Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Head of SAP Security (m/f/d) image - Rise Careers
Job details

Head of SAP Security (m/f/d)

Company Description

METRO is a leading international food wholesaler which specialises in serving the needs of hotels, restaurants, and caterers (HoReCa) as well as independent merchants (Traders). Around the world, METRO has approx. 15 million customers who benefit from the wholesale company’s unique multichannel mix: customers can purchase their goods in one of the large stores in their area as well as by delivery (Food Service Distribution, FSD) – all digitally supported and connected. In parallel, METRO MARKETS is being developed as an international online marketplace for the needs of professional customers which has been growing and expanding continuously since 2019. Acting sustainably is one of the company principles of METRO which has been listed in various sustainability indices and rankings, including MSCI, Sustainalytics and CDP. METRO operates in more than 30 countries and employs over 85,000 people worldwide. In financial year 2023/24, METRO generated sales of €31 billion.

At METRO, we have set ourselves ambitious goals with our “sCore” growth strategy which is closely accompanied by our Fundamentals. These shared values provide us with rules of conduct that are binding for everyone at METRO, in all countries and companies. Our commitment to wholesale is at the forefront of our mission, and we are constantly striving to improve. With our ONE METRO spirit, everyone stands together, bringing curiosity, determination, courage, drive, commitment, and trust. Find out more about METRO at careers.metroag.de.

    Job Description

    The purpose of the Head of SAP Security is to oversee and drive the definition, implementation, and strategic direction of SAP Security across METRO. The role of SAP Security Head oversees the security framework and ensures the protection of SAP applications across METRO. This role requires strong leadership and technical expertise in SAP systems, security protocols, and risk management.

    Key Task:

    Security Strategy & Governance:

    • Develop and implement a comprehensive security strategy and governance for SAP applications in use across METRO (e.g., SAP S/4HANA, SAP ERP, SAP Fiori, etc.).
    • Engage, support and educate SAP system owners and business  process owners in different METRO entities about their roles and responsibilities and in implementing METRO requirements
    • Establish and enforce security policies, standards, and procedures for SAP systems.
    • Lead risk assessments and threat modeling of SAP applications.
    • Ensure compliance with industry regulations and security frameworks (e.g., GDPR, SOX, ISO 27001, NIST)

    Security Architecture & Risk Management:

    • Define and enforce security architecture for SAP landscapes to ensure the confidentiality, integrity, and availability of data.
    • Monitor and analyze potential vulnerabilities within SAP systems and third-party applications.
    • Lead vulnerability management initiatives for SAP applications (patching, remediation, etc.).
    • Implement and oversee access control systems, authentication protocols (e.g., SAML, Single Sign-On), and role based access control (RBAC) for SAP users.

    Auditing and Compliance:

    • Collaborate with internal and external auditors to meet compliance requirements.
    • Ensure SAP systems adhere to relevant security regulations and best practices.

    Security Tools & Technology:

    • Implement and manage security tools specific to SAP environments (e.g., SAP GRC, SAP Solution Manager, SAP Security Optimization Service).
    • Keep abreast of new security technologies and methodologies to enhance SAP security posture.

    SAP Systems Knowledge: Deep understanding of SAP applications, modules, and platforms (e.g., SAP S/4HANA, SAP ERP, SAP Fiori, SAP BW).
    Application Security: Expertise in securing applications, particularly within complex enterprise environments like SAP.
    Risk Management: Ability to assess, prioritize, and mitigate risks related to SAP applications.
    Security Standards and Compliance: Knowledge of security regulations and compliance frameworks (ISO 27001, SOC 2, NIST, GDPR).
    Security Standards and Compliance: Knowledge of security regulations and compliance frameworks (ISO 27001, SOC 2, NIST, GDPR).

    Qualifications

    • Bachelor’s degree or similar qualification in information security, Cybersecurity, Computer Science, or a related field. Master’s degree is a plus.
    • SAP Certifications (e.g., SAP Security, SAP GRC).
    • Security Certifications (e.g., CISSP, CISM, CISA, or equivalent).
    • 8+ years of experience in Information Security, with at least 5+ years in SAP security management.
    • Proven experience in leading security operations within SAP environments.
    • Experience with cloud-based SAP solutions (e.g., SAP S/4HANA on Cloud) is a plus.
    • Strong leadership skills to lead and motivate a team of SAP professionals, including developers, product owners and BAU Operations Team.
    • Effective communication with technical and non-technical stakeholders to articulate SAP Security strategies, policies, and issues.
    • Strong documentation skills for creating policies, procedures, and reports.
    • Ability to inspire and motivate the IAM team to achieve departmental and organizational goals.
    • Ability to provide clear direction, set expectations, and foster a positive work environment.

