Sovereign Cloud Security Senior Specialist
Role details
Job location
Tech stack
Job description
We are looking for a Security Compliance Senior Specialist (f/m/d) within the Security & Compliance unit of the newly formed Sovereign Cloud Technology & Deliver team as part of the SAP Government Security & Secrecy board area.
In this role you will become a founding member of the Technology and Engineering team. You will help to build a security and compliance program for Sovereign Cloud, including defining processes and requirements, conducting assessments, and managing remediation.
This a compliance role where you would manage a set of compliance requirements. In addition, you would focus on either risk management or engineering.
- With a risk management focus, you would assist the Security & Compliance team with articulating and escalating risks to the Sovereign Cloud Risk Coordinator. You would manage the risk register and draft risk responses. You would also mentor other team members on risk management topics.
- With an engineering focus, you would act as the subject matter expert within the team for technical domains. You would analyze regional requirements, translate bi-directionally between technical and non-technical personnel, and mentor other team members on engineering topics., Successful candidates might be required to undergo a background verification with an external vendor. AI Usage in the Recruitment Process For information on the responsible use of AI in our recruitment process, please refer to our Guidelines for Ethical Usage of AI in the Recruiting Process.
Please note that any violation of these guidelines may result in disqualification from the hiring process.
Requirements
Do you have experience in NIST standards?, * Thorough understanding of security related topics
- Strong technology skills and the willingness to learn new topics quickly
- Strong analytical research and problem solving skills
- Ability to take large quantities of information and identify key themes
- Ability to clearly and succinctly describe processes
- Ability to manage through ambiguities while being innovative and collaborative
- Strong communication skills and cultural awareness
- Ability to communicate complex technical requirements to a variety of stakeholders
- Strong commitment to high quality work
- Willingness to work flexible hours to accommodate time differences working with colleagues based in other time zones
- Willingness to travel (less than 10%)
- Fluent in English (required)
- Fluent in other languages (second language preferred)
WORK EXPERIENCE
- 4+ years of related professional experience, such as IT audit, risk management, or DevOps (required)
- Specialization in either risk management or engineering (one of the two required)
- Risk management focus requires experience with quantitative risk management
- Engineering focus requires hands-on Security DevOps experience in a cloud environment
- Experienced in the use of at least two cybersecurity frameworks such as UK Cyber Essentials, BSI IT Grundschutz, SecNumCloud, ISO 27001, or NIST 800-53 (preferred)