Senior Product Security Engineer (f/m/d)

SAP
Berlin
Workplace: HybridFull timeFunction: CybersecurityExperience: 8+ yearsSkills: ["Collaboration","Consulting","Mentoring","Stakeholder management","Problem-solving"]

Work with SAP LeanIX’s security team to ensure the application and infrastructure security of the enterprise architecture platform. You’ll lead secure requirements and architecture reviews, threat modeling, secure code review, penetration testing, and incident-response support. Analyze complex vulnerabilities, collaborate with developers and product managers on fixes, support security audits, and embed secure development practices throughout CI/CD. Improve automated security checkpoints and tools while consulting stakeholders and mentoring junior engineers.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
SAP
SAP
2 hours ago

Senior Product Security Engineer (f/m/d)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 2 hours agoStatus: Live

Job Summary

Work with SAP LeanIX’s security team to ensure the application and infrastructure security of the enterprise architecture platform. You’ll lead secure requirements and architecture reviews, threat modeling, secure code review, penetration testing, and incident-response support. Analyze complex vulnerabilities, collaborate with developers and product managers on fixes, support security audits, and embed secure development practices throughout CI/CD. Improve automated security checkpoints and tools while consulting stakeholders and mentoring junior engineers.
Location: Berlin
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Conduct secure requirements, architecture/design, threat modeling, secure code reviews, penetration testing, and incident response activities.
  • •Review and analyze security scan findings, identify patterns, and collaborate with developers and stakeholders on remediation.
  • •Perform analysis of complex vulnerability findings and help design/implement patches or mitigations across teams.
  • •Provide security consulting to cross-functional teams, including developers and product managers, and support security audits/compliance checkpoints.
  • •Continuously monitor product infrastructure security via automated configuration management, and enhance tools/processes with advanced automated security checkpoints; assist leadership metrics and mentor junior team members.
Travel: Low travel

Key Requirements

  • •8+ years of industry experience in application security, secure code reviews, DevSecOps (SAST, SCA), and infrastructure security.
  • •Experience with web application and network vulnerability scanning tools such as Tenable and Qualys.
  • •Hands-on use of security frameworks including OWASP Top 10, NIST, CIS, and SANS CWE.
  • •Cloud security testing experience (Azure/AWS/GCP), including penetration testing and posture management.
  • •Security certifications are a plus (e.g., OSCP, OSWE, CEH, CHFI, CREST).
Experience:8+ years
Skills:CollaborationConsultingMentoringStakeholder managementProblem-solving
Certifications:CREST CRTCREST CPSAOSCPOSWECEHCHFI
Languages:English
Tech Stack:TenableQualysOWASP Top 10NISTCISSANS CWEAzureAWSGCPJavaScriptTypeScriptKotlinJavaPython

Company Brief

SAP
Global enterprise software company best known for ERP systems and business applications covering finance, supply chain, procurement, HR, analytics, and customer management for large organizations.
Industry: Enterprise Software
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Walldorf, Germany
Founded: 1972
Glassdoor
Glassdoor: 4.1
WebsiteLinkedInGlassdoor