SAP Platform Security Architect
SAP Platform Security Architect (SAP RISE)
Position Summary
The SAP Platform Security Architect is responsible for defining, governing, and evolving the enterprise security architecture for a large-scale SAP RISE environment supporting Purchasing, Finance, Treasury, Material Management & Planning (MMP), and more than 60 Agile Product Teams. This role establishes enterprise security standards, architecture patterns, governance, and technical direction to ensure secure, scalable, and compliant SAP platforms.
The architect partners with Enterprise Architecture, Product Teams, Platform Engineering, Identity Services, Cybersecurity, Infrastructure, and Business stakeholders to ensure SAP security is implemented consistently across cloud and hybrid environments while enabling rapid delivery of business capabilities.
This role is accountable for the long-term security strategy of the SAP platform rather than day-to-day operational security administration.
Primary Responsibilities
Enterprise SAP Security Architecture
Define the enterprise SAP Security Reference Architecture.
Develop security patterns for SAP RISE and hybrid landscapes.
Govern security architecture across more than 60 product teams.
Establish platform security standards and reusable design patterns.
Lead architecture reviews for new SAP capabilities.
Review solution designs before implementation.
Define security guardrails for all SAP products.
Ensure alignment with Enterprise Architecture principles.
Maintain platform security roadmaps.
SAP Identity and Access Management
Design and govern enterprise identity architecture including:
Microsoft Entra ID
SAP Identity Authentication Service (IAS)
SAP Identity Provisioning Service (IPS)
SAP Access Control
SAP Cloud Identity Services
SAP Identity Access Governance (IAG)
Privileged Access Management integration
Single Sign-On (SSO)
Multi-Factor Authentication (MFA)
OAuth 2.0
OpenID Connect
SAML
SCIM provisioning
Authorization Architecture
Provide enterprise guidance for:
Role design standards
Business role architecture
Technical role architecture
Derived role strategy
Composite role strategy
Organizational level security
Fiori Catalogs
Fiori Spaces
Fiori Pages
Authorization Objects
CDS Authorization
RAP authorization concepts
Embedded Analytics security
SAP RISE Security
Provide architecture and governance for:
SAP S/4HANA RISE
SAP Business Technology Platform (BTP)
SAP Integration Suite
SAP Build
SAP Build Process Automation
SAP Event Mesh
SAP Work Zone
SAP Mobile Services
SAP Joule and AI capabilities
SAP Datasphere
SAP Analytics Cloud
SAP Cloud ALM
Platform Security Governance
Establish governance across all Product Teams by:
Reviewing architecture designs.
Defining secure implementation patterns.
Maintaining security standards.
Driving architecture consistency.
Reviewing exception requests.
Managing technical debt.
Publishing reference architectures.
Leading security design reviews.
Approving security architecture decisions.
Security Risk Management
Lead architecture for:
Segregation of Duties (SoD)
Sensitive Access
Emergency Access (Firefighter)
Privileged Access
Critical Transaction Monitoring
Platform Risk Assessments
Threat Modeling
Security Exception Management
Audit Readiness
Compliance Reporting
Cloud Security
Provide architecture for:
Network segmentation
Private Link
Secure connectivity
Encryption at rest
Encryption in transit
Key Management
Certificate Management
Secrets Management
API Security
WAF integration
Reverse Proxy
Secure Internet Access
AI Security
Define security architecture for:
SAP Joule
AI Agents
Generative AI
AI Governance
Prompt Security
Model Access Controls
Data Privacy
AI Risk Controls
Responsible AI
Agent-to-Agent integrations
DevSecOps
Develop secure engineering practices including:
CI/CD security
Transport governance
Secure software delivery
Static code analysis
Security testing
Infrastructure as Code security
Automated compliance validation
Release governance
Platform Governance Across Product Teams
Provide architecture oversight for over 60 Product Teams supporting:
Purchasing
Finance
Treasury
Material Management & Planning (MMP)
Logistics
Supplier Management
Manufacturing
Enterprise Integration
Analytics
Master Data
Responsibilities include:
Architecture reviews
Design approvals
Security standards
Platform consistency
Security roadmaps
Product team guidance
Technical mentoring
Required Technical Skills
SAP Platforms
SAP S/4HANA
SAP RISE
SAP BTP
SAP Fiori
SAP Gateway
SAP HANA
SAP Cloud ALM
SAP Integration Suite
SAP Datasphere
SAP Analytics Cloud
SAP Build
SAP Mobile Services
SAP Joule
Security Technologies
SAP GRC
SAP IAG
Microsoft Entra ID
IAS
IPS
OAuth
OpenID Connect
SAML
SCIM
Azure Key Vault
Microsoft Defender
SIEM integration
Onapsis (preferred)
SecurityBridge (preferred)
Enterprise Architecture
Experience with:
TOGAF
NIST Cybersecurity Framework
NIST AI Risk Management Framework
Zero Trust Architecture
Defense-in-Depth
Secure-by-Design principles
Cloud Security Architecture
Required Experience
5+ years of SAP Security experience.
