Good understanding of SAP Basis and security concepts, such as system configuration, vulnerability and patch management, system monitoring, authorization concepts, and user maintenance.
Excellent knowledge in developing, implementing, and maintaining security assessment processes & tools to review security controls for mission-critical engineering and ERP applications. (SAP)
Strong understanding of information security management principles, SAP application security implementation methodologies, role-based access controls, distributed systems administration, and system recovery.
Conduct cybersecurity assessments and implement remedial measures on SAP Systems closely aligned with the application teams.
Conduct security assessments on internalapplications/infrastructureand deliver reports detailing assessment observations and associated recommendations for information security program development to help the client meet security and compliance standards.
Align standards, frameworks, and security with overall business and technology strategy.
Identify security design gaps in existing and proposed architectures and recommend changes or enhancements.
Partner with the SAP application and infrastructure team and collaborate to enhance/implement necessary information security controls
Review the design of new and existing functionality for security vulnerabilities and suggest best practices and improvements.
Perform proactive research to identify, categorize, and produce reports on new and existing threats.
Continuously and proactively assesses the ERP and engineering applications for cybersecurity weaknesses and prioritizes plans to enhance security controls.
Develop, monitor, and manage cybersecurity metrics for SAP.
Skills
Good experience in SAP Basis, Security, and audit areas
Knowledge of common information security management frameworks, such as ISO/IEC 27001, ITIL, and COBIT, as well as those from NIST, including 800-53 and Cybersecurity Framework