
Chief Information Security Officer (CISO)
Job Description
We help the world run better
At SAP, we keep it simple: you bring your best to us, and we'll bring out the best in you. We're builders touching over 20 industries and 80% of global commerce, and we need your unique talents to help shape what's next. The work is challenging – but it matters. You'll find a place where you can be yourself, prioritize your wellbeing, and truly belong. What's in it for you? Constant learning, skill growth, great benefits, and a team that wants you to grow and succeed.
OVERVIEW
SAP secures the digital core of the world's most complex organizations. As AI-industrialized cybercrime fundamentally reshapes the threat landscape, we are strengthening an already high-performing security organization to bring our capabilities together in ways that will make us faster, smarter, and more seamlessly integrated.
We are seeking
With Cyber-threats evolving at machine speed, SAP is seeking a strategic, operationally rigorous and technology-forward Chief Information Security Officer (CISO) to lead core cybersecurity functions. The CISO will serve as the executive accountable for cyber defense, security engineering, identity protection, incident response, and operational resilience. The CISO will advance the secure adoption of AI across complex cloud environments while strengthening SAP’s protection against AI-specific threats and cloud vulnerabilities.
Under our federated governance model, the CISO operates as the executive leader accountable for SAP’s core cyber defense capabilities while maintaining close strategic alignment with dedicated enterprise leaders across Physical Security, Product Security, Cloud Compliance, Security Risk Management and Customer Assurance & Trust. This position demands an executive who can build resilient technical guardrails, advance AI-enabled and highly automated threat response, and protect enterprise assets without slowing business execution.
The role
As CISO, you will lead the capabilities that protect SAP from cyber threats, reduce exploitable exposure, govern access to critical systems and data, and strengthen the resilience of SAP's essential business services. Reporting directly to the Chief Security Officer, you will bring together deep operational expertise and sound executive judgment to protect SAP and enable the business to operate securely on a global scale.
This role carries significant external reach - you will interface regularly with customers, regulators, law enforcement, intelligence partners, and government authorities worldwide. At the forefront of your mandate: accelerating the responsible adoption of AI-driven security technologies while advancing SAP's ability to anticipate, detect, and respond to AI-enabled threats at speed and scale.
What you’ll build
You will drive the ongoing evolution and optimization of our enterprise-wide portfolio spanning:
- Global 24×7 security operations
- Cyber detection and threat defense
- Cyber incident response and crisis management
- Vulnerability and attack-surface reduction
- Identity and access management
- Enterprise security engineering, automation, and zero-trust architecture
- AI and agentic systems security, including AI-enabled cyber defense
- Business continuity, technology resilience, disaster recovery, and cyber recovery
Key Responsibilities
Global security operations and cyber defense
- Lead SAP’s global 24×7 Security Operations Center, including security monitoring, detection engineering, threat intelligence, threat hunting, investigation, containment, remediation, and operational recovery.
- Architect SAP’s machine-speed defense capabilities by driving the continued evolution of an intelligence-led, AI-enabled, and highly automated SOC capable of real-time detection, investigation, and response.
- Advance autonomous containment and remediation where appropriate, governed by defined decision criteria, technical guardrails, and human oversight.
- Establish measurable performance expectations for detection coverage, response effectiveness, service reliability, operational readiness, automation, and continuous improvement.
Incident response and threat intelligence
- Direct SAP’s global cyber-incident response capability, including crisis playbooks, escalation structures, technical coordination, executive communications, containment, remediation, and recovery.
- Lead preparedness exercises, simulations, and red-team scenarios addressing sophisticated criminal, state-sponsored, insider, cloud, supply-chain, and AI-enabled threats.
- Translate threat intelligence, incident findings, and lessons learned into measurable improvements across prevention, detection, response, remediation, and resilience.
- Maintain effective relationships with relevant customers, regulators, law enforcement, government authorities, intelligence partners, and industry stakeholders.
Enterprise security engineering, identity, and exposure management
- Define and enforce enterprise security architecture and zero-trust principles across SAP’s multi-cloud, corporate, identity, endpoint, network, infrastructure, API, and software supply-chain environments.
- Lead enterprise identity and access management, including identity governance, privileged access, authentication, authorization, lifecycle management, access assurance, and machine identities.
- Drive continuous threat-exposure management across on-premises and legacy systems, cloud platforms, SaaS environments, identities, externally accessible assets, and SAP’s enterprise AI landscape.
- Establish risk-based remediation priorities, escalation pathways, exception processes, and transparent accountability for reducing exploitable vulnerabilities, exposures, and attack paths.
AI and Agentic systems security
- Establish security controls, identity and access models, data protections, and runtime safeguards for AI models, autonomous agents, LLM pipelines, prompt and context interactions, APIs, microservices, and supporting cloud integrations.
- Advance AI-enabled detection, investigation, threat analysis, attack-path identification, and response automation to counter increasingly sophisticated and AI-accelerated threats.
- Partner with Product Security, development, architecture, and engineering leaders to address threats affecting AI models, agents, pipelines, interfaces, integrations, and runtime environments.
- Ensure AI and emerging-technology security requirements are incorporated into applicable enterprise architecture, engineering, operational, monitoring, and incident-response processes.
Continuity and resilience
- Lead SAP’s enterprise business-continuity, technology-resilience, disaster-recovery, and cyber-recovery capabilities.
- Establish critical-service and dependency mapping, recovery objectives, resilience standards, testing requirements, crisis-management integration, and executive reporting.
- Validate SAP’s ability to withstand and recover from severe cyber and operational disruption through scenario exercises, technical recovery testing, and disciplined remediation.
- Ensure incident response, business continuity, disaster recovery, and cyber recovery operate as an integrated resilience capability.