5+ years of SAP Security Architecture experience.
Experience leading enterprise SAP transformations.
Experience with SAP RISE.
Experience governing enterprise SAP platforms.
Experience supporting large-scale global SAP implementations.
Experience defining enterprise security standards.
Experience working with Enterprise Architecture.
Experience supporting Agile Product Teams.
Experience presenting to executive leadership and Architecture Review Boards.
Leadership Expectations
The successful candidate will:
Influence without direct authority.
Drive enterprise standards.
Build consensus across Product Teams.
Communicate effectively with executives.
Mentor architects and engineers.
Balance security with business agility.
Translate complex technical topics into executive-level recommendations.
Foster a culture of secure-by-design engineering.
Success Metrics
Within the first 12 months, the architect will:
Establish an enterprise SAP Security Reference Architecture.
Publish reusable security patterns for SAP RISE and SAP BTP.
Implement governance processes supporting 60+ Product Teams.
Reduce architecture exceptions through standardized security patterns.
Improve security review consistency and delivery speed.
Strengthen identity governance, privileged access controls, and Segregation of Duties.
Enhance cloud security posture and audit readiness.
Enable secure adoption of SAP AI capabilities, including Joule and agentic workflows.
Primary Responsibilities
Enterprise SAP Security Architecture
- Define the enterprise SAP Security Reference Architecture.
- Develop security patterns for SAP RISE and hybrid landscapes.
- Govern security architecture across more than 60 product teams.
- Establish platform security standards and reusable design patterns.
- Lead architecture reviews for new SAP capabilities.
- Review solution designs before implementation.
- Define security guardrails for all SAP products.
- Ensure alignment with Enterprise Architecture principles.
- Maintain platform security roadmaps.
You may not check every box, or your experience may look a little different from what we've outlined, but if you think you can bring value to Ford Motor Company, we encourage you to apply!
As an established global company, we offer the benefit of choice. You can choose what your Ford future will look like: will your story span the globe, or keep you close to home? Will your career be a deep dive into what you love, or a series of new teams and new skills? Will you be a leader, a changemaker, a technical expert, a culture builder…or all of the above? No matter what you choose, we offer a work life that works for you, including:
• Immediate medical, dental, vision and prescription drug coverage
• Flexible family care days, paid parental leave, new parent ramp-up programs, subsidized back-up child care and more
• Family building benefits including adoption and surrogacy expense reimbursement, fertility treatments, and more
• Vehicle discount program for employees and family members and management leases
• Tuition assistance
• Established and active employee resource groups
• Paid time off for individual and team community service
• A generous schedule of paid holidays, including the week between Christmas and New Year’s Day
• Paid time off and the option to purchase additional vacation time.
This position is a salary grade 6-8 and ranges from $74,300-$166,200.
Final determination of salary grade will be based on candidate's skills and experience, and base salary will be set within the applicable range according to job scope, responsibility and competitive market value.
For more information on salary and benefits, click here: https://fordcareers.co/GSR
Visa sponsorship is not available for this position.
Candidates for positions with Ford Motor Company must be legally authorized to work in the United States. Verification of employment eligibility will be required at the time of hire.
We are an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, age, sex, national origin, sexual orientation, gender identity, disability status or protected veteran status. In the United States, if you need a reasonable accommodation for the online application process due to a disability, please call 1-888-336-0660.
This position is hybrid. Candidates who are in commuting distance to a Ford hub location may be required to be onsite four or more days per week.
#LI-Hybrid
#LI-GR1