In this role, you will assess regional and industry specific seurity compliance regulations, perform gap-analyses, create implementation roadmaps and implement these standards across the affected teams. In particular you will implement the GxP compliance and upcoming new security obligations in SAP Cloud ERP solutions (e.g. SAP S/4HANA Cloud Public Edition). You will interact with SAP Global Security and Complinace teams, Product Development and Operation teams, Go-To-Market teams on the requirements coming from obligations and customers. In addition, you will lead internal and external audit programs, support customer audits and security inquries.
Your main topics includes:
Drive new security compliance obligations onboarding process and achieve compliance certificate/attestation
Translate security compliance requirements into executable processes and tool enhancements in collaboration with operators and product teams
Security control design and implementation
Lead in internal and external audits, support customer audits and security inquries
Drive security vulnerability and compliance finding mitigation
Drive security and compliance innovation in the ERP Cloud Delivery environment together with the teams
Own and drive Security & Compliance excellence with a strong focus on quality, continuous improvement, including a cloud mindset
Define and / or execute on Security Infrastructure Automation.
Implement new processes with the goal to optimize SAPs security system
Stay up to date with latest security technology and trends
Attend related educational events to stay competent
What you bring
Bachelor / Masters degree or equivalent in Computer Science, Engineering or Business Information Technology
Very deep knowledge and experience in ISO27001/ISMS/QMS, SOC1/2, GxP, IRAP/CSA, etc.
Strong security mindset, both from a technological and operational aspect
At least one Security and Compliance related certification, such as CISA, CISSP or CASP and/or SIEM-specific training and certification
Process knowledge of operations processes, especially security processes (ITIL Certificate is preferred)
Understanding of cloud service models (IaaS, PaaS, SaaS) and cloud delivery models (private cloud, public cloud)
Excellent team player with strong people / team management skills, able to inspire and energize team and "can-do" attitude with proven agility and flexibility
Basic programming knowledge
Knowledge of Agile Development processes
Critical thinker and problem-solving skills
Basic understanding of Container technology
Experience in SLES operation is highly appreciated
Strong awareness of global cultural differences; previous work experience in a multi-national environment
Work Experience
5+ years of work experience as a cyber security expert or IT auditor
Job Classification
Industry: IT Services & ConsultingFunctional Area / Department: IT & Information SecurityRole Category: IT SecurityRole: Manager Information SecurityEmployement Type: Full time