Create Alert

IT Business Services (Senior) Consultant as PCI DSS - Internal Controls Senior Specialist (m/f)

Date: Jul 20, 2026

Location: Walldorf, Germany

Company: automation-1

Ref-Code: DE-60431789-EN-15-001
Work area: Information Technology
Expected travel: 0% - 10%
Career status:
Employment type: Regular Full Time


COMPANY DESCRIPTION

SAP is the global market leader for business software and thus contributes a considerable part of the world's economic power grid. At SAP you get your chance to put your ideas into action with maximum impact.Within the Business Innovation and IT organization the department Security, Risk & Compliance Office (SRCO), is globally responsible for the IT Security and Compliance Management Framework of SAP Cloud and SAP's internal IT. SRCO provides strategic Cloud & IT security, compliance & data privacy direction and operational advisory services to enable SAP to be the best-run Enterprise Cloud Company. SRCO is acting internally and externally as the trusted partner & advisor for security, risk management and compliance matters. The objectives of the IT Corporate Compliance Team are mainly to:
- Achieve PCI DSS compliance for SAP
- Achieve SOX compliance for SAP IT
- Protect confidential and strictly confidential information by implementing mitigating security & control measures
- Maintain a stable and efficient authorization concept to be able to control access to critical data Based on legal requirements the PCI DSS - Internal Controls Specialist supports all related compliance activities to continually improve the effectiveness of the internal control system for SAP Cloud & IT. This role will provide effective guidance and oversight for general processes in operations, as well as own key decisions regarding quality thresholds and regulatory compliance. It is also required to ensure that the processes are documented in alignment with the SAP process methodology including embedded controls and uses best practices that were already implemented. Within the IT SRCO team, we practice a trust-based working model. We work in a dynamic fast paced environment with periods of intense delivery.

EXPECTATIONS AND TASKS

- Support the internal control frameworks of SAP Cloud & IT
- Support in reaching Attestations (e.g. PCI DSS) for the SAP Group
- Support regarding Compliance requests (e.g. internal Projects, M&A activities)
- Support SRCO in providing control efficiency for PCI DSS related processes
- Monitor & test effectiveness of the defined internal control system
- Actively collaborate with Cloud & IT units to improve the internal control system matching the derived business requirements
- Manage & conduct internal IT security and quality management audits and ensure effectiveness of such audits
- Present and report audit results including the identification, quantification, prioritization of preventive and corrective actions
- Manage and drive the creation of mitigation plans and follow up on the defined implementation measures

WORK EXPERIENCE

- At least 1-3 years' experience in IT Compliance or Audit Management, preferably as an Auditor or IT Internal Controls Consultant

EDUCATION AND QUALIFICATION / SKILLS AND COMPETENCIES

- Very good knowledge of common Attestation demands for PCI DSS Compliance demands
- Quick adaption of new working areas and audit norms
- Result orientation and execution focus
- Strong communication skills are an advantage
- Proactive behavior and high willingness to learn
- Demand for a challenging position with the chance to develop your own ideas
- Business fluent in English and German of great additonal advantage are the following skills:
- Experience of common Certification Standards for IT Security, Business Continuity & Quality Management (e.g. ISO 27001, ISO22301, ISO 9001) as well as leading practices for IT processes and controls (e.g. ITIL, COBIT).
- Experience in auditing practices and methodology. ISO 27001 Lead Auditor certification is an advantage.