Diese Stelle teilen

Lead Cyber Threat Intelligence Analyst- Cyber Fusion Center - Cyber Defense (Senior/ Expert) (f/m/d)

Datum: 28.03.2021

Standort: Walldorf, DE, 69190

Unternehmen: SAP

Requisition ID: 257260
Work Area: Information Technology
Location: Walldorf
Expected Travel: 0 - 10%
Career Status: Berufserfahren
Employment Type: Part time or Regular Full Time


SAP started in 1972 as a team of five colleagues with a desire to do something new. Together, they changed enterprise software and reinvented how business was done. Today, as a market leader in enterprise application software, we remain true to our roots. That’s why we engineer solutions to fuel innovation, foster equality and spread opportunity for our employees and customers across borders and cultures.

SAP values the entrepreneurial spirit, fostering creativity and building lasting relationships with our employees. We know that a diverse and inclusive workforce keeps us competitive and provides opportunities for all. We believe that together we can transform industries, grow economics, lift up societies and sustain our environment. Because it’s the best-run businesses that make the world run better and improve people’s lives.

Summary & Role Information:
We are looking for a Lead Cyber Threat Intelligence Analyst (f7m/d) to join the SAP Global Security Operations Team to help defend our networks from sophisticated threats. Our Lead Cyber Threat Intelligence Analysts (f/m/d) are responsible for overseeing threat intelligence analysis in SAP CFC hubs located worldwide.  This position requires rapid identification of advanced cyber threats to SAP and responding in a coordinated fashion by leveraging actionable intelligence to inform stakeholders and mitigate the risk. This position also generates actionable intelligence reporting on cyber adversary TTPs that supports cyber threat hunting operations to detect malicious activity within SAP networks.
In this role, you will be a member of SAP’s Cyber Threat Intelligence team and work closely with your Cyber Fusion Center peers at SAP’s global headquarters in Waldorf, Germany.  You will be responsible for overseeing the day-to-day operations of cyber threat intelligence analysis in the EMEA area of operations and will work closely with your threat intelligence colleagues located worldwide. This position will require both leadership experience and the ability to serve as a CTI analyst responding to a dynamic threat landscape that is constantly evolving. A strong candidate will have demonstrated work experience not only in CTI but also working with related security teams including incident response, vulnerability management, threat hunting, and security engineering.  In addition, this role will require building intelligence sharing relationships with European security agencies to better serve the security interests of SAP. as thrive in a dynamic work environment with rapidly changing priorities. This role is an exciting opportunity to join a new team that is defending a world-class multinational corporation against some of todays most advanced and persistent cyber threats.  
Experience/ Role Requirements:
We are looking for an experienced and motivated Cyber Threat Intelligence analyst who has at least 5 years of experience working as one or a combination of the following: cyber threat target analyst, cyber threat intelligence analyst, or information security analyst.  This position requires English language proficiency (verbal and written) and the ability to conduct intelligence briefings in English and German to a diverse range of SAP stakeholders. The ideal candidate has experience in a European security agency (BND, BfV, BKA, LKA, LfV) working a cyber threat intelligence mission and can translate that experience into the commercial sector. This individual should also be a self-starter who has experience taking initiative and translating loosely defined requirements into actionable, timely, and relevant intelligence reports.
You should also have the following technical skills and experience:

  • A Bachelor’s degree in one of the following areas: Cybersecurity, Computer Science, or related field.
  • Experience with commercial SIEM and threat intelligence platforms
  • Experience engaging and managing intelligence sharing partnerships with commercial and governmental agencies
  • Knowledge of cyber threat intelligence analytic frameworks including Diamond Model, Cyber Kill Chain, and Mitre ATT&CK 
  • Experience working with CFC functional teams including incident response, security engineering, vulnerability management, and threat hunting
  • Ability to enrich and pivot on technical indicators of compromise to enumerate additional indicators
  • Operational experience in leveraging the intelligence lifecycle and its application to cyber threat analysis
  • Security Certifications (e.g. Security+, GCIA, GCIH, GCFA, GCNA, CEH, CISSP, etc.)
  • Knowledge of Advanced Persistent Threat (APT) actors and associated tools, techniques, and procedures (TTPs)
  • Work experience With European security agencies in the cyber mission space




Success is what you make it. At SAP, we help you make it your own.

A career at SAP can open many doors for you. If you’re searching for a company that’s dedicated to your ideas and individual growth, recognizes you for your unique contributions, fills you with a strong sense of purpose, and provides a fun, flexible and inclusive work environment – apply now.

To harness the power of innovation, SAP invests in the development of its diverse employees. We aspire to leverage the qualities and appreciate the unique competencies that each person brings to the company.

SAP is committed to the principles of Equal Employment Opportunity and to providing reasonable accommodations to applicants with physical and/or mental disabilities. If you are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to Recruiting Operations Team (Americas: or, APJ:, EMEA:

Successful candidates might be required to undergo a background verification with an external vendor.

Additional Locations: