen regulatorische Anforderungen effizient in die Praxis umsetzen?

Mit unserer Data Responsibility Plattform unterstützen wir Unternehmen dabei, Datenschutz-, Compliance- und Informationssicherheitsanforderungen wie DSGVO, ISO 27001, NIS2, KI-Verordnung oder künftig DORA verständlich, skalierbar und zukunftssicher abzubilden. Unsere Mission: We make the legal way the lighter way.

Wir suchen einen
(Senior) Information Security & Compliance Expert (m/w/d)
, der fundierte Erfahrung im Bereich Informationssicherheit mitbringt und komplexe regulatorische Anforderungen in verständliche Inhalte, Prozesse und Produktanforderungen übersetzen kann. Du hilfst dabei, die Sprache der Informationssicherheit für unterschiedliche Zielgruppen im Unternehmen nutzbar zu machen – vom Product Team über Sales und Customer Success bis hin zum Marketing.

Deine Rolle

Brücke zwischen Informationssicherheit & Produkt

  • Analysiere neue und bestehende Anforderungen aus Informationssicherheit und Compliance (u. a. ISO 27001, ISMS, NIS2, DORA) und übersetze diese gemeinsam mit dem Produktteam in klare, praxisnahe Produktfunktionalitäten.
  • Entwickle fachliche Inhalte, Workflows und Entscheidungshilfen, die regulatorische Anforderungen verständlich, anwendbar und nutzerorientiert vermitteln.
  • Bringe deine Expertise in die Produktstrategie ein und unterstütze das Product Management bei der Priorisierung und Ausgestaltung relevanter Themen.
  • Hilf dabei, komplexe Anforderungen so aufzubereiten, dass daraus konkrete und umsetzbare Produktanforderungen entstehen.

Kollaboration im Produktteam

  • Arbeite eng mit Product Management, UX und Engineering zusammen.
  • Stelle sicher, dass Anforderungen aus Informationssicherheit und Compliance nicht nur korrekt umgesetzt, sondern für Nutzer verständlich und praktikabel nutzbar werden.
  • Fördere ein gemeinsames Verständnis regulatorischer Anforderungen innerhalb des Produktteams.
  • Bringe neue Entwicklungen und Best Practices aus dem Bereich Informationssicherheit frühzeitig in die Produktentwicklung ein.

Unterstützung von Sales & Customer Success

  • Begleite Sales bei Kundengesprächen als fachliche Ansprechpartner für Fragen rund um Informationssicherheit, Compliance und die Umsetzung dieser Themen in unserem Produkt.
  • Unterstütze unsere Sales- und Customer-Success-Teams dabei, regulatorische Anforderungen sicher und verständlich gegenüber Prospects und Kunden zu kommunizieren.
  • Erstelle Materialien, Leitfäden und Schulungsinhalte, die interne Teams befähigen, fachlich fundiert und kundenorientiert zu agieren.

Marketing & Thought Leadership

  • Recherchiere, strukturiere und bereite Themen aus Informationssicherheit und Compliance für Webinare, Whitepaper, Blogartikel, Fachbeiträge oder Kampagnen auf.
  • Positioniere dich und caralegal als kompetente Stimme für Informationssicherheit, Compliance und digitale Regulierung.
  • Identifiziere relevante regulatorische Entwicklungen und übersetze sie in verständliche und nutzbringende Inhalte für unterschiedliche Zielgruppen.

Dein Profil

  • Abgeschlossenes Studium in Informatik, Informationssicherheit, IT-Sicherheit, Wirtschaftsinformatik oder einer vergleichbaren Fachrichtung – alternativ eine vergleichbare Qualifikation mit entsprechender Berufserfahrung.
  • 2–5+ Jahre relevante Berufserfahrung im Unternehmen, idealerweise im Bereich Informationssicherheit, IT-Compliance, Governance, Risk & Compliance (GRC) oder einem vergleichbaren Umfeld.
  • Fundiertes Verständnis von Informationssicherheitsstandards und regulatorischen Anforderungen, insbesondere ISO 27001, ISMS und idealerweise NIS2.
  • Fähigkeit, komplexe fachliche und regulatorische Anforderungen verständlich für unterschiedliche Zielgruppen aufzubereiten.
  • Erfahrung in der Zusammenarbeit mit verschiedenen Stakeholdern und der Vermittlung zwischen Fachbereichen.
  • Ausgeprägte Kommunikations- und Präsentationsfähigkeiten.
  • Strukturierte, selbstständige Arbeitsweise und hoher Qualitätsanspruch.
  • Idealerweise Erfahrung im Umfeld digitaler Produkte, SaaS oder B2B-Softwareunternehmen.
  • Kenntnisse angrenzender Regulierungsbereiche wie DSGVO, KI-Verordnung, DORA oder Data Act sind von Vorteil.
  • Fließende Deutsch- und Englischkenntnisse.
  • Wohnsitz in Deutschland.

Warum wir?

  • Wir bieten Dir abwechslungsreiche und verantwortungsvolle Aufgaben mit viel Gestaltungsspielraum.
  • Wir sind ein internationales Team mit flachen Hierarchien und kurzen Kommunikationswegen.
  • Wir bieten Dir eine kollaborative und offene Unternehmenskultur, in der Deine Ideen geschätzt und Deine Stärken gefördert werden.
  • Wir bieten Dir flexible Arbeitszeiten mit der Möglichkeit, remote zu arbeiten.
  • Wir bieten ein faires Vergütungspaket, bestehend aus Fixum und Provision.
  • Wir bezuschussen Deine betriebliche Altersvorsorge.
  • Wir mögen unsere moderne Arbeitsplatz-Ausstattung in unmittelbarer Nähe zum Hauptbahnhof.
  • Wir lieben Feste: Team- und Firmenevents sowie regelmäßige Get-together.

