Share this Job
Information Technology

Product Security Expert

What we offer

Our company culture is focused on helping our employees enable innovation by building breakthroughs together. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and future-focused work. We offer a highly collaborative, caring team environment with a strong focus on learning and development, recognition for your individual contributions, and a variety of benefit options for you to choose from. Apply now!



This position is part of SAP’s larger global Security structure, an organization that drives the latest best practices around Cyber Threat Intelligence, Incident Response, Crisis Management, Digital Forensics and Vulnerability Management. 


For SAP Concur we are looking for a Product Security Expert to prevent, detect, and correct security flaws in Concur software. SAP Concur is a B2B business that has millions of end users, providing best in class Web based SAAS Applications. Our customers have high expectations of us that the software we deliver them is secure and that SAP Concur protects their data. SAP Concur’s application security team therefore supports security tooling, process, and governance across the secure development lifecycle.


The Application Security Team’s mission is to enable developers to deliver secure products and to evaluate the results of application security tooling. You will be focused on working with teams in Europe across several offices. The ability to travel 10% is preferred, but not required. SAP Concur has a mature, well resourced, application security team. Combine that with a very healthy work life balance that SAP supports, we’ve done an excellent job of constantly supporting engineer growth and continuous development of talent.

What is this team’s tech stack today?

As a team, Application Security has to be somewhat language agnostic as the security engineer will work with many teams across the organization, there will be exposure to: C#, Java, Go Lang, NodeJS among others, in Web environment, based on microservices, and REST APIs.


⦁    Designing and maintaining software security in an Agile and platform-oriented environment is an exciting challenge: your mission is to ensure best-in-class security and data protection for Concur and its customers while enabling fast-paced innovation on Concur SaaS and mobile solutions

⦁    Securing both older and newer web applications, rest APIs and Mobile Apps with process, tooling, and by educating developers.

⦁    Hands-on leadership and take ownership of development support for application security for Concur's SaaS-based financial services and SaaS product.

⦁    Provide subject matter expertise to the various development teams including communicating architectural decisions and mentoring other technical staff around the various development technologies and decisions.


⦁    Development background particularly building enterprise Web applications and working knowledge of securing applications in a cloud environment (mostly AWS)           

⦁    Experience in identifying security flaws in current code, ability to evaluate risk, triage and provide remediation solutions

⦁    Strong understanding of Web Application security risks, including but not limited to OWASP top 10

⦁    Proficiency with auditing object-oriented languages and script-based languages for vulnerabilities

⦁    Experience threat modeling at scale - applications and experience securing REST services

⦁    Experience translating threats and business risk to R&D teams and executive leadership and the ability to recognize and address antipatterns at scale.

⦁    Experience with Web security tooling, Static analysis (Source level scans), Dynamics scans (black box web app testing), Interactive testing (grey box testing)




We are SAP

SAP innovations help more than 400,000 customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evolved to become a market leader in end-to-end business application software and related services for database, analytics, intelligent technologies, and experience management. As a cloud company with 200 million users and more than 100,000 employees worldwide, we are purpose-driven and future-focused, with a highly collaborative team ethic and commitment to personal development. Whether connecting global industries, people, or platforms, we help ensure every challenge gets the solution it deserves. At SAP, we build breakthroughs, together.


Our inclusion promise

SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone – regardless of background – feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better and more equitable world.


SAP is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to the values of Equal Employment Opportunity and provide accessibility accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for employment with SAP and are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to Recruiting Operations Team: Americas: Careers.NorthAmerica@sap.com or Careers.LatinAmerica@sap.com, APJ: Careers.APJ@sap.com, EMEA: Careers@sap.com.


EOE AA M/F/Vet/Disability:

Qualified applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity, age, gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disability.

Successful candidates might be required to undergo a background verification with an external vendor.

 Requisition ID:292996 | Work Area: Information Technology | Expected Travel: 0 - 10% | Career Status: Professional | Employment Type: Regular Full Time  | Additional Locations: Virtual - USA

Product Security Expert

Facility:  292996
Posted Date:  Oct 24, 2021
Work Area:  Information Technology
Career Status:  Professional
Employment Type:  Regular Full Time
Expected Travel:  0 - 10%

Bellevue, WA, US, 98004

Nearest Major Market: Seattle
Nearest Secondary Market: Bellevue

Job Segment: ERP, SAP, Cloud, Java, Security, Technology