Senior Product Security Engineer (f/m/d)
We help the world run better At SAP, we keep it simple: you bring your best to us, and we'll bring out the best in you. We're builders touching over 20 industries and 80% of global commerce, and we need your unique talents to help shape what's next. The work is challenging – but it matters. You'll find a place where you can be yourself, prioritize your wellbeing, and truly belong. What's in it for you? Constant learning, skill growth, great benefits, and a team that wants you to grow and succeed.
What you will do
Summary: We are looking for an experienced Senior Product Security Engineer to work within the security team of SAP LeanIX. In this role, you shall be closely working with Product and Engineering organization and reporting to Director of Information Security.
The Role
As a Senior Product Security Engineer, you shall be responsible for application and infrastructure security of the SAP LeanIX enterprise architecture solution. You could be based in Bonn, Walldorf, Berlin, Dresden or Munich.
Your key tasks shall include:
- Conducting secure requirements review, architecture and design review, threat modeling, secure code review, penetration testing, incident response etc.
- Reviewing security scan findings to find patterns, and collaborating with relevant stakeholders such as developers for resolution
- Performing analysis of complex vulnerability findings; collaborating across functional teams to develop and implement patches/solutions as required to resolve/mitigate the vulnerabilities
- Providing consulting to cross functional teams such as developers and product managers with their security related questions
- Supporting security audits; reviewing/auditing/ensuring compliance to secure development lifecycle checkpoints
- Integrating secure development best practices and methodologies throughout the development and deployment processes for new or existing solutions
- Collaborating across functional teams to implement solutions during incident response efforts
- Monitoring security of product infrastructure on a continuous basis via automated configuration management tools that help ensure that components are updated and secured
- Enhancing tools and processes by developing advanced/automated security checkpoints & solutions, and implementing new tools and techniques
- Assisting leadership in developing and tracking program metrics
- Contribute to extending and improving the security knowledge base in the organization
- Proactively researching latest trends and emerging technologies in security and development, and recommending solution upgrades
- Providing support and guidance to junior team members
What you bring
- Minimum 8 years of true industry experience with application security, secure code reviews, DevSecOps (SAST, SCA) and infrastructure security
- Experience with common web application and network vulnerability scanning tools (e.g. Tenable, Qualys)
- Experience with security frameworks such as OWASP Top 10, NIST, CIS, SANS CWE
- Experience with testing of cloud security (e.g. for Azure, AWS, GCP) including penetration testing, posture management, etc.
- Experience with security testing of AI products>
- Experience in performing / leading threat modeling sessions
- Knowledge of programming languages such as JS/TypeScript, Kotlin, Java, Python
- Relevant Security Certifications are a plus e.g. CREST CRT, CREST CPSA, OSCP, OSWE, CEH, CHFI, etc.
- Fluent in spoken and written English
Meet your team
The Information Security team is responsible for managing the security of SAP LeanIX enterprise architecture solution in coordination with Product and Engineering organization as well as SAP’s central security team.
SAP is committed to the values of Equal Employment Opportunity and provides accessibility accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for employment with SAP and are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e‑mail with your request to Recruiting Operations Team:
#J-18808-Ljbffr