Submitting more applications increases your chances of landing a job.

Here’s how busy the average job seeker was last month:

Opportunities viewed

Applications submitted

Keep exploring and applying to maximize your chances!

Looking for employers with a proven track record of hiring women?

Click here to explore opportunities now!
We Value Your Feedback

You are invited to participate in a survey designed to help researchers understand how best to match workers to the types of jobs they are searching for

Would You Be Likely to Participate?

If selected, we will contact you via email with further instructions and details about your participation.

You will receive a $7 payout for answering the survey.


User unblocked successfully
https://bayt.page.link/2zq1rXJRRBrAcoEQA
Back to the job results

Cyber Security Design Specialist- Cloud Security

Today 2026/09/03
Other Business Support Services
Create a job alert for similar positions
Job alert turned off. You won’t receive updates for this search anymore.

Job description

We help the world run better
At SAP, we keep it simple: you bring your best to us, and we'll bring out the best in you. We're builders touching over 20 industries and 80% of global commerce, and we need your unique talents to help shape what's next. The work is challenging – but it matters. You'll find a place where you can be yourself, prioritize your wellbeing, and truly belong. What's in it for you? Constant learning, skill growth, great benefits, and a team that wants you to grow and succeed. 


What you’ll build 


Service Design & Ownership



  • Define the WAF and DDoS security service model, including scope, service tiers, and supported use cases



  • Establish standard DDoS protection levels and WAF baseline configurations aligned with SAP security standards and customer requirements



  • Define clear service boundaries, ownership, and responsibilities between architecture, operations, incident response, and platform teams



  • Act as the design authority for WAF and DDoS capabilities across hyperscalers (AWS, Azure, GCP, AliCloud)



Operational Process Definition



  • Design and document endtoend operational processes, including: 



  • Incident intake and triage



  • Zeroday and emergency WAF rule deployment



  • DDoS event escalation and customer communication



  • Exception handling and rule lifecycle management



  • Define RACI models, runbooks, and playbooks for the operations teams



  • Establish change management, testing, rollback, and approval workflows for WAF and DDoS changes



  • Ensure processes are scalable, auditable, and aligned with compliance requirements


    Standards, Architecture & Guardrails



    • Define reference architectures and security patterns for application exposure, ingress, and egress



    • Review and remediate design antipatterns (e.g., overly permissive allowlists, unmanaged custom rules)



    • Set guardrails that enable rapid response while minimizing operational and customer risk



    • Drive consistency and parity across hyperscaler implementations



    Enablement of Operations Teams



    • Enable Cloud Security Operations teams with: 



    • Clear documentation and operational guidance



    • Preapproved rule templates and emergency procedures



    • Welldefined escalation paths and decision frameworks



    • Support onboarding and upskilling of ops teams through knowledge transfer and walkthroughs



    • Act as escalation support for complex or highrisk scenarios (design and policy guidance only)



    Stakeholder & Customer Alignment



    • Work with security architecture, platform engineering, incident response, and compliance teams to align requirements



    • Translate customer security requirements into actionable service capabilities



    • Support customer conversations on WAF and DDoS posture, capabilities, and limitations



    • Provide leadershiplevel visibility into risk, coverage gaps, and service maturity




What you bring 


Required Experience & Skills



  • 5–7 years of experience in cloud security, application security, or network security



  • Strong handson background with WAF and DDoS technologies (design and configuration experience required; ops execution not required)



  • Deep understanding of: 



  • Web attack patterns and OWASP Top 10



  • Layer 7 and volumetric DDoS risks



  • Hyperscaler security controls and shared responsibility models



  • Proven experience defining security services, processes, and operating models



  • Excellent documentation, communication, and stakeholdermanagement skills



  • Ability to influence without direct authority and drive adoption across teams



Where you belong


Team: Global Cloud Operations Security



The WAF and DDoS Security Engineer will be responsible for designing, implementing, maintaining, and operating Web Application Firewall (WAF) and Distributed Denial of Service (DDoS) protection controls across multicloud environments. The role focuses on ensuring consistent security posture, rapid response to emerging threats (including zeroday events), and operational resilience across hyperscaler platforms.



Bring out your best
SAP innovations help more than four hundred thousand customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evolved to become a market leader in end-to-end business application software and related services for database, analytics, intelligent technologies, and experience management. As a cloud company with two hundred million users and more than one hundred thousand employees worldwide, we are purpose-driven and future-focused, with a highly collaborative team ethic and commitment to personal development. Whether connecting global industries, people, or platforms, we help ensure every challenge gets the solution it deserves. At SAP, you can bring out your best.  
We win with inclusion
SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone – regardless of background – feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better world.
SAP is committed to the values of Equal Employment Opportunity and provides accessibility accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for employment with SAP and are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to Recruiting Operations Team: Careers@sap.com.
For SAP employees: Only permanent roles are eligible for the
SAP Employee Referral Program, according to the eligibility rules set in the SAP Referral Policy. Specific conditions may apply for roles in Vocational Training.
Qualified applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity,  gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disability, in compliance with applicable federal, state, and local legal requirements.
Successful candidates might be required to undergo a background verification with an external vendor.


AI Usage in the Recruitment Process


For information on the responsible use of AI in our recruitment process, please refer to our Guidelines for Ethical Usage of AI in the Recruiting Process.


Please note that any violation of these guidelines may result in disqualification from the hiring process.
Requisition ID: 438038  | Work Area: Information Technology  | Expected Travel: 0 - 10%  | Career Status: Professional  | Employment Type: Regular Full Time   | Additional Locations:  #LI-Hybrid


This job post has been translated by AI and may contain minor differences or errors.

You’ve reached the maximum limit of 15 job alerts. To create a new alert, please delete an existing one first.
Job alert created for this search. You’ll receive updates when new jobs match.
Are you sure you want to unapply?

You'll no longer be considered for this role and your application will be removed from the employer's inbox.