Cyber Defense Engineer
SAP Fioneer • Romania
Posted: September 18, 2026
Job Description
Innovation is and will always be the core to SAP Fioneer, and it is the promise of why we were spun out of SAP: agility, innovation, and delivery.
SAP Fioneer builds on a heritage of outstanding technology and a deep understanding of corporate and consumer demands. At the heart of it all it is simple: We bring financial services to the next level with innovative software solutions and platforms.
We are helping companies in the financial services industry to achieve speed, scalability, and cost-efficiency through digital business innovation, cloud technology, and solutions that cover banking and insurance processes end-to-end.
A global company, rapid growth, innovative people, and a lean organization make SAP Fioneer a place where you accelerate your future!
About the role
In this role, you will play a key part in strengthening our security operations by supporting incident response, enhancing detection capabilities, and driving automation across our defense activities. You will collaborate closely with IT, Privacy, and other stakeholders to improve security controls, ensure effective system hardening, and maintain compliance with key security standards and regulatory frameworks. This is a hands-on role with the opportunity to shape and continuously improve our overall security posture.
Responsibilities
- Participate in the Incident Response (IR) function, investigating and responding to security incidents in a timely and effective manner
- Automate IR and defense center activities by leveraging playbooks, automation rules, and scripts, ensuring consistency and efficiency across operations
- Tune and develop detection rules aligned with organizational needs to maintain strong detection coverage and a high true-positive rate
- Collaborate with IT and other relevant stakeholders to ensure proper hardening configurations across laptops and servers, and partner with the Privacy team on notifications to affected parties in the event of a data disclosure
- Ensure ongoing compliance with relevant standards and frameworks, including ISO 27001, SOC 2, DORA, and others
- 3+ years of experience in defense engineering or incident response, with hands-on expertise configuring detection mechanisms
- Strong understanding of cloud environments and experience with security tooling for detection and response (e.g., SIEM/XDR/EDR platforms such as Microsoft Sentinel, Defender, or equivalents). Azure knowledge is a plus.
- Strong understanding of attacker methodologies, TTPs, and attack paths within cloud environments and across Windows, macOS, and Linux operating systems
- Proficiency in scripting and KQL (Kusto Query Language) or similar query languages.
- Working knowledge of APIs for security tooling and automation (e.g., Microsoft Graph, Defender, Purview, or equivalents)
- Proficiency English language level, both written and verbal