
Security Operations Engineering Lead
4 semanas atrás
**PURPOSE AND OBJECTIVES**
SAP Concur Security Operations is a central function that is responsible for ensuring SAP Concur's ability to maintain and improve our SOC Maturity Model, determine ongoing control and remediation requirements and monitor them to ensure remediation of security gaps. SAP Concur Security Operations further supports the line of business in developing threat hunting techniques for Service Organization Control (SOC) detections and investigations.
SAP Concur Security Operations is a global team with a follow-the-sun structure. It closely interacts with global and local functions in the areas of development and compliance, product development, audit support, incident management and other internal and external stakeholders. Members of the Security Operations team will utilize a threat-based security approach focused on known and active adversarial behaviors.
- Live your virtue as a problem solver for complex issues and security requirements
- Be a functional lead and drive internal projects
- Be part of a global and diverse team
- Work in an operations and security function (incident management and data loss prevention)
- Learn about security and compliance aspects of all of SAP Concur's products
- Learn how SAP Concur is dealing with third party products and build-in's
- Obtain insights to risk management and respective mitigation
- Broaden your network within security and other functions such as development
- Have fun
**EXPECTATIONS AND TASKS**
- Lead incidents of local, regional, and global scales, setting goals and prioritizing tasks
- Is part of a 24/7 follow-the-sun organization
- Drives continuous improvement and increases efficiency through standardization and automation
- Work independently and with management on highly visible, complex projects
- Contributes to major, global scale incidents by conducting root cause analysis and writing summaries or reports
- Maintain excellent collaboration with internal and external key stakeholders
- Establish and perform knowledge management activities, such as lessons learned, knowledge-based articles, and trainings
- Designs, implement and verify new detection mechanisms
- Conduct investigations and forensics on internal and cloud assets
- Support other SAP Concur teams in their day-to-day business activities
**EDUCATION AND QUALIFICATIONS / SKILLS AND COMPETENCIES**
Bachelor/ master's degree in information systems engineering, computer science, cybersecurity, software development or equivalent similar education
One or more security certifications (e.g. Security+, GCIA, GCIH, CISSP)
**Required skills**
- Experience in the area of creation and maintenance of detection use cases, designing mitigation playbooks, and security event monitoring
- Experience managing cases with enterprise SIEM or Incident Management systems (Information Security, Information Systems, Engineering or related work experience)
- Good knowledge of one or more of the following: Windows/AD file system, registry functions and memory artifacts, Unix/Linux file systems and memory artifacts, Mac file systems and memory artifacts, Cybersecurity automation, Security Information and Event Management (SIEM) tools (Splunk, Fortinet, Skybox, Gigamon, Akamai, Thales, Nexpose, Tenable, Tanium, Sophos, clamAV, Device42)
- Knowledge of Advanced Persistent Threat (APT) actors; their tools, techniques, and procedures (TTPs),
- Ability to demonstrate analytical expertise, close attention to detail, excellent critical thinking, logic, solution orientation, and to learn and adapt quickly
- Able to explain complex issues in layman terms
- High quality awareness and process-oriented thinking and acting
- Willingness and ability to work in a security function
- Ability to work as an individual contributor and closely collaborate across, organizations, teams and cultures
- Fluent Business English is a must
**Preferred skills**
- Experience in network security and network systems including LANs/WANs/VPNs/Firewalls and IDS's
- Experience with one or more scripting languages (Powershell, Python, Bash, etc.)
- Experience in Data Loss Prevention (DLP)
- International working experience
**WORK EXPERIENCE**
Solid professional experience; experience in high-tech industry closely related to security operations as well as experience in critical incident management
**We are SAP**
**Our inclusion promise**
SAP's culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone - regardless of background - feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better and more equitable world.
EOE AA M/F/Vet/Disability:
Qualified applicants will receive conside
-
Rust Engineering Lead
4 semanas atrás
Porto Alegre, Rio Grande do Sul, Brasil Canonical Tempo inteiroRust Engineering Lead - Linux and Open Source Join or sign in to find your next job Join to apply for the Rust Engineering Lead - Linux and Open Source role at Canonical Rust Engineering Lead - Linux and Open Source 14 hours ago Be among the first 25 applicants Join to apply for the Rust Engineering Lead - Linux and Open Source role at Canonical Get...