    Additional Information

    • Work-life balance: Flexible working hours with the option of mobile working in agreement with your line manager, 30 days of holidays.
    • Training: A comprehensive training offer via our own training center or externally.
    • Well-being: Health days with lots of health checks and information about your well-being, company medical care including a range of preventive services, such as flu shots, OTHEB employee assistance program. 
    • Exciting life on campus: Free gym and sports classes, Rioba coffee bar, canteen with discounted meals for employees, many campus events.
    • Discounts: discounted Jobticket as well as discounts in our wholesale stores and at many partner companies.
    • Comfort: Good transport connections, free parking spaces, JobBike. 
    • Company pension plan: You will receive a contribution to your company pension. 
    • Family driven: Three daycare centers for children on campus, support of holiday camps for children of employees.

    Average salary estimate

    $100000 / YEARLY (est.)
    min
    max
    $80000K
    $120000K

    If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

    What You Should Know About Head of SAP Security (m/f/d), METRO/MAKRO

    Are you ready to take on a pivotal role at METRO as the Head of SAP Security? Located in the vibrant heart of Düsseldorf, you'll spearhead the comprehensive SAP security strategy across our expansive organization. Here at METRO, we're not just a leading international food wholesaler; we are a community of over 85,000 people committed to innovation, sustainability, and delivering the best service to our customers. In this role, you’ll oversee security governance and ensure that our SAP applications remain secure while aligning with industry regulations such as GDPR and ISO 27001. Your expertise in SAP systems and security protocols will be invaluable as you lead risk assessments and collaborate with both internal and external auditors. You'll also implement cutting-edge security tools and manage vulnerabilities, ensuring the protection of sensitive data. Your leadership will inspire a dedicated team of SAP professionals as you engage with stakeholders across different METRO entities. With flexible working hours, opportunities for personal development, and a fantastic campus environment that promotes well-being, METRO provides the perfect platform for you to make a significant impact on our SAP security landscape.

    Frequently Asked Questions (FAQs) for Head of SAP Security (m/f/d) Role at METRO/MAKRO
    What are the key responsibilities of the Head of SAP Security at METRO?

    The Head of SAP Security at METRO is responsible for overseeing the security framework that protects SAP applications, developing a robust security strategy, leading risk assessments, and ensuring compliance with industry regulations. This role involves engaging with system owners to educate them about their security responsibilities and implementing security policies that enhance the protection of critical data.

    Join Rise to see the full answer
    What qualifications are required for the Head of SAP Security position at METRO?

    Candidates for the Head of SAP Security at METRO should possess a Bachelor’s degree in information security, Cybersecurity, Computer Science, or a related field. Furthermore, SAP certifications and several security certifications such as CISSP or CISM are essential. A minimum of 8 years in Information Security with 5 years specifically in SAP Security management is also a requirement.

    Join Rise to see the full answer
    How does METRO ensure compliance in SAP Security?

    At METRO, compliance in SAP Security is achieved through the establishment of comprehensive security policies, regular audits, and adherence to industry regulations such as GDPR and ISO 27001. The Head of SAP Security leads these initiatives, working closely with internal and external auditors to ensure that all systems meet the necessary compliance requirements.

    Join Rise to see the full answer
    What soft skills are important for the Head of SAP Security at METRO?

    In addition to technical expertise, the Head of SAP Security at METRO should have strong leadership skills to inspire and motivate a team. Effective communication abilities are crucial for articulating SAP security strategies to both technical and non-technical stakeholders, fostering a collaborative environment, and setting clear expectations for team members.

    Join Rise to see the full answer
    What benefits and opportunities does METRO offer to the Head of SAP Security?

    METRO offers a range of benefits for the Head of SAP Security, including flexible working hours, opportunities for continuous learning and training, access to wellness programs, and a vibrant campus environment. Additional perks include health checks, discounted employee meals, and a company pension plan, creating a supportive environment for personal and professional growth.

