Product Security Engineer

hace 6 días


Barcelona, España SAP A tiempo completo

**We help the world run better**

At SAP, we enable you to bring out your best. Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and future-focused work. We offer a highly collaborative, caring team environment with a strong focus on learning and development, recognition for your individual contributions, and a variety of benefit options for you to choose from.

**What you’ll do**
Join an extraordinary team of innovative engineers, designers, and product managers at SAP Learning Systems — a dynamic hub within the global SAP Learning organization. Our mission is to revolutionize how the SAP ecosystem learns and upskills, creating impactful solutions for our customers and partners. Nestled in the city of Barcelona, our diverse, multicultural, and cross-functional team embodies the agility of a startup, coupled with the scale and influence of a global enterprise.

**Key responsibilities include**:
Security Governance & Compliance:

- Understand and contribute to SAP's standards, enterprise governance, and global security policies.

Risk Assessment & Mitigation:

- Oversee security risks, conduct targeted security risk assessments, and review security exceptions.
- Understand the concrete agile delivery process of the organisation and ensure that the delivery is reinforced with all quality and security standards
- Evaluate the criticality of the security vulnerabilities and risks to ensure an outstanding time-to-marked
- Actively work on automation together with the agile teams to streamline the quality of the delivery

Strategic Leadership:

- Advise corporate leadership on risk reduction proposals, backed by cost justifications.
- Provide leadership, mentoring, and training to security personnel and other SAP stakeholders.

Collaboration & Communication:

- Work collaboratively with internal and external partners for third-party security assessments.
- Develop and monitor security risk metrics, providing periodic updates to executive management.

Secure Development Knowledge:

- Should have knowledge of OWASP Top 10, SANS 25 and NIST Framework.
- Having Hands on Knowledge of implementing Secure development Pipeline of DevSecOps Mind set.
- Having hands on Knowledge on Threat modelling.
- Having Knowledge of Handling Zero-day Vulnerability Management to proactively identify, assess and mitigate emerging threats.

**What you’ll bring**
- BA/BS in Computer Science, Information Security, Business Administration or related work experience
- Minimum of five (5) years of managing IT initiatives/project management required
- Minimum of five (5) years information security, audit, risk management, compliance or risk consulting related experience preferred
- Experience working with Azure Pipelines, GitHub, and GitOps
- Experience managing vulnerabilities with multiple SAST, OSS,FOSS and IP-Scan analysis tools for large solutions
- Hands-on experience securing, managing and/or designing micro-service cloud solutions
- Experience using Governance, Risk and Compliance (GRC) tools preferred
- Security certification, e.g. CISSP, CISA - CRISC preferred
- Ability to demonstrate analytical expertise, close attention to detail, excellent conflicesolution and negotiation skills, logic, and solution orientation and to learn and adapt quickly, thinking out of the box mindset
- Excellent written and oral communication skills in English
- Ability to understand and operate in a dynamic and agile environment
- Proven experience working in multi-functional and multi-cultural teams
- Proactive, self-managed, and able to interface well with sponsor personnel and inter-disciplinary teams across an organization
- Experience with information security compliance audit frameworks and requirements, e.g. NIST, COBIT, CMMI, ISO27001, FISMA, FedRAMP, SOC, SOX, PCI-DSS, GDPR and Data Privacy

**About the Team**
SAP Learning System is building and running SAP’s next generation learning and community experience. We are a newly created organization within SAP Learning, the education, training and adoption unit within SAP.
We’re a 200+ people team, fast running and laser-focused, with a bold vision: enable more than 2M people to learn, upskill and join the SAP ecosystem per year. Given our central role in SAP’s ecosystem, the huge market buzz on moving to cloud, and our unique setup with strong existing assets such as SAP Learning Hub, openSAP and the SAP Community, we believe we have the opportunity of a lifetime to make a big impact in the world of B2B software.

**Bring out your best**

**We win with inclusion**

SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone - regardless of background - feels included and can run at their best. At SAP, we believe we are made stron



  • Barcelona, España Mirantis A tiempo completo

    **Company Description** **About Mirantis** Mirantis is seeking a **Senior Product Security Engineer** to help secure our portfolio of products and services, including enterprise software and critical infrastructure. This role is part of our growing** Product Security program** and will play a key role in implementing security controls, driving remediation...


  • Barcelona, España Mirantis A tiempo completo

    1 day ago Be among the first 25 applicantsAbout MirantisMirantis is the Kubernetes-native AI infrastructure company, enabling organizations to build and operate scalable, secure, and sovereign infrastructure for modern AI, machine learning, and data-intensive applications. By combining open source innovation with deep expertise in Kubernetes orchestration,...


  • Barcelona, España Mirantis A tiempo completo

    Job Description Mirantis is seeking a Senior Product Security Engineer to help secure our portfolio of products and services, including enterprise software and critical infrastructure. This role is part of our growing Product Security program and will play a key role in implementing security controls, driving remediation efforts, supporting compliance...

  • Security Engineer

    hace 1 semana


    Barcelona, España Glovo A tiempo completo

    **About Glovo**: We're a Barcelona-based startup and the fastest-growing delivery player in Europe, Africa, and Western Asia. With food at the core of the business, Glovo delivers any product within your city at any time of day. At Glovo, you'll have the job of your life while working together towards our shared vision to give everyone easy access to...


  • barcelona, España Mirantis A tiempo completo

    Mirantis is the Kubernetes-native AI infrastructure company, enabling organizations to build and operate scalable, secure, and sovereign infrastructure for modern AI, machine learning, and data-intensive applications. By combining open source innovation with deep expertise in Kubernetes orchestration, Mirantis empowers platform engineering teams to deliver...

  • Cloud Security Engineer

    hace 1 semana


    Barcelona, España Product Madness Espana, S.L. A tiempo completo

    **Company Summary** Product Madness is one of the world's largest mobile game studios, with a global presence. Founded in 2007, we’re today a top-grossing leader in social casino mobile games that are crafted with passion and commitment. Our ambition is to entertain millions of players around the world with our remarkable titles that include Heart of...


  • Barcelona, España Mirantis A tiempo completo

    Mirantis is the Kubernetes-native AI infrastructure company, enabling organizations to build and operate scalable, secure, and sovereign infrastructure for modern AI, machine learning, and data-intensive applications. By combining open source innovation with deep expertise in Kubernetes orchestration, Mirantis empowers platform engineering teams to deliver...


  • Barcelona, España TravelPerk A tiempo completo

    **About Us** TravelPerk is a hyper-growth SaaS business travel platform and a pioneer in the future of travel for work. Its all-in-one platform gives travelers the freedom they want whilst providing companies with the control they need. The result saves time, money, and hassle for everyone. TravelPerk has industry-leading travel inventory alongside...


  • Barcelona, España Product Madness Espana, S.L. A tiempo completo

    **Company Summary** Product Madness is one of the world's largest mobile game studios, with a global presence. Founded in 2007, we’re today a top-grossing leader in social casino mobile games that are crafted with passion and commitment. Our ambition is to entertain millions of players around the world with our remarkable titles that include Heart of...


  • Barcelona, España Melza Consulting A tiempo completo

    **Descripción de puesto**: Do you want to work in an Agile environment challenged by the latest trends on software engineering? This is a unique opportunity to be part of an exceptional company that is transforming how thousands of user experience shopping. Main responsibilities: - Direct report to the Chief Information Security Officer and Domain Tech...