Cybersecurity is a critical enabler of SSAB's business transformation journey, and we are now looking for an experienced SAP Security Manager to strengthen the security of our growing SAP landscape and take ownership of cybersecurity governance, security architecture, and risk management across our SAP applications while helping shape the future security of integrated business and manufacturing environments.
You will join SSAB's Group IT team, working closely with colleagues responsible for SAP Technical and Security Operations while bringing a dedicated cybersecurity perspective that helps ensure cybersecurity is embedded into decisions, designs, and processes from the start. You will also be working closely with a global team of experts from Group Security and Division IT, where your role will be critical in building strong relationships and driving collaboration with security stakeholders across the organization.
You will play a central role in our strategic transformation initiatives working closely with business process owners, architects, manufacturing operations, engineering teams, and external partners. You will drive security governance across business-critical SAP processes, integrations, and connected systems making this a uniqueopportunity to influence future cybersecurity direction of a global industrial organization.
Main Responsibilities
- Own SAP cybersecurity governance and security architecture across the SAP landscape ensuring our SAP solutions comply with internal security requirements, regulatory obligations, and customer expectations
- Define and maintain and continuously improve SAP security strategy, standards, controls and operating model, establishing a scalable and sustainable security foundation across the SAP ecosystem in collaboration with Cybersecurity Architect, platform owners, and IT and engineering teams
- Lead the development of SSAB's SAP security roadmap including SAP security risk management, compliance activities, and audit coordination and drive security reviews of SAP integrations and connected business-critical systems
- Own and evolve SAP authorization concepts, role models, privileged access management processes, and Segregation of Duties controls
- Lead identity lifecycle and access governance processes, ensuring effective user provisioning, access reviews, privileged access management, and SoD compliance
- Provide security expertise and guidance for major transformation programs, ensuring secure-by-design principles are embedded throughout SAP initiatives
- Develop the roadmap for SAP and OT cybersecurity governance and support secure IT/OT convergence across manufacturing environments
- Support vulnerability management, risk remediation, and continuous improvement initiatives across SAP platforms and connected systems acting as a subject matter expert and trusted advisor, helping stakeholders understand risks, priorities, and business impacts.
About you
- You have extensive work experience (typically 10+ years) within cybersecurity, information security, or related security disciplines from industrial manufacturing, engineering, automotive, metals, energy, or other production-intensive industries
- You have solid hands-on (at least 3-5 years) experience working with SAP security in complex enterprise environments, preferably SAP S/4HANA where integrations between enterprise applications and operational technology (OT) environments are key
- You are familiar with OT/industrial environments and cybersecurity challenges related to IT/OT convergence and know how to develop and implement pragmatic security improvements in complex operational settings
- You have strong knowledge of SAP security architecture, authorization concepts, role design, access governance, privileged access management, and Segregation of Duties controls
You have proven experience operating or implementing SecurityBridge or equivalent SAP security platforms across vulnerability, threat, and code/change domains
You have a solid understanding of security frameworks and audit standards (ISO 27001, NIST CSF, GDPR) and possess some cybersecurity certifications such as CISSP, CISM, CRISC, AAISM
- You come with experience playing a key role in large-scale SAP transformation or ERP modernization programs and can easily translate technical security requirements into clear and actionable guidance for technical and business stakeholders
- You are great a nurturing strong stakeholder relationship and driving adoption of cybersecurity practices across all our businesses
- You are fluent in English, both written and spoken
Julia Källmar, Group Talent Acquisition Partner, julia.kallmar@ssab.com