-
Lead Golang Software Engineer, Commercial Systems
4 semanas atrás
Porto Alegre, Rio Grande do Sul, Brasil Canonical Tempo inteiroLead Golang Software Engineer, Commercial Systems Join or sign in to find your next job Join to apply for the Lead Golang Software Engineer, Commercial Systems role at Canonical Lead Golang Software Engineer, Commercial Systems 3 days ago Be among the first 25 applicants Join to apply for the Lead Golang Software Engineer, Commercial Systems role at...
-
Application Consultant for Security Services
4 semanas atrás
Porto Alegre, Rio Grande do Sul, Brasil SAP Tempo inteiro**We help the world run better****#SAPECSCareers****PURPOSE AND OBJECTIVES**A key service for customers during operations phase at SAP is the SAP ECS - Cloud Application Services (SAP CAS). The mission of SAP CAS is to maximize customer success in the run phase of SAP software lifecycle by taking over responsibility for smooth end to end operations and...
-
IT Security Engineer
1 semana atrás
Porto Alegre, Rio Grande do Sul, Brasil Rocket Tempo inteiro R$60.000 - R$120.000 por anoJob Title: IT Security EngineerLevel: Junior | Mid LevelWorking Hours: Full Time(40h/Week)Contract: ContractorLocation: LATAMYour TeamYou will report to our Head of Security and join the Security team. On TheOrg you can view the complete structure of our organisation, including information about every team member, hiring managers and the size of each...
-
Engineering Program Director
3 semanas atrás
Porto Alegre, Rio Grande do Sul, Brasil Jones Lang LaSalle Tempo inteiroOverview JLL empowers you to shape a brighter way. Our people at JLL and JLL Technologies are shaping the future of real estate by combining world class services, advisory and technology for our clients. We are committed to hiring the best, most talented people and empowering them to thrive, grow meaningful careers and to find a place where they belong....
-
Senior Information Security Analyst
4 semanas atrás
Porto Alegre, Rio Grande do Sul, Brasil Kto Group Tempo inteiroWelcome to KTO Group, where innovation drives excitement in iGaming. Founded in 2018 by Andreas Bardun, we're transforming online gaming with a focus on transparency and player satisfaction.AtKTO.com, we blend the thrill of sports betting with online casino entertainment, tailored to local markets and powered by our proprietary platform for a seamless,...
-
Application Security Engineer
4 semanas atrás
Porto Alegre, Rio Grande do Sul, Brasil Varsity Tutors, a Nerdy Company Tempo inteiroOverview We are seeking an experienced Application Security Engineer to serve as a trusted partner to our software development teams. This role focuses on making our product secure by design—embedding security into how software is architected, written, deployed, and maintained. Unlike infrastructure security roles, this position centers on...
-
Senior Network Security Engineer
1 dia atrás
Porto Alegre, Rio Grande do Sul, Brasil WEX Tempo inteiro R$120.000 - R$360.000 por anoAbout the Team/RoleWe're the Global Information Security Team at WEX, responsible for implementing and operating security technologies and processes throughout WEX. We partner closely with internal teams and customers to assure WEX operates in a secure and compliant manner. Our team holds itself to a high-standard and we collaborate closely with one another...
-
Application Security Engineer
4 semanas atrás
Porto Alegre, Rio Grande do Sul, Brasil Varsity Tutors LLC Tempo inteiroOverview We are seeking an experienced Application Security Engineer to serve as a trusted partner to our software development teams. This role focuses on making our product secure by design—embedding security into how software is architected, written, deployed, and maintained. Unlike infrastructure security roles, this position centers on...
-
Information Security Engineer
4 semanas atrás
Porto Alegre, Rio Grande do Sul, Brasil WEX Tempo inteiroJoin to apply for the Information Security Engineer - IAM role at WEXJoin to apply for the Information Security Engineer - IAM role at WEXAbout The Team/RoleWe are the WEX Identity Protection Team, tasked with deploying and managing security IAM technologies and procedures across the enterprise. We work closely with internal teams and clients to ensure the...