In this position...
We are seeking an SAP Security Specialist (GSR Level) with deep expertise in SAP Identity Access Governance (IAG) and public cloud SAP deployments. In this role, you will be responsible for designing, implementing, and maintaining robust security architectures and access controls across our SAP landscape, ensuring secure migration and operations of critical enterprise systems hosted in public cloud environments.
Ford Energy is a newly formed, wholly-owned subsidiary of Ford Motor Company dedicated to accelerating U.S. energy independence. Leveraging Ford's century of manufacturing excellence and world-class battery energy storage systems (BESS) technology, Ford Energy designs, manufactures, and services grid-scale and commercial DC battery energy storage systems (BESS). Ford Energy is uniquely positioned to capture the growing demand for reliable, US-built energy storage systems. We are not just building batteries; we are building the infrastructure for the next generation of the American grid. Why Ford Energy? At Ford Energy, you have the backing of an industrial manufacturing powerhouse with the agility of a dedicated energy startup offering industry leading technology. We offer a competitive compensation package including performance-based bonuses, Ford vehicle discounts, and the opportunity to shape the energy strategy of one of the world's most iconic brands.
What you'll do...
Key Responsibilities
- SAP Cloud Security & Governance: Design, configure, and maintain secure access controls and segregation of duties (SoD) policies using SAP Identity Access Governance (IAG) and SAP Cloud Identity Services (IAS/IPS).
- Public Cloud SAP Deployments: Partner with infrastructure and cloud engineering teams to secure SAP landscapes (such as SAP S/4HANA, BTP, and RISE with SAP) hosted on public cloud platforms.
- Identity & Access Management (IAM): Implement and optimize user provisioning, single sign-on (SSO), multi-factor authentication (MFA), and federated identity flows between SAP systems, public clouds, and enterprise identity providers (e.g., Microsoft Entra ID).
- Vulnerability & Compliance Monitoring: Conduct regular vulnerability assessments, security audits, and configuration reviews of public cloud SAP infrastructure and database layers (HANA security).
- Policy & Control Enforcement: Translate corporate cybersecurity requirements into concrete SAP security baselines, ensuring compliance with internal policies and external regulatory standards (e.g., SOC 2, ISO 27001).
- Role Design & Administration: Define, build, and audit SAP business roles, authorization objects, and emergency access management (Firefighter) procedures to maintain a least-privilege security posture.
- Incident Support & Remediation: Act as the subject matter expert for SAP-related security incidents, assisting in rapid investigation, forensic analysis, and the implementation of permanent remediation measures.
- Collaboration: Work closely with SAP functional teams, enterprise GRC analysts, cloud architecture teams, and external integration partners to ensure secure-by-design SAP deployments.
What you'll do...
Key Responsibilities
- SAP Cloud Security & Governance: Design, configure, and maintain secure access controls and segregation of duties (SoD) policies using SAP Identity Access Governance (IAG) and SAP Cloud Identity Services (IAS/IPS).
- Public Cloud SAP Deployments: Partner with infrastructure and cloud engineering teams to secure SAP landscapes (such as SAP S/4HANA, BTP, and RISE with SAP) hosted on public cloud platforms.
- Identity & Access Management (IAM): Implement and optimize user provisioning, single sign-on (SSO), multi-factor authentication (MFA), and federated identity flows between SAP systems, public clouds, and enterprise identity providers (e.g., Microsoft Entra ID).
- Vulnerability & Compliance Monitoring: Conduct regular vulnerability assessments, security audits, and configuration reviews of public cloud SAP infrastructure and database layers (HANA security).
- Policy & Control Enforcement: Translate corporate cybersecurity requirements into concrete SAP security baselines, ensuring compliance with internal policies and external regulatory standards (e.g., SOC 2, ISO 27001).
- Role Design & Administration: Define, build, and audit SAP business roles, authorization objects, and emergency access management (Firefighter) procedures to maintain a least-privilege security posture.
- Incident Support & Remediation: Act as the subject matter expert for SAP-related security incidents, assisting in rapid investigation, forensic analysis, and the implementation of permanent remediation measures.
- Collaboration: Work closely with SAP functional teams, enterprise GRC analysts, cloud architecture teams, and external integration partners to ensure secure-by-design SAP deployments.