Submitting more applications increases your chances of landing a job.
Here’s how busy the average job seeker was last month:
Opportunities viewed
Applications submitted
Keep exploring and applying to maximize your chances!
Looking for employers with a proven track record of hiring women?
Click here to explore opportunities now!You are invited to participate in a survey designed to help researchers understand how best to match workers to the types of jobs they are searching for
Would You Be Likely to Participate?
If selected, we will contact you via email with further instructions and details about your participation.
You will receive a $7 payout for answering the survey.
We help the world run better
At SAP, we keep it simple: you bring your best to us, and we'll bring out the best in you. We're builders touching over 20 industries and 80% of global commerce, and we need your unique talents to help shape what's next. The work is challenging – but it matters. You'll find a place where you can be yourself, prioritize your wellbeing, and truly belong. What's in it for you? Constant learning, skill growth, great benefits, and a team that wants you to grow and succeed.
What you’ll build
Service Design & Ownership
Define the WAF and DDoS security service model, including scope, service tiers, and supported use cases
Establish standard DDoS protection levels and WAF baseline configurations aligned with SAP security standards and customer requirements
Define clear service boundaries, ownership, and responsibilities between architecture, operations, incident response, and platform teams
Act as the design authority for WAF and DDoS capabilities across hyperscalers (AWS, Azure, GCP, AliCloud)
Operational Process Definition
Design and document end‑to‑end operational processes, including:
Incident intake and triage
Zero‑day and emergency WAF rule deployment
DDoS event escalation and customer communication
Exception handling and rule lifecycle management
Define RACI models, runbooks, and playbooks for the operations teams
Establish change management, testing, rollback, and approval workflows for WAF and DDoS changes
Ensure processes are scalable, auditable, and aligned with compliance requirements
Standards, Architecture & Guardrails
Define reference architectures and security patterns for application exposure, ingress, and egress
Review and remediate design anti‑patterns (e.g., overly permissive allow‑lists, unmanaged custom rules)
Set guardrails that enable rapid response while minimizing operational and customer risk
Drive consistency and parity across hyperscaler implementations
Enablement of Operations Teams
Enable Cloud Security Operations teams with:
Clear documentation and operational guidance
Pre‑approved rule templates and emergency procedures
Well‑defined escalation paths and decision frameworks
Support onboarding and upskilling of ops teams through knowledge transfer and walkthroughs
Act as escalation support for complex or high‑risk scenarios (design and policy guidance only)
Stakeholder & Customer Alignment
Work with security architecture, platform engineering, incident response, and compliance teams to align requirements
Translate customer security requirements into actionable service capabilities
Support customer conversations on WAF and DDoS posture, capabilities, and limitations
Provide leadership‑level visibility into risk, coverage gaps, and service maturity
What you bring
Required Experience & Skills
5–7 years of experience in cloud security, application security, or network security
Strong hands‑on background with WAF and DDoS technologies (design and configuration experience required; ops execution not required)
Deep understanding of:
Web attack patterns and OWASP Top 10
Layer 7 and volumetric DDoS risks
Hyperscaler security controls and shared responsibility models
Proven experience defining security services, processes, and operating models
Excellent documentation, communication, and stakeholder‑management skills
Ability to influence without direct authority and drive adoption across teams
Where you belong
Team: Global Cloud Operations Security
The WAF and DDoS Security Engineer will be responsible for designing, implementing, maintaining, and operating Web Application Firewall (WAF) and Distributed Denial of Service (DDoS) protection controls across multi‑cloud environments. The role focuses on ensuring consistent security posture, rapid response to emerging threats (including zero‑day events), and operational resilience across hyperscaler platforms.
Bring out your best
SAP innovations help more than four hundred thousand customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evolved to become a market leader in end-to-end business application software and related services for database, analytics, intelligent technologies, and experience management. As a cloud company with two hundred million users and more than one hundred thousand employees worldwide, we are purpose-driven and future-focused, with a highly collaborative team ethic and commitment to personal development. Whether connecting global industries, people, or platforms, we help ensure every challenge gets the solution it deserves. At SAP, you can bring out your best.
We win with inclusion
SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone – regardless of background – feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better world.
SAP is committed to the values of Equal Employment Opportunity and provides accessibility accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for employment with SAP and are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to Recruiting Operations Team: Careers@sap.com.
For SAP employees: Only permanent roles are eligible for the SAP Employee Referral Program, according to the eligibility rules set in the SAP Referral Policy. Specific conditions may apply for roles in Vocational Training.
Qualified applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity, gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disability, in compliance with applicable federal, state, and local legal requirements.
Successful candidates might be required to undergo a background verification with an external vendor.
AI Usage in the Recruitment Process
For information on the responsible use of AI in our recruitment process, please refer to our Guidelines for Ethical Usage of AI in the Recruiting Process.
Please note that any violation of these guidelines may result in disqualification from the hiring process.
Requisition ID: 438038 | Work Area: Information Technology | Expected Travel: 0 - 10% | Career Status: Professional | Employment Type: Regular Full Time | Additional Locations: #LI-Hybrid
You'll no longer be considered for this role and your application will be removed from the employer's inbox.