We help the world run better
Our company culture is focused on helping our employees enable innovation by building breakthroughs together. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and future-focused work. We offer a highly collaborative, caring team environment with a strong focus on learning and development, recognition for your individual contributions, and a variety of benefit options for you to choose from. Apply now!
What you`ll do
An SAP Global Security Operations Incident Responder is a crucial front-line defender of SAP’s digital enterprise. Our Incident Responders are responsible for triaging security alerts detected by Enterprise Detection and SIEM, analyzing all available data to determine if a cyber-attack is occurring, scoping the extent of a suspected attack, coordinating efforts to contain attacks, performing forensic investigations to determine the details around an attack, and providing guidance on remediation actions.
The Role:
- Performs incident response duties as part of the global cyber incident response team
- Provide timely and relevant updates to SAP leadership and internal stakeholders Acts as a technical liaison for internal and external incident responders
- Carries out attack scope and root cause analyses by using forensic investigation methods
- Partner with internal teams to review monitoring requirements and create detection alerts
- Develop automated workflows that will reduce detection and response times
- Ensure the review and closure of resolved and end-user confirmed cybersecurity incidents
- Follow proper evidence handling and chain of custody protocols to produce written reports documenting digital forensic findings
- Review current process workflows and make improvements to detection and alerting mechanisms
- Identify increasing trend of repetitive incidents, and work with architecture,
- DevOps, and infrastructure teams to identify root cause and create action plans to increase resiliency
- Continuously monitor levels of service as well as interpret and prioritize threats through use of intrusion detection systems, firewalls, other boundary protection devices, and any security incident management products deployed
- Recognize potential, successful, and unsuccessful intrusion attempts and compromises through review and analyses of relevant event detail and summary information
- Test and maintain incident response plans and processes to address existing and emerging threats
What you bring
- Bachelor’s or master’s degree in Computer Science, Information Security, Information Systems, Engineering or related work experience.
- Profound understanding of one or more technical areas like:
- Network protocols (TCP/IP, TLS, HTTP, DNS, SMB, etc.)
- File systems (exFAT, NTFS, ext4, APFS, etc.)
- Memory forensics
- Database and web application security
- Cloud security
- First experiences with one or more scripting languages (PowerShell, Python, Bash, etc.)
- Strong ability to demonstrate analytical expertise, close attention to detail, excellent critical thinking, logic, and solution orientation
- Willingness to learn and operate in a dynamic environment
We build breakthroughs together
SAP innovations help more than 400,000 customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evolved to become a market leader in end-to-end business application software and related services for database, analytics, intelligent technologies, and experience management. As a cloud company with 200 million users and more than 100,000 employees worldwide, we are purpose-driven and future-focused, with a highly collaborative team ethic and commitment to personal development. Whether connecting global industries, people, or platforms, we help ensure every challenge gets the solution it deserves. At SAP, we build breakthroughs, together.
We win with inclusion
SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone – regardless of background – feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better and more equitable world.
SAP is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to the values of Equal Employment Opportunity and provide accessibility accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for employment with SAP and are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to Recruiting Operations Team: Careers@sap.com
For SAP employees: Only permanent roles are eligible for the SAP Employee Referral Program, according to the eligibility rules set in the SAP Referral Policy. Specific conditions may apply for roles in Vocational Training.
EOE AA M/F/Vet/Disability:
Qualified applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity, age, gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disability.
Successful candidates might be required to undergo a background verification with an external vendor.
Requisition ID: 388620 | Work Area: Information Technology | Expected Travel: 0 - 10% | Career Status: Professional | Employment Type: Regular Full Time | Additional Locations: #LI-Hybrid.