Company Profile
Founded in 1976, CGI is among the largest independent IT and business consulting services firms in the world. With 94,000 consultants and professionals across the globe, CGI delivers an end-to-end portfolio of capabilities, from strategic IT and business consulting to systems integration, managed IT and business process services and intellectual property solutions. CGI works with clients through a local relationship model complemented by a global delivery network that helps clients digitally transform their organizations and accelerate results. CGI Fiscal 2024 reported revenue is CA$14.68 billion and CGI shares are listed on the TSX (GIB.A) and the NYSE (GIB). Learn more at cgi.com.
Job Title: SAP Security Testing Consultant
Position: Software Engineer / Senior Software Engineer
Experience: 4-9 Years
Category: Cybersecurity / SAP Security
Work Mode: Hybrid (3 days in office, 2 days WFH)
Primary Location: Bangalore/Hyderabad
Employment Type: Full Time
Certification Required: CEH
Role Summary
We are seeking a skilled SAP Security Testing professional to support security assessment and testing activities across SAP applications and related technologies. The role involves understanding SAP non-functional and security requirements, assessing application architecture, developing security testing strategies, conducting penetration testing and vulnerability assessments, and supporting clients with remediation recommendations.
The candidate will also contribute to security testing automation, DevSecOps integration, cloud security testing, security audits, and Proofs of Concept (PoCs) for emerging security tools and technologies. The role requires strong ownership, client interaction, technical expertise, and the ability to manage multiple projects simultaneously.
Your future duties and responsibilities
Participate in requirement-gathering calls and understand SAP NFRs and security testing requirements.
Understand system architecture, application components, integrations, and associated security considerations.
Conduct SAP Proofs of Concept (PoCs) for new security tools and technologies.
Prepare and present security test plans, including recommendations on appropriate testing methodologies for SAP applications.
Create and execute SAP security test cases based on identified security testing requirements and services.
Develop expertise in manual source code review and gain proficiency in Checkmarx or similar SAST/code review tools.
Conduct manual penetration testing of SAP applications using tools such as Burp Suite and OWASP ZAP.
Demonstrate strong understanding of OWASP Top 10 for web, API, and mobile application penetration testing.
Conduct vulnerability scanning and vulnerability management activities, including assessment, prioritization, remediation tracking, and coordination with relevant teams.
Lead vulnerability assessment activities and prepare detailed remediation assessments and recommendations.
Conduct security audits with a strong understanding of NIST security controls and frameworks.
Develop and execute security testing practices for cloud technologies.
Automate security testing services by integrating security activities into SSDLC, CI/CD pipelines, and DevSecOps practices.
Identify and validate false positives and prepare detailed security assessment reports, including vulnerability counts, severity, impact, and remediation recommendations.
Take ownership of assigned activities and ensure timely completion with minimal supervision.
Own end-to-end project delivery, including daily status updates, weekly reporting, client communication, and report walkthroughs.
Collaborate effectively with application, infrastructure, cloud, development, and other security teams.
Demonstrate the ability to manage and deliver multiple projects simultaneously while maintaining quality and timelines.
Required qualifications to be successful in this role
Education
Bachelor's or Master's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related technical field.
Experience
3+ years of experience in Cybersecurity, Application Security, SAP Security Testing, Vulnerability Assessment, or Penetration Testing.
Hands-on experience in SAP application security testing and assessment.
Experience in security testing across web applications, APIs, mobile applications, and/or cloud environments.
Experience preparing security test plans, test cases, vulnerability reports, and remediation recommendations.
Experience working with multiple stakeholders and managing security testing activities independently.
Technical Skills
Strong understanding of SAP security and SAP application architecture.
Hands-on experience with manual penetration testing and application security testing.
Proficiency with Burp Suite and OWASP ZAP (Zed Attack Proxy).
Strong knowledge of OWASP Top 10, including web and API security testing.
Knowledge of mobile application security testing.
Experience with manual code review and SAST tools such as Checkmarx or equivalent.
Experience with vulnerability scanning and vulnerability management.
Strong understanding of NIST security controls and security audit practices.
Knowledge of cloud security testing across platforms such as Azure, AWS, or GCP.
Understanding of SSDLC, CI/CD, and DevSecOps security practices.
Ability to automate security testing and integrate security controls into development pipelines.
Strong capability to analyze vulnerabilities, validate false positives, assess risk, and provide remediation recommendations.
Good technical documentation and security reporting skills.
Required Certification
Certified Ethical Hacker (CEH) certification is mandatory.
Preferred Skills
Experience conducting security testing for complex SAP landscapes and enterprise applications.
Exposure to SAP security tools and technologies.
Knowledge of additional penetration testing and vulnerability assessment tools.
Experience with DevSecOps and security automation.
Knowledge of cloud security frameworks and controls.
Understanding of security standards and frameworks such as NIST, OWASP, and SSDLC.
Strong analytical, problem-solving, communication, and stakeholder-management skills.
Ability to work independently, take ownership, and deliver within defined timelines.
Ability to manage multiple projects and priorities simultaneously.
Strong client-facing skills, including the ability to present findings and conduct security report walkthroughs.
Together, as owners, let’s turn meaningful insights into action.
Life at CGI is rooted in ownership, teamwork, respect and belonging. Here, you’ll reach your full potential because…
You are invited to be an owner from day 1 as we work together to bring our Dream to life. That’s why we call ourselves CGI Partners rather than employees. We benefit from our collective success and actively shape our company’s strategy and direction.
Your work creates value. You’ll develop innovative solutions and build relationships with teammates and clients while accessing global capabilities to scale your ideas, embrace new opportunities, and benefit from expansive industry and technology expertise.
You’ll shape your career by joining a company built to grow and last. You’ll be supported by leaders who care about your health and well-being and provide you with opportunities to deepen your skills and broaden your horizons.
That same commitment to fairness extends to how we use technology. To support our recruitment team, AI tools may be used to help assess applications though they never replace human judgement. All hiring decisions remain entirely in the hands of our recruitment professionals.
Come join our team—one of the largest IT and business consulting services firms in the world.