SAP

Senior Security Engineer - SAP Ariba

SAP

June 11, 2021


What we offer
Our company culture is focused on helping our employees enable innovation by building breakthroughs together. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and future-focused work. We offer a highly collaborative, caring team environment with a strong focus on learning and development, recognition for your individual contributions, and a variety of benefit options for you to choose from. Apply now!

Senior Security Engineer - SAP Ariba


The Role

As a Senior Security Engineer at Ariba, you will lead the effort to secure the world’s #1 cloud procurement platform. You and team of security architects will set the direction and coordinate efforts across the Ariba operations and platform on all security topics. You will also closely coordinate with your peers in the other SAP cloud businesses and the SAP Global Security team to help develop the overall strategy and ensure that Ariba is aligned to it.
Role Responsibilities

  • Manage security requirements for container-based solutions within Kubernetes and Nomad environments.
  • Ensure that security requirements are followed during build, ship, and run-time phases of the container deployment.
  • Align with various teams to ensure that container vulnerabilities are remediated within pre-defined SLA’s to limit potential compromise
  • Align with internal teams to ensure successful security and compliance programs that align with client and regulatory compliance requirements
  • Support exception and risk management processes, by documenting vulnerability scan and remediation exception requests and risks as needed.
  • Evaluate risks that the applicable container vulnerabilities pose to the organization and understand the technical implementation details to assess and recommend security control improvements or identify mitigating controls
  • Assist with remediation of control deficiencies identified during the audit process.
  • Perform vulnerability assessments
  • Ensure communication and escalation of security activities to leadership, assist in the development process and operating procedures
  • Develop technical solutions to help mitigate security vulnerabilities.
  • Review and enhance on premise and cloud-based image creation process, to ensure compliance with security requirements.

Qualifications

  • 5-7 years’ professional experience with 3-5 years involving container security, vulnerability management, risk management, compliance, and privacy of non-public personal data
  • In-depth experience in medium to complex computing environments, with advanced
  • knowledge of container systems like Docker and container orchestration like Nomad, Kubernetes.
  • Understanding of container security, orchestration, registries, container build strategies, cloud storage,
  • Experience securing Kubernetes stacks and ensuring their safe usage for development environments Understanding of various cloud environments (GCP, AWS, Azure) security and vulnerability management
  • Experience with IT security and privacy risk assessments and audits of IT general security controls
  • Knowledge of Mitre and Cyber Kill Chain methods
  • Experience in Web Services
  • Broad vulnerability scanning experience (network, operating systems, applications, database, containers) a plus.
  • Good working knowledge of infrastructure security concepts including firewalls, DMZs, intrusion detection/prevention systems, network security, application security concepts, password management, RBAC, access provisioning, SIEM and OWASP a plus
  • Experience with the phases of the software development lifecycle
  • Experience with common vulnerability scanning and penetration testing tools
  • Knowledge of common computer security issues, including network and application vulnerabilities
  • Knowledge of Linux and its security a plus
  • Post-secondary qualifications involving technical analysis, financial services, problem solving, and writing
  • Thorough understanding of computer networking, routing, and protocols


Location

Palo Alto, CA or Fully Remote hire is possible.

About SAP Ariba

Ariba, an SAP Company makes business commerce as easy as consumer commerce. Every day, we help our customer find opportunities to cut costs, reduce risk, and grow revenue through better
collaboration with trading partners. We enable the collaboration through the Ariba Network – a cloud-based community where you will find buying, selling, and managing cash to be as easy as using Amazon,
eBay, and PayPal. We also host other online communities where business commerce professionals network and share information and best practices, just like friends on Facebook.
#WorkWithMaxx

We are SAP

SAP innovations help more than 400,000 customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evolved to become a market leader in end-to-end business application software and related services for database, analytics, intelligent technologies, and experience management. As a cloud company with 200 million users and more than 100,000 employees worldwide, we are purpose-driven and future-focused, with a highly collaborative team ethic and commitment to personal development. Whether connecting global industries, people, or platforms, we help ensure every challenge gets the solution it deserves. At SAP, we build breakthroughs, together.

Our inclusion promise

SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone – regardless of background – feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better and more equitable world.
SAP is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to the values of Equal Employment Opportunity and provide accessibility accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for employment with SAP and are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to Recruiting Operations Team: Americas: Careers.NorthAmerica@sap.com or Careers.LatinAmerica@sap.com, APJ: Careers.APJ@sap.com, EMEA: Careers@sap.com.
EOE AA M/F/Vet/Disability:
Qualified applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity, age, gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disability.
Successful candidates might be required to undergo a background verification with an external vendor.
Requisition ID:292331 | Work Area: Information Technology | Expected Travel: 0 - 10% | Career Status: Professional | Employment Type: Regular Full Time | Additional Locations: Virtual - USA