# SAP Security Engineer, Ford Energy

**Company**: Ford Energy
**Location**: Dearborn, MI
**Work arrangement**: hybrid
**Experience**: senior
**Job type**: full-time
**Category**: IT
**Industry**: Automotive

**Apply**: https://efds.fa.em5.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/67004?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_fbdfacf1-91a

## Description

We are seeking an SAP Security Specialist with deep expertise in SAP Identity Access Governance (IAG) and public cloud SAP deployments. In this role, you will design, implement, and maintain robust security architectures and access controls across our SAP landscape, ensuring secure migration and operations of critical enterprise systems hosted in public cloud environments.

## Responsibilities

- Design, configure, and maintain secure access controls and segregation of duties (SoD) policies using SAP Identity Access Governance (IAG) and SAP Cloud Identity Services (IAS/IPS).

- Partner with infrastructure and cloud engineering teams to secure SAP landscapes hosted on public cloud platforms.

- Implement and optimize user provisioning, single sign-on (SSO), multi-factor authentication (MFA), and federated identity flows between SAP systems, public clouds, and enterprise identity providers.

- Conduct regular vulnerability assessments, security audits, and configuration reviews of public cloud SAP infrastructure and database layers.

- Translate corporate cybersecurity requirements into concrete SAP security baselines, ensuring compliance with internal policies and external regulatory standards.

- Define, build, and audit SAP business roles, authorization objects, and emergency access management procedures to maintain a least-privilege security posture.

- Act as the subject matter expert for SAP-related security incidents, assisting in rapid investigation, forensic analysis, and the implementation of permanent remediation measures.

- Collaborate with SAP functional teams, enterprise GRC analysts, cloud architecture teams, and external integration partners to ensure secure-by-design SAP deployments.

## Qualifications

- Minimum of 3–5 years of dedicated experience in SAP Security, including hands-on experience with SAP GRC or SAP Identity Access Governance (IAG).

- Demonstrated experience securing SAP workloads deployed in public cloud environments, including a strong understanding of cloud infrastructure security, network security groups, and IAM policies.

- Practical experience implementing and configuring SAP Cloud Identity Services and enterprise IAM solutions.

- Deep technical knowledge of SAP security architectures, authorization objects, role design, and Segregation of Duties (SoD) analysis.

- Bachelor’s or Master’s degree in Computer Science, Information Technology, Cybersecurity, or a related technical field, or equivalent related work experience.

## Benefits

- Competitive compensation package including performance-based bonuses

- Ford vehicle discounts

- Opportunity to shape the energy strategy of one of the world's most iconic brands

## Skills

### Required
- SAP Security
- SAP Identity Access Governance (IAG)
- public cloud SAP deployments
- cloud infrastructure security
- network security groups
- IAM policies
- SAP Cloud Identity Services
- enterprise IAM solutions
- SAP security architectures
- authorization objects
- role design
- Segregation of Duties (SoD) analysis

### Nice to have
- SAP Certified Technology Associate - SAP System Security and Authorizations
- cloud-specific security certifications
- SAP Business Technology Platform (BTP) security configurations
- RISE with SAP compliance frameworks
- SAP Enterprise Threat Detection (ETD)
- integrating SAP security logs with enterprise SIEM platforms

---

Source: [Apply at efds.fa.em5.oraclecloud.com](https://efds.fa.em5.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/67004?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
