(Senior) IT Risk Specialist
Role details
Job location
Tech stack
Job description
SAP SS&D (Sovereign Services & Delivery) is looking for an IT Risk Specialist (f/m/d) to operate and further develop the infrastructure at our Walldorf location.
In this role, you will be responsible for the secure operation and risk-compliant management of the local IT environment, including the on-site Micro Data Center. This includes managing and maintaining the hardware infrastructure, performing preventive maintenance and troubleshooting, and applying regular updates and security patches to ensure a compliant and stable system landscape. You will also be responsible for the provisioning, rollout, and support of hardened clients at the site.
Your tasks will involve both strategic and hands-on responsibilities: from installing and configuring systems, virtualization, and hardware lifecycle management, to ensuring compliance with relevant IT security, physical protection, and regulatory requirements.
You will support and further develop key infrastructure components, contribute to continuous improvements, and serve as the contact for all operations at the Walldorf site. Your work directly supports secure development and delivery capabilities for public sector and regulated industry customers, helping SAP meet the highest confidentiality and compliance standards.
Your primary responsibilities will include:
- Operating and extending technical and structural infrastructure components for highly secure environments, both for internal platforms and customer-facing projects
- Supporting security accreditation processes and administrating relevant systems and security technologies
- Providing technical support for SAP processes
- Acting as the local contact and coordinating liaison with external IT service providers and technology partners
- Managing secure IT operations in close alignment with central SAP SS&D operations, especially for externally operated systems and providers in Walldorf and Berlin
- Administration and maintenance of virtualized environments (VMS) and support in setting up new virtual machines
- Operation and management of Active Directory components and secure identity/access controls
- Managing backup and recovery operations using VEEAM to ensure high availability and data integrity
- Handling IT asset management, including lifecycle tracking and compliance for all devices
- Provisioning and support of hardened clients, including onboarding, maintenance, and troubleshooting
- Working with SIEM systems, ideally Splunk, to analyze logs, detect anomalies, and support incident response
- Supporting the mitigation of IT security incidents and helping the business fulfill governmental regulatory requirements
- Enabling classified development projects by ensuring secure environments according to national and international requirements
- Starting your career in SAP SS&D by learning and applying the strict requirements for handling customer information, in collaboration with government authorities (e.g. multi-/bilateral agreements and process handling)
Requirements
You are a committed and proactive IT risk specialist with a strong background in secure infrastructure operations and classified environments. Your profile should demonstrate experience in several of the following areas:
- Master's degree (or equivalent) in IT, cybersecurity, or a related field. Alternatively, completed vocational training as an IT specialist (Fachinformatiker) with relevant professional experience
- 4+ years of relevant working experience in secure IT operations
- Proven knowledge of IT security frameworks and compliance standards, ISO 27001, and BSI IT-Grundschutz
- Hands-on experience with BSI-certified IT security products (7164) and secure IT architectures for both on-premise and cloud deployments
- Practical experience in operating and managing certfied environments, including understanding of related legal and procedural requirements
- Experience in setting up and maintaining virtualized environments
- First experience with administration of Active Directory (AD) and management of secure user identities
- Operation and maintenance of backup solutions
- Familiarity with IT asset lifecycle management within secure infrastructures
- First experience with SIEM systems, for log analysis, correlation, and incident response
- Strong organizational skills and the ability to manage complex operational tasks securely and independently
- A proactive, structured, and solution-oriented working style
- Conduct guided tours of our infrastructure for stakeholders and customers
- Ability to coordinate effectively with internal teams and external service providers
- Excellent German and English communication skills, both written and spoken
- A collaborative, hands-on mindset with strong interpersonal and communication skills