

DevSecOps SAP Engineer
β - Featured Role | Apply direct with Data Freelance Hub
This role is for a DevSecOps SAP Engineer, offering a 12+ month remote contract (PST). Candidates should have 5+ years in IT security, 3+ years in SAP security, and familiarity with DevSecOps practices. Relevant certifications are a plus.
π - Country
United States
π± - Currency
$ USD
-
π° - Day rate
-
ποΈ - Date discovered
June 30, 2025
π - Project duration
More than 6 months
-
ποΈ - Location type
Remote
-
π - Contract type
Unknown
-
π - Security clearance
Unknown
-
π - Location detailed
United States
-
π§ - Skills detailed
#Deployment #Docker #Kubernetes #Ansible #Computer Science #"ETL (Extract #Transform #Load)" #Jenkins #GCP (Google Cloud Platform) #Monitoring #Cloud #Automation #Python #SAML (Security Assertion Markup Language) #Compliance #Scripting #GIT #SAP Hana #AWS (Amazon Web Services) #Cybersecurity #IAM (Identity and Access Management) #DevSecOps #Azure #Security #Kerberos #Documentation #SAP
Role description
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript
DevSecOps SAP Engineer (GC and USC)
Location: Remote (PST Time)
Contract Duration: 12+ Months
We are seeking an experienced and proactive DevSecOps SAP Engineer to join our Cybersecurity Application Platform Security Team. This role combines expertise in SAP security with a strong foundation in DevSecOps practices to ensure the βsecure by designβ, βsecure by defaultβ principles throughout development, deployment, and operation of SAP systems. The ideal candidate will have hands-on experience with Cybersecurity platforms, with a deep understanding of SAP. This position plays a critical role in assisting large IT transformation initiative β Propel, to move SAP platform to cloud; operate securely. maintaining compliance, enhancing security postures, and supporting our SAP ecosystem.
Key Responsibilities:
β’ Work with SAP RISE integration partners to bake-in security controls part of design, implementation, across SAP platforms, including SAP S/4HANA, BusinessObjects (BOBJ), Business Warehouse (BW), Governance, Risk, and Compliance (GRC), and NetWeaver Gateway.
β’ Integrate security best practices into CI/CD pipelines to ensure secure code deployment and infrastructure-as-code for SAP environments.
β’ Collaborate with development, operations, and peer cybersecurity teams to enforce the shared responsibility model for cloud and on-premises SAP deployments.
β’ Ensure compliance with SOX regulations and other industry standards (NERC CIP where applicable) by implementing and monitoring SAP security policies and procedures.
β’ Ensure IAM specific controls like user access management, role design, and segregation of duties (SoD) analysis are implemented according to PG&E standards and best practices.
β’ Implement and support Single Sign-On (SSO) solutions for SAP systems to enhance authentication security.
β’ Conduct security assessments, vulnerability scans, and penetration testing on SAP applications and infrastructure.
β’ Be an integral part of SAP team and provide expertise in securing SAP RISE deployments, leveraging cloud-native security tools and practices (experience with SAP RISE is a plus).
β’ Develop and maintain documentation for security processes, security architecture patterns relevant to the emerging SAP environments.
β’ Stay updated on emerging threats, vulnerabilities, and security trends related to SAP and DevSecOps practices.
β’ Promote cybersecurity awareness among developers and stakeholders.
Qualifications:
β’ Bachelorβs degree in computer science, Information Security, or a related field (or equivalent experience).
β’ 5+ years of experience in IT security, with at least 3 years focused on SAP security engineering.
β’ Proven expertise in SAP platforms, including SAP HANA, BOBJ, BW, GRC, and NetWeaver Gateway.
β’ Strong understanding of DevSecOps principles, including CI/CD pipeline security and automation tools (e.g., Jenkins, Git, Ansible, or similar).
β’ Familiarity with the shared responsibility model in cloud environments (AWS, Azure, GCP) and hybrid SAP deployments.
β’ Familiarity with SAP Cloud ALM (Application Lifecycle Management), clean core a plus.
β’ Experience with SOX compliance and auditing processes in SAP environments.
β’ Hands-on knowledge of SAP security modules, role administration, and SSO implementation (e.g., SAML, OAuth, Kerberos).
β’ Experience with SAP RISE or other SAP cloud transformation initiatives is highly desirable.
β’ Relevant certifications such as SAP Certified Technology Associate β Security, CISSP, CISM, or DevSecOps-specific credentials are a plus.
β’ Strong analytical and problem-solving skills with excellent communication and teamwork abilities.
Preferred Technical Skills:
β’ Experience with scripting languages (e.g., Python, PowerShell) for automation of security tasks.
β’ Knowledge of container security (Docker, Kubernetes) in SAP environments.
β’ Familiarity with secure software development lifecycle (SDLC) practices.
β’ Understanding of identity and access management (IAM) tools integrated with SAP systems.
Soft Skills
β’ Excellent Communication Skills: Ability to clearly articulate security concepts to diverse audiences, including engineers, product managers, and executives.
β’ Collaboration & Influence: Proven ability to work cross-functionally with teams to align on security priorities and influence roadmaps.
The ideal candidate will be passionate about security, have a proactive mindset, and be able to balance security requirements with business needs. They should be comfortable working in a fast-paced environment and be able to adapt to evolving security threats and technologies