Analyst III - Information Security
UST · IT Services & Consulting
- Bangalore
- On-site
- Posted today
- Cybersecurity
About the job
The SAP Cybersecurity and Onapsis Implementation Analyst will support the implementation, configuration, and operationalization of the Onapsis Platform across the SAP environment. This hands-on role will analyze cybersecurity findings, prioritize risk, coordinate remediation, validate closure, and work closely with the Onapsis team and internal SAP, infrastructure, and cybersecurity stakeholders. Key Responsibilities • Support Onapsis implementation, configuration, SAP system onboarding, testing, troubleshooting, and transition to operations. • Coordinate implementation activities with the Onapsis team and SAP Basis, SAP Security, Database, Infrastructure, Development, Functional, SOC, and Vulnerability Management teams. • Analyze Onapsis findings related to SAP vulnerabilities, missing patches, insecure configurations, authorizations, custom code, transports, operating systems, and databases. • Validate and prioritize findings based on severity, exploitability, system criticality, business impact, and compensating controls. • Translate findings into clear remediation recommendations and track vulnerabilities through assignment, remediation, retesting, exception management, and closure. • Coordinate remediation reviews, resolve blockers, and escalate overdue or high-risk findings. • Support integration of relevant Onapsis s with SOC monitoring and incident-response processes. • Develop dashboards and reports covering cybersecurity posture, critical findings, remediation progress, aging, exceptions, and risk trends. • Maintain implementation documentation, operating procedures, remediation trackers, and knowledge-transfer materials. Required Qualifications • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or equivalent professional experience. • Five or more years of experience in SAP security, SAP Basis, cybersecurity, vulnerability management, or application security. • Hands-on experience implementing, configuring, administering, or operationalizing the Onapsis Platform. • Experience analyzing Onapsis findings and coordinating remediation across SAP technical teams. • Strong knowledge of SAP architecture, SAP Basis, SAP Security Notes, patching, system hardening, authentication, authorizations, interfaces, and SAP database and operating-system dependencies. • Experience managing vulnerabilities from identification through remediation, validation, exception management, and closure. • Ability to provide clear, actionable remediation guidance to technical teams. • Strong analytical, documentation, communication, and stakeholder-management skills. • Ability to work independently and coordinate activities across global teams. Preferred Qualifications • Experience with Onapsis vulnerability assessment, threat monitoring, custom code analysis, transport analysis, or compliance reporting. • Experience integrating security s with SIEM, SOC, ServiceNow, or other vulnerability-management workflows. • Experience with SAP S/4HANA, ECC, NetWeaver, HANA, BTP, or cloud-hosted SAP environments. • Knowledge of NIST Cybersecurity Framework, NIST SP 800-53, ISO 27001, CIS Controls, or COBIT. • Relevant SAP, Onapsis, CISSP, CISM, CRISC, GIAC, or cloud security certification is preferred. Key Deliverables • Onapsis implementation and SAP system-onboarding support. • Validated and prioritized SAP cybersecurity findings. • Vulnerability remediation tracker with owners and target dates. • Retesting and closure evidence, including risk exceptions and escalation records. • SAP cybersecurity dashboards, metrics, SOC procedures, operational runbooks, and knowledge-transfer documentation. Position Details: Experience: Five or more years Shift: India day shift, with flexibility for global meetings. Travel: Limited, if required Work Style: Hands-on technical and stakeholder coordination role.