SAP
- Location:
- Sofia (1407) – Bulgaria
- Salary:
- Competitive
- Type:
- Permanent
- Main Industry:
- Search Aerospace Jobs
- Other Industries & Skills:
- Engineering, Finance, Banking & Insurance, Government & Public Sector, Information Technology, Legal, Management & Executive
- Advertiser:
- SAP
- Job ID:
- 132761012
- Posted On:
- 11 March 2026
We help the world run better
At SAP, we keep it simple: you bring your best to us, and we’ll bring out the best in you. We’re builders touching over 20 industries and 80% of global commerce, and we need your unique talents to help shape what’s next. The work is challenging – but it matters. You’ll find a place where you can be yourself, prioritize your wellbeing, and truly belong. What’s in it for you? Constant learning, skill growth, great benefits, and a team that wants you to grow and succeed.
The SAP Signavio Security, Compliance and Governance team is looking for a motivated Information Security Compliance Senior Specialist to engage in activities related to the SAP Signavio Information Security Management System, and drive implementation and design of compliance controls for the SAP Signavio cloud application portfolio.
This position puts particular focus on Sovereign Cloud / Cloud in Country certifications such as FedRAMP, DESC and Kingdom of Saudi Arabia CST approval, and on control ownership for selected cross-engineering controls.
What You’ll Do
-Work together with colleagues in development, governance and security functions.
-Organize workshops and trainings for control owners and security champions to better understand requirements and best practices.
-Lead and manage compliance certification efforts for Sovereign Cloud and Cloud in Country environments for Signavio applications, including frameworks like DESC, FedRAMP, or equivalent national standards.
-Translate complex regulatory and government compliance requirements into actionable technical tasks and policy updates.
-Stay current with global and local regulations related to data sovereignty, privacy, and government cloud security to ensure proactive compliance.
-Collaborate with certification bodies and internal certification intermediaries.
-Engage as (deputy) control owner for selected cross-engineering controls that are owned by the Signavio Security, Compliance and Governance unit.
-Oversee the resolution of CAPA items.
-Coordinate certification projects and small networks of functional colleagues for successfully obtaining certifications.
-Engange in Audit sessions together with internal and external auditors.
What You Bring
-Bachelor’s degree in information technology, Information Security or related Science, Technology, Engineering, and Mathematics (STEM) disciplines.
-7+ years in Information Security, with at least 4 years focus on GRC (Governance, Risk, and Compliance), IT Audit, or a similar compliance-related role.
-Proven experience leading certification or attestation projects for at least one major information security framework (e.g., ISO 27001, SOC 2, C5).
-Deep understanding of GRC assessment methodologies, control design, and the audit lifecycle.
-Excellent written and verbal communication skills in English, with the ability to articulate complex technical and compliance concepts to diverse audiences (from engineers to executives).
-Experience with Jira.
-You’re an open-minded team player.
-Fluent spoken and written English communication skills.
Beneficial skills
-Experience with SAP Signavio application portfolio or SAP BTP
-Experience in BCM / DR topics
-Direct, hands-on experience with government-specific cloud compliance frameworks such as FedRAMP (US), DESC (UAE), IRAP (Australia), or similar national programs.
-Experience with NIST standards, particularly the NIST Risk Management Framework (RMF) and controls defined in NIST SP 800-53.
-Industry recognized professional certification such as CISSP, CISA, Lead Auditor or SANS
-Familiarity with scripting languages (e.g., Python, PowerShell) for automating compliance tasks and evidence gathering
-Spoken and written German communication skills
Meet your team
SAP Signavio is the owner of SAP’s process management and analytics product portfolio, and we are the responsible Security, Compliance and Governance team. The team covers almost every aspect of the aforementioned topics for SAP Signavio products from three locations, Berlin, Walldorf and Sofia. Taking a risk-based approach to security, compliance and governance, we support thousands of colleagues and customers within and outside of SAP Signavio. We team up with others in SAP (e.g., SAP Global Security and Cloud Compliance, SAP DPP, SAP BTP) to identify, implement, and operate technically effective and trade-off efficient security, compliance and governance solutions.
This position can be filled as part time position (-75%).
Bring out your best
SAP innovations help more than four hundred thousand customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evolved to become a market leader in end-to-end business application software and related services for database, analytics, intelligent technologies, and experience management. As a cloud company with two hundred million users and more than one hundred thousand employees worldwide, we are purpose-driven and future-focused, with a highly collaborative team ethic and commitment to personal development. Whether connecting global industries, people, or platforms, we help ensure every challenge gets the solution it deserves. At SAP, you can bring out your best.
We win with inclusion
SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone – regardless of background – feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better world.
SAP is committed to the values of Equal Employment Opportunity and provides accessibility accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for employment with SAP and are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to Recruiting Operations Team: Careerssap.
For SAP employees: Only permanent roles are eligible for the
SAP Employee Referral Program
, according to the eligibility rules set in the SAP Referral Policy. Specific conditions may apply for roles in Vocational Training.
Qualified applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity, gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disability, in compliance with applicable federal, state, and local legal requirements.
Successful candidates might be required to undergo a background verification with an external vendor.
AI Usage in the Recruitment Process
For information on the responsible use of AI in our recruitment process, please refer to our
Guidelines for Ethical Usage of AI in the Recruiting Process
.
Please note that any violation of these guidelines may result in disqualification from the hiring process.
Requisition ID: 447852 | Work Area: Information Technology | Expected Travel: 0 – 10% | Career Status: Professional | Employment Type: Regular Full Time | Additional Locations: #LI-Hybrid
To help us track our recruitment effort, please indicate in your email/cover letter where (vacanciesineu.com) you saw this job posting.
