Technology Internal Control Senior Specialist (f/m/d)

We help the world run better

Our company culture is focused on helping our employees enable innovation by building breakthroughs together. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and future-focused work. We offer a highly collaborative, caring team environment with a strong focus on learning and development, recognition for your individual contributions, and a variety of benefit options for you to choose from. Apply now!

  The Technology & Security Control Senior Specialist is a critical position within the Global Risk & Assurance function at SAP (Internal Audit, Risk, & Controls). They are responsible for the independent evaluation of control designs and testing of effectiveness across widespread regulatory areas, with a keen focus on Cybersecurity & Technology compliance (frameworks such as; SOC 2, PCI DSS, ISO 27001, 27002, NIST..)  You will collaborate closely with internal stakeholders to assess and enhance SAPs control environment, supporting adherence to industry standards and regulations.


  • Review and evaluate internal controls to ensure they are designed effectively to address regulatory requirements, including SOC 2, PCI DSS, ISO 27001, 27002, NIST.
  • Develop and execute risk based testing plans to assess the effectiveness of controls and compliance with regulatory standards.
  • Identify potential control deficiencies and gaps in the control framework and recommend remediation measures.
  • Maintain accurate documentation of control assessments, testing results, and compliance evidence.
  • Prepare comprehensive reports on control assessments and testing outcomes for senior management and regulatory bodies as required.
  • Collaborate with cross-functional teams, including IT, legal, cybersecurity, and audit teams, to ensure a coordinated approach to control assessments and compliance.






  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering Technology or a related field; Master's degree or professional certification (e.g., CIA, CISA, CISM, CRISC, CISSP, CIPT, CEH, ) is preferred.
  • 5+ years of experience in; auditing, security technician, or internal control assessments and testing, preferably in a regulated environment, public accounting firm, or similar software provider.
  • Strong knowledge of regulatory frameworks and standards, including SOC 2, PCI DSS, ISO 27001, 27002, NIST.
  • Familiarity with control design principles and best practices.
  • Proficiency in control testing methodologies and tools.
  • Excellent analytical and problem-solving skills, with attention to detail.
  • Strong communication and interpersonal skills to collaborate effectively with stakeholders.
  • Ability to work independently and manage multiple projects simultaneously.
  • Adaptability to a dynamic and fast-paced environment.
  • Desire to work as part of a global team to achieve objectives.

Global Risk & Assurance Services at SAP offers assurance and safeguarding, delivering insights on risks and process enhancements to empower informed, fact-based business decisions.

Our purpose is to ensure transparency and assurance to SAP's stakeholders about the company's financial, strategic, and operational integrity, affirming its stature as a resilient, sustainable, and excellently managed enterprise. We achieve this through disciplined, systematic approaches, contributing significantly to the enhancement and optimization of SAP's operations.

We build breakthroughs together

SAP innovations help more than 400,000 customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evolved to become a market leader in end-to-end business application software and related services for database, analytics, intelligent technologies, and experience management. As a cloud company with 200 million users and more than 100,000 employees worldwide, we are purpose-driven and future-focused, with a highly collaborative team ethic and commitment to personal development. Whether connecting global industries, people, or platforms, we help ensure every challenge gets the solution it deserves. At SAP, we build breakthroughs, together.

We win with inclusion

SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone – regardless of background – feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better and more equitable world.
SAP is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to the values of Equal Employment Opportunity and provide accessibility accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for employment with SAP and are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to Recruiting Operations Team:
For SAP employees: Only permanent roles are eligible for the SAP Employee Referral Program, according to the eligibility rules set in the SAP Referral Policy. Specific conditions may apply for roles in Vocational Training.

EOE AA M/F/Vet/Disability:

Qualified applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity, age, gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disability.
Successful candidates might be required to undergo a background verification with an external vendor.

Requisition ID: 388449  | Work Area: Administration  | Expected Travel: 0 - 10%  | Career Status: Professional  | Employment Type: Regular Full Time   | Additional Locations: #LI-Hybrid.

Requisition ID:  388449
Posted Date:  May 16, 2024
Work Area:  Administration
Career Status:  Professional
Employment Type:  Regular Full Time
Expected Travel:  0 - 10%

Belgrade, RS, 11070

Job alert

Job Segment: Compliance, ERP, Computer Science, Testing, Law, Legal, Technology