Merck logo
默克药厂
SAP ERP Security Specialist APAC

SAP ERP Security Specialist APAC

发布于 42 分钟前

普通员工/个人贡献者

Bangalore, Karnataka, India
中级经验
全职员工
仅现场办公
本科
信息安全
Abap
Devsecops
Iso 27001
S/4Hana
Sap
Sap Basis
Sap Ecc
Sap Security
Siem

AI 估算 · 15k–25k

High demand for SAP security specialists; global pharma company offers competitive pay in Bangalore.

职位详情

关于这个职位

This SAP ERP Security Specialist role at Merck, based in Bangalore, is responsible for safeguarding security architecture across SAP S/4HANA and ECC landscapes. You will manage access governance, compliance, and integrate security controls into critical business processes, collaborating with cross-functional teams. The role offers exposure to cutting-edge Zero Trust and DevSecOps practices in a global pharmaceutical leader.

最低要求

Minimum Qualifications:

Minimum 2 years of experience in SAP solution consulting, with a strong track record in solution design and full-cycle product implementations.
Good knowledge of SAP system components, architecture, technical integration concepts, ABAP and API.
Experience with SAP BASIS and Unix system administration.
Deep understanding of SAP security and authorization concepts, including access control, authentication and data protection.
Hands-on experience with SAP security administration and risk management (roles/profiles, provisioning, policy maintenance, risk assessment) and relevant security/compliance standards (e.g., NIS, KRITIS, GDPR, SOX).
Proficiency with test and release management tools, ticketing systems, SAP security tools/transaction codes, and ABAP for security-related custom solutions and troubleshooting.
Cybersecurity knowledge or skills related to SAP framework: OS security, DB security, firewall concepts, SAP network zone design, network infrastructure knowledge, vulnerabilities, SAP application design security, encryption, cloud cybersecurity architecture, data privacy and integrity, data protection.
Knowledge of SAP DevSecOps: deep SAP security & architecture expertise, strong knowledge of SAP platforms and security architecture, including SAP S/4HANA, SAP NetWeaver, SAP BTP, and SAP Fiori, SAP transport management and secure configuration, SAP-specific vulnerabilities and patch management.
Integration of security into DevSecOps pipelines: automating SAP code security scans (ABAP, UI5, integrations), implementing security gates in pipelines, supporting secure transport and release management, implementing continuous monitoring and compliance controls, SAP security monitoring and logging (SIEM integration).
Compliance with standards such as ISO 27001, NIST, KRITIS, and GDPR; managing identity governance and access risk analysis.
Bachelor's degree in Business Informatics, IT technology, or a comparable field.
Several years of experience in SAP-based Authorization, BASIS, Cybersecurity, Technical integration, and Cybersecurity areas.
Understanding of SAP system profiles, authentication, patching, secure network communication, encryption, database security, infrastructure security.
Good knowledge of information security policy, cybersecurity incident response, disaster recovery, industrial policy and compliance, physical security, OS security, MFA, network architecture, vulnerability management, log and monitoring, OWASP Top 10, secure configuration.
Experience with DevOps.

工作职责

Key Accountabilities:

Process and System Responsibility:
Enterprise SAP Security Strategy & Architecture Ownership: Ensure architecture and security level meet the IT/OT Cybersecurity SOP. Support the end-to-end security architecture across SAP S/4HANA and SAP ECC landscapes. Define and govern role design standards, authorization concepts, Fiori security architecture, and cross-system integration controls. Ensure alignment with enterprise security frameworks and business process requirements.
Implement and enforce Zero Trust: Enable security principles within SAP ERP landscapes, ensuring strict identity verification, least-privilege access, and continuous authentication across SAP applications, users, and integrated systems. Learn new trends, threats, and challenges in cybersecurity, such as Zero Trust and Double Zero.
Access Governance & Compliance Management: Manage user access provisioning, modifications, and de-provisioning in line with internal policies and regulatory standards (e.g., SOX, GDPR where applicable). Perform regular access reviews, SoD analysis, and audit support to ensure ongoing compliance.
System Monitoring & Risk Management: Monitor SAP systems for security risks, vulnerabilities, and unauthorized activities. Conduct risk assessments, support remediation plans, and ensure timely resolution of security incidents related to SAP ERP platforms.
Process Ownership & Security Integration: Act as the security process owner for SAP ERP environments, embedding security controls into business processes such as Finance, Procurement, Supply Chain, and HR. Collaborate with functional teams to ensure secure configuration and change management practices.
Continuous Improvement & Stakeholder Collaboration: Drive continuous improvement of SAP security processes, including automation, cybersecurity tool optimization, and documentation updates. Provide guidance and training to business users, IT teams, and management on SAP security best practices and governance standards.
Collaboration:
Security & Governance Stewardship: Provide SAP security governance across S/4HANA and ECC platforms. Support security review boards, define policy standards, and ensure consistent enforcement of global SAP access and control frameworks. Support resolving daily incidents and tasks related to security topics.
Cross-Functional & Executive Collaboration: Partner closely with Business Process Owners, IT leadership, Internal Audit, Risk & Compliance, and external auditors to align SAP security with enterprise risk strategy. Translate technical security risks into business-impact language for executive stakeholders and steering committees.
Transformation & Change: Lead security workstreams during SAP implementations, upgrades, rollouts, and S/4HANA and ECC transformation programs. Drive organizational change by promoting secure-by-design principles, influencing stakeholders, and ensuring security requirements are embedded early in project lifecycles.
Impact and Performance Management:
Support the liaison & enablement team's results, impacting the performance of related Cybersecurity Operation teams through effective demand, capacity, and change management.
Meet key KPIs (e.g., demand throughput, lead times, change success rate, capacity utilization, compliance) and drive performance improvements.
Develop and apply policies and guidelines to enhance cybersecurity operational efficiency and process consistency in Cybersecurity Operation liaison and enablement.
Efficiently and effectively support cybersecurity tasks to meet SOP and KPI.
Complex Problem-Solving:
Analyzing skills: Analyze complex information (e.g., audit findings, security advisories, demand/capacity data, vendor input) to support sound decision-making.
Sustainable and resilient solutions: Address operational challenges across demand, security, testing, release, and lifecycle processes with sustainable solutions.

