Perform Inherent Risk Assessments with the Line of Business Units for the services to be provided by third parties to identify the relevancy of the risk based on security, privacy and compliance.
Perform Security Risk Assessments to the third parties that provide relevant services to SAP, evaluate responses, technical and non-technical evidences and raise potential findings.
Track timelines of identified findings on a periodic basis to ensure the remediation of controls gaps.
Communicate efficiently the results of the different risk assessments to the relevant stakeholders: third parties, Line of Business Units, BISO/risk coordinators.
Negotiate redlines from third parties on the Third Party Security Agreement before the signature from a security perspective.
Follow-up the status of the risk assessments, findings and security agreements, and appropriately escalate to the relevant stakeholders when needed.
What you bring
Professional working experience within Cyber Security, Compliance and/or Security Risk functions and processes.
Knowledge in security related laws: regulations, strategies, processes & operations, standards, and services
Stakeholder engagement/management communicate clearly and convincingly with different stakeholders.
Demonstrate accountability, transparency, integrity, and a team-oriented approach.
good communication and presentation skills.
8+ years of total experience with 6 years of relevant experience working in cyber security risk operations or compliance operations functions.
Fluent written and spoken English skills.
Our mission of the SAP Global Security and Cloud Compliance (SGSC) organization is to strengthen the security foundation for SAP, fitting for a world class enterprise software company. Security and Compliance is a critically necessary requirement for the success at SAPs transformation in the areas of cloud, Al, and sustainability, both internally and externally for SAPs customers. The Role within Security Risk Management is part of the Global Security Compliance and Risk unit which encompasses Governance, Compliance and Certification, as well as Security Risk Management. Security Risk Management aims to proactively safeguard our organizations assets, reputation, and stakeholders by improving the risk culture for behaviour towards, risk taking, negative outcomes, and policy compliance by enhancing trust and risk mitigation while protecting the core values of our organization at all times .
#SecurityT3
Bring out your best
. Successful candidates might be required to undergo a background verification with an external vendor.
Requisition ID: 426014 | Work Area: Administration | Expected Travel: 0 - 10% | Career Status: Professional | Employment Type: Regular Full Time | Additional Locations: #LI-Hybrid.
Requisition ID: 426014
Posted Date: May 14, 2025
Work Area: Administration
Career Status: Professional
Employment Type: Regular Full Time
Expected Travel: 0 - 10%
Location:
Job Classification
Industry: Software ProductFunctional Area / Department: Product ManagementRole Category: Product Management - OtherRole: Product Manager - OtherEmployement Type: Full time