    Join Rise to see the full answer
    Common Interview Questions for Head of SAP Security (m/f/d)
    Can you describe your approach to developing an SAP Security strategy?

    When developing an SAP Security strategy, I focus on aligning the strategy with the organization's overall objectives, conducting risk assessments to identify vulnerabilities within existing systems, and engaging with key stakeholders to understand specific security requirements. Continuous monitoring and adjustments based on industry trends and compliance regulations are also crucial.

    Join Rise to see the full answer
    What experience do you have with security compliance frameworks?

    I have extensive experience with compliance frameworks such as ISO 27001, GDPR, and SOX, which have guided my approach to ensuring that SAP systems adhere to security best practices. I believe in integrating compliance into the security culture of the organization, so all stakeholders are aware and involved in maintaining compliance.

    Join Rise to see the full answer
    How do you handle risk assessment and threat modeling for SAP applications?

    In my past roles, I have conducted comprehensive risk assessments by identifying potential threats and vulnerabilities. This includes analyzing security controls in place and simulating various attack scenarios to evaluate response strategies. Threat modeling helps prioritize risks and develop mitigation strategies appropriately.

    Join Rise to see the full answer
    What tools have you implemented to enhance SAP security?

    I have implemented various security tools tailored for SAP environments, including SAP GRC and SAP Security Optimization Service. I also keep abreast of new technologies to ensure our security posture is strengthened against emerging threats.

    Join Rise to see the full answer
    How do you ensure effective communication on SAP security issues with non-technical stakeholders?

    Effective communication begins with understanding the audience. I tailor my explanations by using simple language and relatable examples, focusing on how security issues impact business operations. Regular briefings and updates are also part of fostering continuous engagement with stakeholders.

    Join Rise to see the full answer
    Describe your experience managing a team in SAP security.

    Managing a team in SAP security involves not just coordinating tasks but also inspiring team members. I prioritize one-on-one meetings to understand their individual strengths and challenges, aligning their goals with organizational objectives while fostering a culture of collaboration and trust.

    Join Rise to see the full answer
    How do you stay updated with the latest trends in SAP Security?

    I stay updated with the latest trends in SAP Security by attending industry conferences, participating in webinars, and leveraging professional networks. Continuous learning is essential, and I regularly review security publications and industry blogs to incorporate new practices into our security strategy.

    Join Rise to see the full answer
    Can you discuss a challenging security incident you managed in the past?

    In a previous role, we experienced a data breach due to unpatched vulnerabilities. I led the incident response team to quickly assess the situation, implemented immediate containment measures, communicated transparently with stakeholders, and formulated a long-term plan to strengthen our security posture.

    Join Rise to see the full answer
    What is your experience with vulnerability management in SAP systems?

    I have led numerous vulnerability management initiatives, including prioritizing patch management for critical SAP applications, conducting regular system audits, and employing automated tools to identify and remediate vulnerabilities swiftly. Developing a proactive strategy for handling vulnerabilities is key to minimizing risks.

    Join Rise to see the full answer
    How do you approach the integration of SAP security with broader organizational security policies?

    Integrating SAP security with broader organizational policies involves collaboration with various teams to ensure alignment and compliance. I advocate for cross-departmental communication to synchronize security practices, share insights, and maintain a cohesive security framework throughout the organization.

    Join Rise to see the full answer
    Similar Jobs
    Photo of the Rise User
    METRO/MAKRO Remote Güneşli, Koçman Cd., 34100 Bağcılar/İstanbul, Türkiye
    Posted 10 days ago

    Join METRO Türkiye's METRO Potentials Programme and embark on a transformative 18-month journey towards leadership in the wholesale industry.

    Photo of the Rise User
    METRO/MAKRO Remote Plac Brama Portowa 1, 70-225 Szczecin, Poland
    Posted 11 days ago

    Join METRO Global Solution Center as an Internal Control Finance Specialist to shape impactful accounting solutions.

    Photo of the Rise User

    Join CI&T as a Salesforce Marketing Cloud Engineer to create and manage innovative marketing campaigns from the comfort of your home.