优先资格

Preferred Qualifications:

Advanced certifications in SAP Security, SAP Architecture, or Service Management technologies (e.g., SAP Certified Technology Associate).
Graduate degree in a relevant discipline (IT Technology or Computer Science).

AI 洞察

优缺点分析

优点

  • Global pharma leader with stable, long-term career prospects.
  • High demand for SAP security specialists, offering strong salary potential.
  • Exposure to modern security practices like Zero Trust and DevSecOps.
  • Opportunity to work in a diverse, multinational environment.
  • Requires working on-site in Bangalore, potentially limiting flexibility.
  • High responsibility for security compliance may involve pressure during audits or incidents.
  • Need to keep up with rapidly evolving cybersecurity threats and SAP updates.
  • Ideal for experienced SAP security professionals who enjoy deep technical work and want to grow within a global enterprise, with a passion for cybersecurity.

缺点 / 挑战

暂无明显挑战项

角色解读

  • Progress to SAP Security Architect or Cybersecurity Lead, overseeing enterprise-wide security frameworks.
  • Move into broader IT security management roles, given the intersection of SAP and cybersecurity.
  • Opportunity to lead S/4HANA transformation security workstreams, becoming a strategic advisor.
  • Own and manage SAP security architecture across S/4HANA and ECC systems, ensuring compliance with enterprise frameworks.
  • Implement Zero Trust principles, manage user access, and perform regular audits and SoD analysis.
  • Monitor SAP systems for vulnerabilities, lead risk assessments, and drive remediation.
  • Collaborate with global teams to embed security into business processes and support transformation projects.
  • Deep expertise in SAP security, authorization concepts, and technical architecture (SAP BASIS, ABAP, etc.).
  • Hands-on experience with SAP security tools, access governance, and compliance standards (SOX, GDPR, ISO 27001).
  • Knowledge of cybersecurity fundamentals: OS security, network security, encryption, SIEM, and DevSecOps practices.
  • Strong analytical and communication skills to translate technical risks for stakeholders.

申请策略

  • Research Merck's business segments and security challenges in the pharma industry.
  • Tailor your CV to align with the job description's specific keywords like Zero Trust, SoD, and SAP ECC.
  • Emphasize hands-on SAP security administration and SAP BASIS experience.
  • Highlight specific projects involving S/4HANA security, role design, and compliance (SOX, GDPR).
  • Showcase any experience with DevSecOps, SIEM integration, or Zero Trust initiatives.
  • Quantify outcomes such as reduced security incidents or improved audit results.
  • Deepen knowledge of SAP S/4HANA security architecture and Fiori security.
  • Gain certifications like SAP Certified Technology Associate - SAP System Security.

面试指南

  • Use the STAR method for behavioral questions: Situation, Task, Action, Result.
  • For technical questions, structure your answer: problem, approach, solution, and lessons learned.
  • Always link your answers to business impact and compliance requirements.
  • Describe a time you implemented SAP security controls to ensure SOX compliance.
  • How do you approach access segregation (SoD) analysis in a complex SAP landscape?
  • What are the key principles of Zero Trust and how would you apply them to SAP systems?
  • Explain how you would handle a security vulnerability discovered in a critical SAP application.
  • How do you communicate technical security risks to non-technical executives?

职位点评

64
综合评分

Global pharma leader, competitive pay, strong technical growth, but on-site in Bangalore with unclear work-life balance.

从薪资福利、成长空间、工作节奏和岗位方向综合评估,方便横向比较。

更适合这类人
This role suits professionals passionate about SAP security and eager to develop deep technical expertise in a global enterprise environment.
表现最好
成长发展
相对薄弱
工作生活
薪资福利65
成长发展72
工作生活50
使命价值70

薪资福利

65中等

The position offers stable employment with a global pharma leader, though salary specifics are not disclosed.

薪资信号未披露(AI估算:15K-25K/月)

成长发展

72中等

The role provides deep exposure to cutting-edge SAP security, Zero Trust, and DevSecOps practices, with strong skill development potential.

技术前沿主流现代技术
技术栈SAP S/4HANA、SAP ECC、SAP BTP、Fiori、ABAP、DevSecOps、Zero Trust、SIEM
业务类型cost_center

工作生活

50较低

The role requires on-site presence in Bangalore with no mention of remote work or flexible hours, typical for security-focused positions.

工作模式仅现场办公
办公地点未明确
加班情况未提及(无法判断)

使命价值

70中等

Working at Merck contributes to improving lives through healthcare and life science innovations, but the security role itself has indirect social impact.

行业发展稳定成熟行业
社会影响正向社会影响力较高
使命信号enrich people's lives
创新程度积极采用新技术
Watch Jobs