*****NEED PROFILES*****
Job Description: SAP Security Architect β BTP
Location: Rosemead, CA
Duration: 6 months
Key Responsibilities
Security Architecture & Design
β’ Design and maintain secure architecture for SAP BTP services including:
o Cloud Foundry
o Kyma Runtime
o SAP Integration Suite
o SAP Extension Suite
β’ Define security patterns for multi-account, subaccount, and tenant-based BTP landscapes
β’ Architect secure cloud-to-cloud and cloud-to-on-premise integrations
Identity & Access Management (IAM)
β’ Architect and manage authentication and authorization using:
o SAP Identity Authentication Service (IAS)
o SAP Identity Provisioning Service (IPS)
o SAP BTP Authorization concepts (roles, role collections)
β’ Implement Single Sign-On (SSO) and Federated Identity (SAML 2.0, OAuth 2.0, OpenID Connect)
β’ Integrate SAP BTP security with corporate IdPs (Azure AD, Okta, etc.)
Application & Integration Security
β’ Secure REST APIs, events, and integrations within SAP BTP
β’ Define API security using OAuth scopes, XSUAA, certificates, and token-based authentication
β’ Ensure secure connectivity using SAP Cloud Connector and mTLS
Platform & Infrastructure Security
β’ Implement network security controls, trust configuration, and secure connectivity
β’ Apply secure configuration for BTP services and runtimes
β’ Define standards for secrets management and certificate lifecycle management
Governance, Risk & Compliance (GRC)
β’ Establish security standards, policies, and guardrails for SAP BTP
β’ Ensure compliance with regulatory frameworks (ISO 27001, SOC 2, GDPR, SOX, etc.)
β’ Support security audits, risk assessments, and penetration testing activities
DevSecOps & Monitoring
β’ Embed security into CI/CD pipelines for BTP applications
β’ Define secure coding and deployment guidelines
β’ Monitor security events using SAP and enterprise security tools and respond to incidents
Required Skills & Qualifications
Technical Skills
β’ Strong expertise in SAP BTP security architecture
β’ Hands-on experience with:
o SAP IAS / IPS
o XSUAA
o OAuth 2.0, SAML 2.0, OpenID Connect
β’ Deep understanding of cloud security principles (Zero Trust, least privilege)
β’ Experience securing SAP landscapes (S/4HANA, SuccessFactors, Ariba, etc.)
β’ Knowledge of API security, certificates, encryption, and key management
Cloud & Integration Knowledge
β’ Good understanding of cloud platforms (SAP BTP, Azure, AWS, or GCP)
β’ Experience with hybrid integrations and SAP Cloud Connector
β’ Familiarity with DevSecOps practices and CI/CD security
Certifications (Preferred)
β’ SAP Certified Technology Associate β SAP BTP
β’ SAP Security or SAP Cloud certifications
β’ Cloud security certifications (Azure Security Engineer, CISSP, CCSP β a plus)
Β Β
Rahul Mehra
[Upgrade to PRO to see contact]