Praca SAP Security Architect Manager (m/f/d) Warszawa, mazowieckie

Praca SAP Security Architect Manager (m/f/d) Warszawa, mazowieckie

JTI Polska profil

Jesteśmy wiodącą, międzynarodową firmą tytoniową, wywodzącą się z Grupy Japan Tobacco. Działamy w 130 krajach na świecie, zatrudniamy ponad 45 tys. osób i mamy w swoim portfolio jedne z najbardziej znanych marek, w tym Camel, LD, Winston oraz Logic dostępne na polskim rynku.

W Polsce zatrudniamy prawie 3 tys. pracowników i jesteśmy trzecim graczem w branży tytoniowej. Wkraczając na polski rynek w 2007 roku, postanowiliśmy, że na pierwszym miejscu zawsze będziemy stawiać naszych pracowników. Tworzymy kulturę opartą na współpracy, dzięki czemu w naszych zespołach panuje wyjątkowa atmosfera. Szerokie zakresy odpowiedzialności dają możliwość zdobycia nowej wiedzy i umiejętności, co przekłada się na świetną jakość działania oraz szybki rozwój naszej firmy. Stosujemy także najlepsze praktyki w zakresie rozwoju talentów, wdrażania nowo zatrudnionych osób czy możliwości szkoleniowych.

Nasze starania, by być najlepszym pracodawcą dla naszych pracowników, co roku zostają doceniane przez Top Employers Institute. Najlepszym dowodem na to jest przyznawany nam nieustannie od 2010 roku certyfikat Najlepszego Pracodawcy nie tylko w Polsce, a także w Europie (1. miejsce w rankingu w 2021 roku) oraz na świecie.

Firma: JTI Polska | SAP Security Architect Manager (m/f/d)

Miejsce: Warszawa, mazowieckie

Nr ref. 107123

Opis stanowiska

Position Purpose:

In this role, you will be designing and maintaining access model and governance related business processes based on information from stakeholders and identified needs. You will design and implement controls, manage partners/vendors, ensure stakeholders’ satisfaction, and promote an information security culture driven by risk considerations.

We are seeking an SAP Business Technology Platform (BTP) Manager with deep specialization in Security, Identity Management, and Access Governance to join our Identity and Access Governance team. The ideal candidate will be responsible for defining, implementing, and maintaining secure access models across our SAP BTP (mainly) and rest of SAP cloud landscapes, ensuring alignment with corporate compliance and SAP best practices.

You will collaborate closely with SAP Basis, IT Security, Functional (BTS) and Internal Controls teams to establish governance frameworks, role-based permissions, and integrations with SAP Cloud Identity Services.

Position:

BTP Security Architecture & Strategy:

  • Design and maintain the BTP security architecture, including subaccount structure, trust configuration, and connectivity to Identity Providers (IdPs)
  • Define and document security standards and governance models for multi-tenant SAP cloud environments
  • Implement and optimize Identity Authentication (IAS) and Identity Provisioning (IPS) services

Access & Role Management:

  • Design and maintain a sustainable BTP to facilitate maintenance of authorizations in the JTI SAP BTP landscape. (develop and maintain role-based access control (RBAC) and attribute-based access control (ABAC) model)
  • Act as interface between the different stakeholders (Business, IT, Compliance/Legal teams) to ensure alignment on the access design and the implementation plan
  • Manage SAP Cloud security parameters and access, including administrators, developers, and integration users
  • Coordinate with compliance teams to ensure adherence to SoD (Segregation of Duties) principles.
  • Look for improvement opportunities via automation of internal processes or leveraging existing system functionality
  • Manage and transfer knowledge by designing training materials, training SAP security staff and other stakeholders
  • Support integration with Identity and Access Management solutions (Identity IIQ/SailPoint preferred)

Governance & Compliance:

  • Define and implement SAP cloud security and Access Governance policies, procedures, and standards in alignment with enterprise IT security frameworks
  • Design and implement new controls ensuring SAP BTP and cloud systems remain available, transactional integrity is guaranteed, data sensitivity and confidentiality requirements are met, and risks are considered
  • Support audit activities by providing documentation, logs, and risk assessments
  • Implement security monitoring and reporting using Security Bridge, SAP Cloud ALM, Audit Logs, and Security Analytics tools

Integration & Automation:

  • Integrate SAP BTP with SAP Identity Access Governance (IAG), SAP Cloud Identity, and on-premises SAP systems (S/4HANA, BW/4HANA, etc.)
  • Automate user lifecycle management and access provisioning through APIs and scripting
  • Collaborate with DevOps teams to embed security into CI/CD pipelines

Advisory & Enablement:

  • Provide expert advice on BTP security topics to project teams and business stakeholders
  • Deliver training sessions and internal knowledge transfer on BTP access management

Wymagania

Requirements:

Technical Expertise:

  • 5+ years of experience in SAP Security and Identity Management
  • 3+ years hands-on experience with SAP BTP (Neo & Cloud Foundry environments)
  • strong understanding of SAP Cloud Identity Services (IAS, IPS) and SAP Identity Access Governance (IAG)
  • experience configuring trust relationships, OAuth2, SAML, and XSUAA authorizations
  • knowledge of BTP cockpit administration, subaccount hierarchy, and entitlement management

Preferred Skills:

  • Experience integrating SAP BTP with Azure AD or Okta, or Keycloak
  • Familiarity with SAP Cloud ALM, Security Monitoring, and Audit Log API
  • Exposure to BTP services such as CAP, BAS, Workflow Management, or Integration Suite
  • Knowledge SAP GRC Access control or Cybersecurity frameworks (ISO 27001, NIST2,…)

Soft Skills:

  • Strong communication and documentation abilities
  • Comfortable leading workshops and security design sessions
  • Analytical mindset with a proactive approach to risk management

Oferujemy

What to expect:

Expect well-being initiatives, flexible work arrangements, growth opportunities, and excellent benefits, including a unique family leave policy. For more details on local policies, speak with the Talent Advisor.  

Informacje dodatkowe

Next Steps:

After applying, if selected, please anticipate the following within 1-3 weeks of the job posting closure: Phone screening with Talent Advisor > Assessment tests > Interviews > Offer. Each step is eliminatory and may vary by role type.

Komentarze (0)