🎁 Before you apply, rehearse this interview. Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card. I want my training →
We help the world run better At SAP, we keep it simple: you bring your best to us, and we'll bring out the best in you. We're builders touching over 20 industries and 80% of global commerce, and we need your unique talents to help shape what's next. The work is challenging – but it matters. You'll find a place where you can be yourself, prioritize your wellbeing, and truly belong. What's in it for you? Constant learning, skill growth, great benefits, and a team that wants you to grow and succeed. OVERVIEW SAP secures the digital core of the world's most complex organizations. As AI-industrialized cybercrime fundamentally reshapes the threat landscape, we are strengthening an already high-performing security organization to bring our capabilities together in ways that will make us faster, smarter, and more seamlessly integrated. We are seeking With Cyber-threats evolving at machine speed, SAP is seeking a strategic, operationally rigorous and technology-forward Chief Information Security Officer (CISO) to lead core cybersecurity functions. The CISO will serve as the executive accountable for cyber defense, security engineering, identity protection, incident response, and operational resilience. The CISO will advance the secure adoption of AI across complex cloud environments while strengthening SAP’s protection against AI-specific threats and cloud vulnerabilities. Under our federated governance model, the CISO operates as the executive leader accountable for SAP’s core cyber defense capabilities while maintaining close strategic alignment with dedicated enterprise leaders across Physical Security, Product Security, Cloud Compliance, Security Risk Management and Customer Assurance & Trust. This position demands an executive who can build resilient technical guardrails, advance AI-enabled and highly automated threat response, and protect enterprise assets without slowing business execution. The role As CISO, you will lead the capabilities that protect SAP from cyber threats, reduce exploitable exposure, govern access to critical systems and data, and strengthen the resilience of SAP's essential business services. Reporting directly to the Chief Security Officer, you will bring together deep operational expertise and sound executive judgment to protect SAP and enable the business to operate securely on a global scale. This role carries significant external reach - you will interface regularly with customers, regulators, law enforcement, intelligence partners, and government authorities worldwide. At the forefront of your mandate: accelerating the responsible adoption of AI-driven security technologies while advancing SAP's ability to anticipate, detect, and respond to AI-enabled threats at speed and scale. What you’ll build You will drive the ongoing evolution and optimization of our enterprise-wide portfolio spanning: Global 24×7 security operations Cyber detection and threat defense Cyber incident response and crisis management Vulnerability and attack-surface reduction Identity and access management Enterprise security engineering, automation, and zero-trust architecture AI and agentic systems security, including AI-enabled cyber defense Business continuity, technology resilience, disaster recovery, and cyber recovery Key Responsibilities Global security operations and cyber defense Lead SAP’s global 24×7 Security Operations Center, including security monitoring, detection engineering, threat intelligence, threat hunting, investigation, containment, remediation, and operational recovery. Architect SAP’s machine-speed defense capabilities by driving the continued evolution of an intelligence-led, AI-enabled, and highly automated SOC capable of real-time detection, investigation, and response. Advance autonomous containment and remediation where appropriate, governed by defined decision criteria, technical guardrails, and human oversight. Establish measurable performance expectations for detection coverage, response effectiveness, service reliability, operational readiness, automation, and continuous improvement. Incident response and threat intelligence Direct SAP’s global cyber-incident response capability, including crisis playbooks, escalation structures, technical coordination, executive communications, containment, remediation, and recovery. Lead preparedness exercises, simulations, and red-team scenarios addressing sophisticated criminal, state-sponsored, insider, cloud, supply-chain, and AI-enabled threats. Translate threat intelligence, incident findings, and lessons learned into measurable improvements across prevention, detection, response, remediation, and resilience. Maintain effective relationships with relevant customers, regulators, law enforcement, government authorities, intelligence partners, and industry stakeholders. Enterprise security engineering, identity, and exposure management Define and enforce enterprise security architecture and zero-trust principles across SAP’s multi-cloud, corporate, identity, endpoint, network, infrastructure, API, and software supply-chain environments. Lead enterprise identity and access management, including identity governance, privileged access, authentication, authorization, lifecycle management, access assurance, and machine identities. Drive continuous threat-exposure management across on-premises and legacy systems, cloud platforms, SaaS environments, identities, externally accessible assets, and SAP’s enterprise AI landscape. Establish risk-based remediation priorities, escalation pathways, exception processes, and transparent accountability for reducing exploitable vulnerabilities, exposures, and attack paths. AI and Agentic systems security Establish security controls, identity and access models, data protections, and runtime safeguards for AI models, autonomous agents, LLM pipelines, prompt and context interactions, APIs, microservices, and supporting cloud integrations. Advance AI-enabled detection, investigation, threat analysis, attack-path identification, and response automation to counter increasingly sophisticated and AI-accelerated threats. Partner with Product Security, development, architecture, and engineering leaders to address threats affecting AI models, agents, pipelines, interfaces, integrations, and runtime environments. Ensure AI and emerging-technology security requirements are incorporated into applicable enterprise architecture, engineering, operational, monitoring, and incident-response processes. Continuity and resilience Lead SAP’s enterprise business-continuity, technology-resilience, disaster-recovery, and cyber-recovery capabilities. Establish critical-service and dependency mapping, recovery objectives, resilience standards, testing requirements, crisis-management integration, and executive reporting. Validate SAP’s ability to withstand and recover from severe cyber and operational disruption through scenario exercises, technical recovery testing, and disciplined remediation. Ensure incident response, business continuity, disaster recovery, and cyber recovery operate as an integrated resilience capability. Cross-functional collaboration and governance alignment Align technical priorities and operational security measures with the enterprise risk tolerance and risk management framework established by the Head of Security Risk Management. Partner with Product Security, development and engineering leaders to integrate applicable security requirements, defensive telemetry, and operational readiness into software development and release lifecycles. Drive the automation of applicable Secure Software Development & Operations Lifecycle requirements while supporting development velocity and preserving Prod