    Photo of the Rise User
    ServiceNow Hybrid 4810 Eastgate Mall, San Diego, California, United States
    Posted 6 days ago
    Inclusive & Diverse
    Mission Driven
    Rise from Within
    Diversity of Opinions
    Work/Life Harmony
    Empathetic
    Feedback Forward
    Take Risks
    Collaboration over Competition
    Medical Insurance
    Dental Insurance
    Vision Insurance
    Mental Health Resources
    Life insurance
    Disability Insurance
    Health Savings Account (HSA)
    Flexible Spending Account (FSA)
    Conferences Stipend
    Paid Time-Off
    Maternity Leave
    Equity

    Lead a dedicated team of SRE engineers at ServiceNow to enhance the reliability of critical enterprise platforms for federal clients.

    Photo of the Rise User
    Posted 10 days ago

    Join Highspring as a Senior Epic Analyst to manage and enhance Epic applications for leading healthcare organizations.

    Photo of the Rise User
    Zeon Chemicals Hybrid US, Jefferson County, KY; Kentucky, Louisville, KY
    Posted 3 days ago

    Join Zeon Chemicals as a Business Liaison to enhance SAP functionalities and drive business improvements.

    Seeking a visionary Chief Technology Officer with extensive experience in the federal sector to guide our technology initiatives at LMI.

    Photo of the Rise User

    Join UChicago Medicine as an IAM Analyst to enhance security and optimize systems in a hybrid work environment.

    Photo of the Rise User
    Posted 6 days ago

    Join CyberArk as a GRC Compliance Expert to drive compliance initiatives and support customer security assessments in a hybrid work environment.

    Photo of the Rise User

    Join the University of Maryland Medical System as an Application System Analyst II to enhance healthcare technology solutions.

    Metro, headquartered in Wilkes-Barre, Pennsylvania, and established in 1929, is a manufacturing company specializing in storage and transport products for the foodservice, commercial products, and healthcare industries.

    39 jobs
    MATCH
    Calculating your matching score...
    FUNDING
    SENIORITY LEVEL REQUIREMENT
    TEAM SIZE
    EMPLOYMENT TYPE
    Full-time, hybrid
    DATE POSTED
    April 18, 2025

    Subscribe to Rise newsletter

    Risa star 🔮 Hi, I'm Risa! Your AI
    Career Copilot
    Want to see a list of jobs tailored to
    you, just ask me below!
    LATEST ACTIVITY
    Photo of the Rise User
    Someone from OH, Columbus just viewed Support Associate-7 at Tory Burch
    Photo of the Rise User
    Someone from OH, Columbus just viewed Project Manager at Treering
    Photo of the Rise User
    Someone from OH, Columbus just viewed Product Manager, Assessment Student Experience at Ellevation
    Photo of the Rise User
    Someone from OH, Hamilton just viewed Team Member Travel Coordinator at Allegiant
    Photo of the Rise User
    Someone from OH, Kent just viewed Senior Director, Program at Teaching Lab
    Photo of the Rise User
    Someone from OH, Toledo just viewed IT Telecom Administrator at Anduril Industries
    Photo of the Rise User
    Someone from OH, Kent just viewed Director, Strategic Partnerships at Teaching Lab
    N
    8 people applied to SAP BO Admin at NXTGIG
    G
    Someone from OH, Cincinnati just viewed Operations Lead - AML Refresh Ops (Global Banking) at GHR
    Photo of the Rise User
    Someone from OH, Akron just viewed Data Scientist II at Kaiser Permanente
    Photo of the Rise User
    Someone from OH, Eastlake just viewed Summer Intern at Gooch & Housego
    I
    Someone from OH, Perrysburg just viewed CNC Manufacturing Technician at Innovance
    Photo of the Rise User
    82 people applied to Security Analyst Jr at DEUNA
    Photo of the Rise User
    78 people applied to Cybersecurity Intern at Dewberry
    Photo of the Rise User
    Someone from OH, Cincinnati just viewed Senior Lifecycle Marketing Manager at SoFi
    Photo of the Rise User
    Someone from OH, Cincinnati just viewed Lifecycle Marketing Manager at Caribou
    Photo of the Rise User
    Someone from OH, Cincinnati just viewed Senior Marketing Manager at Ocorian
    Photo of the Rise User
    Someone from OH, Cincinnati just viewed Growth Marketing Manager at Credit Genie
    Photo of the Rise User
    Someone from OH, Cincinnati just viewed Director of Product Marketing - AAA Campaigns at PrizePicks
    Photo of the Rise User
    Someone from OH, Cincinnati just viewed Digital Marketing Analyst, Digital Properties at Darden