Jobs · Michigan

SAP Platform Security Architect

Ford Motor Company · Dearborn, MI · Yesterday
Hybrid$74k–$166k/yrFull-time

Position Summary

The SAP Platform Security Architect is responsible for defining, governing, and evolving the enterprise security architecture for a large-scale SAP RISE environment supporting Purchasing, Finance, Treasury, Material Management & Planning (MMP), and more than 60 Agile Product Teams. This role establishes enterprise security standards, architecture patterns, governance, and technical direction to ensure secure, scalable, and compliant SAP platforms. The architect partners with Enterprise Architecture, Product Teams, Platform Engineering, Identity Services, Cybersecurity, Infrastructure, and Business stakeholders to ensure SAP security is implemented consistently across cloud and hybrid environments while enabling rapid delivery of business capabilities. This role is accountable for the long-term security strategy of the SAP platform rather than day-to-day operational security administration.

Primary Responsibilities

  • Define the enterprise SAP Security Reference Architecture.
  • Develop security patterns for SAP RISE and hybrid landscapes.
  • Govern security architecture across more than 60 product teams.
  • Establish platform security standards and reusable design patterns.
  • Lead architecture reviews for new SAP capabilities.
  • Review solution designs before implementation.
  • Define security guardrails for all SAP products.
  • Ensure alignment with Enterprise Architecture principles.
  • Maintain platform security roadmaps.

SAP Identity and Access Management

Design and govern enterprise identity architecture including: Microsoft Entra ID, SAP Identity Authentication Service (IAS), SAP Identity Provisioning Service (IPS), SAP Access Control, SAP Cloud Identity Services, SAP Identity Access Governance (IAG), Privileged Access Management integration, Single Sign-On (SSO), Multi-Factor Authentication (MFA), OAuth 2.0, OpenID Connect, SAML, and SCIM provisioning.

Authorization Architecture

Provide enterprise guidance for: role design standards, business role architecture, technical role architecture, derived role strategy, composite role strategy, organizational level security, Fiori Catalogs, Fiori Spaces, Fiori Pages, Authorization Objects, CDS Authorization, RAP authorization concepts, and Embedded Analytics security.

SAP RISE Security

Provide architecture and governance for: SAP S/4HANA RISE, SAP Business Technology Platform (BTP), SAP Integration Suite, SAP Build, SAP Build Process Automation, SAP Event Mesh, SAP Work Zone, SAP Mobile Services, SAP Joule and AI capabilities, SAP Datasphere, SAP Analytics Cloud, and SAP Cloud ALM.

Platform Security Governance

Establish governance across all product teams by: reviewing architecture designs, defining secure implementation patterns, maintaining security standards, driving architecture consistency, reviewing exception requests, managing technical debt, publishing reference architectures, leading security design reviews, and approving security architecture decisions.

Security Risk Management

Lead architecture for: Segregation of Duties (SoD), Sensitive Access, Emergency Access (Firefighter), Privileged Access, Critical Transaction Monitoring, Platform Risk Assessments, Threat Modeling, Security Exception Management, Audit Readiness, and Compliance Reporting.

Cloud Security

Provide architecture for: network segmentation, Private Link, secure connectivity, encryption at rest, encryption in transit, Key Management, Certificate Management, Secrets Management, API Security, WAF integration, Reverse Proxy, and Secure Internet Access.

AI Security

Define security architecture for: SAP Joule, AI Agents, Generative AI, AI Governance, Prompt Security, Model Access Controls, Data Privacy, AI Risk Controls, Responsible AI, and Agent-to-Agent integrations.

DevSecOps

Develop secure engineering practices including: CI/CD security, transport governance, secure software delivery, static code analysis, security testing, Infrastructure as Code security, automated compliance validation, and release governance.

Platform Governance Across Product Teams

Provide architecture oversight for over 60 product teams supporting: Purchasing, Finance, Treasury, Material Management & Planning (MMP), Logistics, Supplier Management, Manufacturing, Enterprise Integration, Analytics, and Master Data.

Responsibilities include: architecture reviews, design approvals, security standards, platform consistency, security roadmaps, product team guidance, and technical mentoring.

Required Technical Skills

SAP Platforms: SAP S/4HANA, SAP RISE, SAP BTP, SAP Fiori, SAP Gateway, SAP HANA, SAP Cloud ALM, SAP Integration Suite, SAP Datasphere, SAP Analytics Cloud, SAP Build, SAP Mobile Services, SAP Joule

Security Technologies: SAP GRC, SAP IAG, Microsoft Entra ID, IAS, IPS, OAuth, OpenID Connect, SAML, SCIM, Azure Key Vault, Microsoft Defender, SIEM integration, Onapsis (preferred), SecurityBridge (preferred)

Enterprise Architecture Experience With: TOGAF, NIST Cybersecurity Framework, NIST AI Risk Management Framework, Zero Trust Architecture, Defense-in-Depth, Secure-by-Design principles, Cloud Security Architecture

Required Experience

  • 5+ years of SAP Security experience.
  • 5+ years of SAP Security Architecture experience.
  • Experience leading enterprise SAP transformations.
  • Experience with SAP RISE.
  • Experience governing enterprise SAP platforms.
  • Experience supporting large-scale global SAP implementations.
  • Experience defining enterprise security standards.
  • Experience working with Enterprise Architecture.
  • Experience supporting Agile Product Teams.
  • Experience presenting to executive leadership and Architecture Review Boards.

Leadership Expectations

The successful candidate will: influence without direct authority, drive enterprise standards, build consensus across Product Teams, communicate effectively with executives, mentor architects and engineers, balance security with business agility, translate complex technical topics into executive-level recommendations, and foster a culture of secure-by-design engineering.

Success Metrics Within The First 12 Months

  • Establish an enterprise SAP Security Reference Architecture.
  • Publish reusable security patterns for SAP RISE and SAP BTP.
  • Implement governance processes supporting 60+ Product Teams.
  • Reduce architecture exceptions through standardized security patterns.
  • Improve security review consistency and delivery speed.
  • Strengthen identity governance, privileged access controls, and Segregation of Duties.
  • Enhance cloud security posture and audit readiness.
  • Enable secure adoption of SAP AI capabilities, including Joule and agentic workflows.

Pay

This position is a salary grade 6-8 and ranges from $74,300-$166,200. Final determination of salary grade will be based on candidate's skills and experience, and base salary will be set within the applicable range according to job scope, responsibility and competitive market value.

Benefits

  • Immediate medical, dental, vision and prescription drug coverage.
  • Flexible family care days, paid parental leave, new parent ramp-up programs, subsidized back-up child care and more.
  • Family building benefits including adoption and surrogacy expense reimbursement, fertility treatments, and more.
  • Vehicle discount program for employees and family members and management leases.
  • Tuition assistance.
  • Established and active employee resource groups.
  • Paid time off for individual and team community service.
  • A generous schedule of paid holidays, including the week between Christmas and New Year's Day.
  • Paid time off and the option to purchase additional vacation time.

Schedule

This position is hybrid. Candidates who are in commuting distance to a Ford hub location may be required to be onsite four or more days per week.

This response is AI-generated, for reference only.

Similar jobs