Cross-functional collaboration and governance alignment
- Align technical priorities and operational security measures with the enterprise risk tolerance and risk management framework established by the Head of Security Risk Management.
- Partner with Product Security, development and engineering leaders to integrate applicable security requirements, defensive telemetry, and operational readiness into software development and release lifecycles.
- Drive the automation of applicable Secure Software Development & Operations Lifecycle requirements while supporting development velocity and preserving Product Security’s accountability for secure product development.
- Work through SAP’s federated Business Information Security Officer community to strengthen adoption, accountability, business alignment, and consistent implementation across the enterprise.
- Partner systematically with the Head of Cloud Compliance to embed scalable and automated control requirements into security technologies and operational capabilities.
- Provide the CSO, C-suite, and Executive Board with timely, decision-oriented reporting on operational security performance, material threats, incidents, exposure, AI-related risks, and cyber resilience.
What You'll Bring
For internal candidates: A proven track record of operational excellence within SAP's security or engineering divisions, with demonstrated cross-functional influence and deep familiarity with our technical stack.
For external candidates: Proven experience as a CISO, Deputy CISO, or VP of Security in an enterprise environment, ideally spanning high-velocity cloud systems and AI/ML integrations.
Leadership & Organizational Experience
- Significant executive leadership experience within a large, complex, global technology, cloud, software, critical infrastructure, or highly regulated organization
- A proven record of directing major cyber incident responses and guiding executive stakeholders through high-pressure situations
- Experience leading global, mission-critical security operations, including a 24×7 Security Operations Center
- Experience managing large, geographically distributed organizations, senior leaders, strategic suppliers, managed services, and significant operating budgets
- Experience leading enterprise business continuity, disaster recovery, technology resilience, and cyber-recovery capabilities
Technical Expertise
- Deep knowledge of modern cyber detection and response, threat intelligence, threat hunting, digital forensics, security monitoring, zero-trust architecture, and machine-identity security
- Strong technical command in cloud security (AWS, Azure, GCP), zero-trust design, container/Kubernetes security, and API security
- Strong experience leading vulnerability, exposure, and attack-surface management programs with risk-based remediation
- Strong experience leading enterprise identity governance, privileged access management, authentication, authorization, and identity-lifecycle capabilities
- Solid understanding of AI-specific threat vectors, including prompt injection, model inversion, agent privilege escalation, and training-data poisoning
Communication & Influence
- The ability to collaborate with and influence peer executives while maintaining clear decision rights and organizational accountability
- Outstanding written and verbal communication skills, with experience engaging executive leadership, boards or board committees, customers, regulators, and external stakeholders
Qualifications
- 10 or more years of progressive experience in cybersecurity, information technology, operational resilience, or a related discipline
- A bachelor's or advanced degree in cybersecurity, computer science, engineering, business, risk management, or a related field
- Professional credentials such as CISSP, CISM, or comparable executive-level qualifications are preferred
- Fluency in English is required; proficiency in German and experience working across international environments are an advantage
Meet your team
You will join SAP’s Global Security & Cloud Compliance organization as a member of the CSO’s executive leadership team, working alongside experienced leaders in operations, cyber risk, product security, physical security, compliance, and trust.
Bring out your best
SAP innovations help more than four hundred thousand customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evolved to become a market leader in end-to-end business application software and related services for database, analytics, intelligent technologies, and experience management. As a cloud company with two hundred million users and more than one hundred thousand employees worldwide, we are purpose-driven and future-focused, with a highly collaborative team ethic and commitment to personal development. Whether connecting global industries, people, or platforms, we help ensure every challenge gets the solution it deserves. At SAP, you can bring out your best.
We win with inclusion
SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone – regardless of background – feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better world.
SAP is committed to the values of Equal Employment Opportunity and provides accessibility accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for employment with SAP and are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to Recruiting Operations Team: Careers@sap.com.
For SAP employees: Only permanent roles are eligible for the SAP Employee Referral Program, according to the eligibility rules set in the SAP Referral Policy. Specific conditions may apply for roles in Vocational Training.
Qualified applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity, gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disability, in compliance with applicable federal, state, and local legal requirements.
Compensation Range Transparency: SAP believes the value of pay transparency contributes towards an honest and supportive culture and is a significant step toward demonstrating SAP’s commitment to pay equity. SAP provides the annualized compensation range inclusive of base salary and variable incentive target for the career level applicable to the posted role. The targeted annual combined range for this position is 370,400-629,700 USD. The actual amount to be offered to the successful candidate will be within that range, dependent upon the key aspects of each case which may include education, skills, experience, scope of the role, location, etc. as determined through the selection process. Any SAP variable incentive includes a targeted dollar amount and any actual payout amount is dependent on company and personal performance. Please reference this link for a summary of SAP benefits and eligibility requirements: SAP North America Benefits.
We are ethical and compliant
Our leadership credo: Do what’s right. Make SAP better for generations to come. We believe that great leadership extends far beyond the mere pursuit of business goals. We value and foster leadership that is driven with purpose and integrity. Our leaders are role models who uphold SAP’s values and shape SAP’s culture of integrity, by demonstrating and championing ethical and compliant behavior towards all stakeholders.
AI Usage in the Recruitment Process
For information on the responsible use of AI in our recruitment process, please refer to our Guidelines for Ethical Usage of AI in the Recruiting Process.
Please note that any violation of these guidelines may result in disqualification from the hiring process.
Requisition ID: 458324 | Work Area: Software-Design and Development | Expected Travel: 0 - 30% | Career Status: Executive | Employment Type: Regular Full Time | Additional Locations: #LI-Hybrid
Other jobs you might like
Working at SAP

3 office days / week

Fully flexible hours
