SAP Security Engineer - SAP Cybersecurity

AppleShanghai, ShanghaiOn-siteFull-timeSenior, 5–8 yearsListed 5 hours ago

Apply now

About this role

Imagine what you could do here. At Apple, new ideas have a way of becoming extraordinary products, services, and customer experiences very quickly. Bring passion and dedication to your job and there's no telling what you could accomplish.

Apple's global SAP landscape underpins how our products are planned, built, moved, and sold worldwide. The Information Systems & Technology (IS&T) SAP Cybersecurity team is seeking a dedicated Security Engineer to serve as our regional engineering cornerstone in Greater China. In this role, you will be instrumental in designing and implementing resilient security architectures across on-premise SAP systems and SAP Business Technology Platform (BTP), establishing advanced threat detection capabilities, and ensuring our critical infrastructure withstands active cyber threats.

As a Security Engineer within the SAP Cybersecurity Program, you will take end-to-end ownership of securing mission-critical SAP systems and hybrid cloud platforms across the region. You will partner with globally distributed engineering teams, regional infrastructure peers, and business partners to embed security controls into every layer of our architecture. From platform hardening and identity federation to threat detection and offensive validation, your work will safeguard the enterprise backbone powering Apple’s operations.

Minimum Qualifications

Bachelor’s degree in Computer Science, Information Security, Engineering, or equivalent practical experience.
Experience in hands-on security engineering for enterprise ERP or large-scale, business-critical platforms, with technical depth in both on-premise SAP (NetWeaver, HANA) and SAP BTP.
Experience analyzing and securing SAP technical attack surfaces at the protocol and infrastructure level (RFC, SAP Gateway, ICM/Web Dispatcher, SAProuter, Cloud Connector).
Experience designing and implementing cloud identity, federation, and authorization architectures (OAuth 2.0, OIDC, SAML, JWT validation, mTLS, and SAP Cloud Identity Services).
Experience in at least two core security domains: security architecture design, detection engineering/SIEM development, incident response, or offensive security and penetration testing.
Experience with Linux system administration, network architecture, and scripting (Python preferred) to build automated security tooling.
Professional fluency in written and spoken English and Mandarin, with experience collaborating across regional and globally distributed teams.
Ability to support an overlapping schedule with US-based teammates and participate in occasional international travel.

Preferred Qualifications

Master’s degree in Cybersecurity, Computer Science, or related technical field.
Experience securing SAP environments subject to China regulatory frameworks (Cybersecurity Law, Data Security Law, PIPL, MLPS graded protection, and commercial cryptography standards).
Experience administering and securing SAP BTP within the China (Shanghai) region, including local service catalogs and regional deployment constraints.
Experience with SAP threat detection platforms (SAP Enterprise Threat Detection, Focused Run) and modern detection-as-code or SIEM workflows.
Experience with Kubernetes and container security applied to SAP Kyma or cloud-native microservices.
Experience with SAP Integration Suite security architecture at scale, including keystore and certificate lifecycle management.
Experience evaluating cloud security postures across regional public cloud providers (such as Alibaba Cloud, Tencent Cloud, AWS China, or Azure China).
Industry-recognized security certifications (such as CISSP, OSCP, or relevant cloud/SAP security credentials).