Product Security Specialist
SAP · Software Development
- Location: Sofia (Bulgaria)
- Work arrangement: remote in country
- Employment type: Full Time
- Seniority: senior
- Posted:
Job description
Position:
(Senior) Product Security Specialist/ DevSecOps
Company:
SAP
Location:
(Bulgaria, Sofia)
Employment type:
Regular Full Time
Short Summary:
Join SAP's HANA organization to help protect one of SAP's most strategic cloud platforms, contributing to the security, compliance, and reliability of services used by customers worldwide.
Responsibilities:
- Design, develop and operate scalable microservices that deliver critical security functionalities for SAP HANA Cloud, following secure-by-design and DevSecOps principles.
- Embed security into CI/CD pipelines — integrating automated security scanning, vulnerability management, policy enforcement, and compliance check as first-class pipeline stages.
- Enable a trusted and secure environment for customers by translating regulatory and internal security requirements into automated, code-driven controls.
- Design and maintain secure access control mechanisms — including RBAC models and authentication/authorization flows.
- Collaborate closely with cross-functional engineering teams to align security goals with development priorities from design through deployment.
- Implement and maintain infrastructure-as-code and policy-as-code practices for consistent security configurations.
- Provide ongoing observability, support, and continuous improvement for deployed security services.
Requirement:
- Proven experience developing and operating microservices in cloud-native environments using DevSecOps practices.
- Experience with CI/CD pipelines and security automation tooling (e.g., Azure DevOps, Jenkins).
- Deep understanding and hands-on experience with Kubernetes, including security hardening and public cloud platforms (AWS, Azure, GCP).
- Experience with user access and identity management — including RBAC design and secure authentication mechanisms (OAuth 2.0, OIDC, SAML).
- Good understanding of encryption, secrets management, and key rotation strategies.
- Solid scripting skills (e.g., Python) to automate security operations.
- Experience with log aggregation and visualization platforms for security monitoring.
- A strong collaborative mindset to drive secure practices across engineering teams.
Benefits:
- Constant learning and skill growth.
- Great benefits and a team that supports your growth and success.
(Senior) Product Security Specialist/ DevSecOps
Company:
SAP
Location:
(Bulgaria, Sofia)
Employment type:
Regular Full Time
Short Summary:
Join SAP's HANA organization to help protect one of SAP's most strategic cloud platforms, contributing to the security, compliance, and reliability of services used by customers worldwide.
Responsibilities:
- Design, develop and operate scalable microservices that deliver critical security functionalities for SAP HANA Cloud, following secure-by-design and DevSecOps principles.
- Embed security into CI/CD pipelines — integrating automated security scanning, vulnerability management, policy enforcement, and compliance check as first-class pipeline stages.
- Enable a trusted and secure environment for customers by translating regulatory and internal security requirements into automated, code-driven controls.
- Design and maintain secure access control mechanisms — including RBAC models and authentication/authorization flows.
- Collaborate closely with cross-functional engineering teams to align security goals with development priorities from design through deployment.
- Implement and maintain infrastructure-as-code and policy-as-code practices for consistent security configurations.
- Provide ongoing observability, support, and continuous improvement for deployed security services.
Requirement:
- Proven experience developing and operating microservices in cloud-native environments using DevSecOps practices.
- Experience with CI/CD pipelines and security automation tooling (e.g., Azure DevOps, Jenkins).
- Deep understanding and hands-on experience with Kubernetes, including security hardening and public cloud platforms (AWS, Azure, GCP).
- Experience with user access and identity management — including RBAC design and secure authentication mechanisms (OAuth 2.0, OIDC, SAML).
- Good understanding of encryption, secrets management, and key rotation strategies.
- Solid scripting skills (e.g., Python) to automate security operations.
- Experience with log aggregation and visualization platforms for security monitoring.
- A strong collaborative mindset to drive secure practices across engineering teams.
Benefits:
- Constant learning and skill growth.
- Great benefits and a team that supports your growth and success.
Skills
- ci/cd
- kubernetes
- microservices
- scripting
Languages
EN
Apply
Open this job in our interactive board to apply, save it, or sign up for matched alerts on similar roles.
View & apply