Über uns

Let's make the legal way the lighter way!
caralegal ist ein etabliertes RegTech Unternehmen aus Berlin, das es sich zum Ziel gesetzt hat, Datenverantwortung zur Normalität zu machen. Unser interdisziplinäres Team besteht aus ExpertInnen für Recht, Technologie und User Experience.

Unsere Data Responsibility Plattform macht Datenschutz- und AI-Governance- Prozesse für Unternehmen abbildbar. Gemeinsam mit führenden DatenschutzexpertInnen entwickeln wir intuitive Software, die Unternehmen beim rechtskonformen Einsatz von Technologie entlastet – und Teams dabei hilft, ihren Datenschutz souverän im Griff zu behalten.

So unterstützen wir mittlerweile mehr als 1000 Unternehmen mit unserer Plattform dabei, die datenrechtlichen Compliance-Vorgaben in die Praxis zu übersetzen.

This is a saved copy of a posting published elsewhere. Postings get taken down without notice — check the employer's site before applying. mentors.coach is not the hiring party.

Security Engineer

Senior Product Security Engineer (f/m/d)

SAP

Berlinfulltimesenior

Apply on the employer's site

Role description

We help the world run better
At SAP, we keep it simple: you bring your best to us, and we'll bring out the best in you. We're builders touching over 20 industries and 80% of global commerce, and we need your unique talents to help shape what's next. The work is challenging – but it matters. You'll find a place where you can be yourself, prioritize your wellbeing, and truly belong. What's in it for you? Constant learning, skill growth, great benefits, and a team that wants you to grow and succeed.

What you`ll do:
Summary
We are looking for an experienced Senior Product Security Engineer to work within the security team of SAP LeanIX. In this role, you shall be closely working with Product and Engineering organization and reporting to Director of Information Security.

The Role
As a
Senior Product Security Engineer
, you shall be responsible for application and infrastructure security of the SAP LeanIX enterprise architecture solution. You could be based in Bonn, Walldorf, Berlin, Dresden or Munich.

Your Key Tasks Shall Include

  • Conducting secure requirements review, architecture and design review, threat modeling, secure code review, penetration testing, incident response etc.
  • Reviewing security scan findings to find patterns, and collaborating with relevant stakeholders such as developers for resolution
  • Performing analysis of complex vulnerability findings; collaborating across functional teams to develop and implement patches/solutions as required to resolve/mitigate the vulnerabilities
  • Providing consulting to cross functional teams such as developers and product managers with their security related questions
  • Supporting security audits; reviewing/auditing/ensuring compliance to secure development lifecycle checkpoints
  • Integrating secure development best practices and methodologies throughout the development and deployment processes for new or existing solutions
  • Collaborating across functional teams to implement solutions during incident response efforts
  • Monitoring security of product infrastructure on a continuous basis via automated configuration management tools that help ensure that components are updated and secured
  • Enhancing tools and processes by developing advanced/automated security checkpoints & solutions, and implementing new tools and techniques
  • Assisting leadership in developing and tracking program metrics
  • Contribute to extending and improving the security knowledge base in the organization
  • Proactively researching latest trends and emerging technologies in security and development, and recommending solution upgrades
  • Providing support and guidance to junior team members

What You Bring

  • Minimum 8 years of true industry experience with application security, secure code reviews, DevSecOps (SAST, SCA) and infrastructure security
  • Experience with common web application and network vulnerability scanning tools (e.g. Tenable, Qualys)
  • Experience with security frameworks such as OWASP Top 10, NIST, CIS, SANS CWE
  • Experience with testing of cloud security (e.g. for Azure, AWS, GCP) including penetration testing, posture management, etc.
  • Experience with security testing of AI products
  • Experience in performing / leading threat modeling sessions
  • Knowledge of programming languages such as JS/TypeScript, Kotlin, Java, Python
  • Relevant Security Certifications are a plus e.g. CREST CRT, CREST CPSA, OSCP, OSWE, CEH, CHFI, etc.
  • Fluent in spoken and written English

Meet Your Team
The Information Secuity team is responsible for managing the security of SAP LeanIX enterprise architecture solution in coordination with Product and Engineering organization as well as SAP’s central security team.

Bring out your best
SAP innovations help more than four hundred thousand customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evolved to become a market leader in end-to-end business application software and related services for database, analytics, intelligent technologies, and experience management. As a cloud company with two hundred million users and more than one hundred thousand employees worldwide, we are purpose-driven and future-focused, with a highly collaborative team ethic and commitment to personal development. Whether connecting global industries, people, or platforms, we help ensure every challenge gets the solution it deserves. At SAP, you can bring out your best.

We win with inclusion
SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone – regardless of background – feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better world.

SAP is committed to the values of Equal Employment Opportunity and provides accessibility accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for employment with SAP and are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to Recruiting Operations Team: Careers@sap.com.

For SAP employees: Only permanent roles are eligible for the SAP Employee Referral Program, according to the eligibility rules set in the SAP Referral Policy. Specific conditions may apply for roles in Vocational Training.

AI Usage in the Recruitment Process
For information on the responsible use of AI in our recruitment process, please refer to our Guidelines for Ethical Usage of AI in the Recruiting Process.

Please note that any violation of these guidelines may result in disqualification from the hiring process.

Requisition ID: 443114 | Work Area: Solution and Product Management | Expected Travel: 0 - 10% | Career Status: Professional | Employment Type: Regular Full Time | Additional Locations:

This is a saved copy of a posting published elsewhere. Postings get taken down without notice — check the employer's site before applying. mentors.coach is not the hiring party.

307 more openings in this category and country

Technology Risk & Security Manager (m/f/d)Simon-Kucher · Germany

Apply on the employer's site