Jobs and Careers
SA

Senior Manager, Business Information Security Officer (BISO) (f/m/d)

SAP
Germanyfull_timeVerifiedPosted 1 Dec 2023

About the role

<p> </p> <p>We help the world run better</p> <p> </p> <p>Our company culture is focused on helping our employees enable innovation by building breakthroughs together. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and future-focused work. We offer a highly collaborative, caring team environment with a strong focus on learning and development, recognition for your individual contributions, and a variety of benefit options for you to choose from. Apply now!</p> <p> </p> <p> </p> <p> </p> <p>Meet your team</p> <p> </p> <p>The purpose of Intelligent Enterprise Solutions (IES) – as the internal IT organization and part of the Board Area People &amp; Operations – is to deliver and run the Intelligent Enterprise. IES Security acts as cross-functional unit for all Delivery and Operation units in IES to provide IT Security guidance and services in close alignment with SAP Global Security. </p> <p> </p> <p>As Senior Manager, Business Information Security Officer (f/m/d) your team will be the central and cross-functional security team in SAPs internal IT department. Your colleagues are distributed in Germany and the US. They cover all areas of cyber security and support the teams with their expertise in Risk Management, Awareness &amp; Training, Identity Management, Incident Response etc. New ideas and views are very much appreciated and expected.</p> <p> </p> <p> </p> <p>What you’ll do</p> <p> </p> <p>The BISO leads the security strategy of IES and is the bridge to SAP Global Security (SGS) to better integrating security into all processes. This role is key to ensure cross-functional collaboration and engagement with security experts within (and outside) IES with the goal to protect IES, but also SAP from cyber threats and security incompliance. To reach this, you have to manage multiple cybersecurity topics and lead two teams and several SMEs in all areas of cybersecurity. </p> <p> </p> <p>The main responsibilities will be: </p> <p> </p> <ul> <li>Motivate the own team members, but also other IES teams to be curious and interested in cybersecurity. Lead and empower security experts, acting as security multiplier and be a change agent to ensure that everybody in IES considers security in SAP’s cloud transformation</li> <li>Take over accountability for security processes and tasks, where no owner or specific process is defined yet. Improve the situation (not making it more complex) by supporting other IES units with the security capabilities of your team</li> <li>Align security requirements with IES core business processes and ensure that relevant security aspects are covered while also considering business operation</li> <li>Plan the IES security projects incl. budgets and align them with stakeholders in and outside IES considering new technologies, threats, and chances in the cybersecurity ecosystem</li> <li>Drive the consumption of central security services (e.g., Vulnerability Management) where it is reasonable and provide additional security services (e.g., application-specific security monitoring) </li> <li>Ensure that all functions of the NIST CSF are covered in IES, that external audit requests (ISO, SOX etc.) are adequately handled and that internal audits are coordinated</li> <li>Ensure that roadblocks in security projects (IAM, Security Monitoring, Vulnerability Management, Incident Response etc.) are eliminated </li> <li>Balance the security needs and capabilities from several stakeholders like IES Delivery &amp; Operation units, SGS, Data Protection, Legal etc.</li> </ul> <p> </p> <p> </p> <p>What you bring</p> <p> </p> <ul> <li>Bachelor’s / Master’s degree in Cybersecurity, Computer Science, Business Informatics, or related discipline</li> <li>High level of resilience, patience, and motivation for all cybersecurity topics</li> <li>Very good knowledge in core cybersecurity areas (Risk Management, Security Architecture, IAM, Security Detection, Secure Development, Vulnerability Management, Awareness &amp; Training, Incident Response, Recovery). Technical in-depth / hands-on expertise in at least 4 of these areas required</li> <li>Good knowledge in security compliance areas and how to handle audits (ISO, SOX etc.), but also practical experience in executing audit (responses), defining, and fulfilling controls etc.</li> <li>Strong communication skills (focusing C-Level, technical experts, business experts and auditors)</li> <li>At least 10 years’ experience working in IT Security functions, at least 5 years as a people manager</li> <li>Fluent English language skills are a prerequisite.</li> </ul> <p> </p> <p> </p> <p>We build breakthroughs together</p> <p> </p> <p>SAP innovations help more than 400,000 customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evol

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

SAP

View company profile →