Job Description
You Are Expected To
- Combine your technical expertise with experience in managing complex situations
- Communicate with leading security researchers, customers and SAP’s support organizations on confidential and sensitive disclosures
- Assess the risk of disclosure and work with internal stakeholders to mitigate risk to SAP
What You Bring
Required skills:
- Bachelor Degree in Technology, Computer Science or Engineering
- Enthusiasm for security and technology, understands current security trends
- Experiences in software development, focusing on security or secure software development practices
- Minimum 5-7 years of experience in security, either as a security practitioner, an application security developer, or a security auditor
- Experience in managing complex security incidents as lead/commander
- Experience in working with developers (e.g. DevOps) or other development-supporting roles
Preferred Skills
- Pen-testing experience using tools like Qualys, Burpsuite, Metasploit, etc
- Vulnerability management experience including PoC creation, exploit/attack recreation, triaging, prioritization, fix recommendation and fix validation.
- Thorough understanding of common vulnerability types including OWASP top 10
- Thorough understanding of supply-chain issues in application security
- Awareness of current security relevant regulations (e.g. DORA, CRA)
- Understanding of CVE, CVSS, CWE
- Understanding of NVD, KEV, and the latest CISA initiatives
- Understanding of Cyber Security Framework
- Understanding of Secure SDLC
- Understanding of common security architectures