JobsMondelez International

Platform Engineer, SAP Security

Mondelez International · Chicago, IL

Posted Sep 3, 2026 · We last checked this listing on Sep 20, 2026

Apply at Mondelez International

Likely interview questions for this role

Written from this job description, not a generic list. Each one notes what the interviewer is really checking.

Behavioral

Tell me about a time you led a role redesign or rationalization project. What was messy about the existing environment and how did you clean it up?

real hands-on experience with role remediation versus theoretical knowledge

Describe a SOX or internal audit finding related to SAP access that you had to remediate. What was the root cause and how did you make sure it wouldn't recur?

whether they build sustainable controls or just patch symptoms to close the finding

Tell me about how you've used AI or automation, like SAP Joule or similar tools, to speed up a security task such as role design or SoD analysis. What guardrails did you put around it?

whether AI automation claims are backed by real implementation and awareness of oversight needs, not just buzzword familiarity

Describe a time you had to explain a technical SAP security risk, like an excessive authorization object or a conflicting role, to a non-technical business stakeholder or auditor. How did you get them to act on it?

communication skill translating technical risk into terms that drive business decisions

Technical

Walk me through how you'd design a role architecture for S/4HANA across multiple operating companies that each have some legitimate local requirements. How do you decide what gets standardized versus what stays local?

whether the candidate can balance harmonization goals against real business variation instead of forcing one-size-fits-all roles

How do you configure and use SAP GRC Access Control for access risk analysis and emergency access management? Give a specific example of a ruleset or mitigating control you built.

depth of actual GRC configuration experience versus surface familiarity with the module names

What's your approach to designing controls around firefighter or emergency access in SAP, and how do you keep that access from becoming a standing backdoor?

understanding of privileged access risk in SAP specifically, not generic PAM concepts

How would you integrate SAP access provisioning with an enterprise IGA platform like SailPoint, including identity lifecycle events like a transfer or termination?

practical knowledge of IAM integration points and lifecycle-driven deprovisioning, a named gap area in the posting

Walk me through how you'd approach security cutover activities during an S/4HANA go-live, including what could go wrong during testing or UAT.

experience with the pressure and sequencing of live transformation cutovers, not just steady-state operations

What does least-privilege access design actually look like when you're building composite versus derived roles with organizational-level restrictions?

technical fluency with the specific SAP role-building mechanics named in the posting

Situational

Say you find a critical SoD conflict embedded in a role that's already in production and heavily used across several business units. What do you do first?

how they sequence risk mitigation against business disruption, and whether they loop in the right stakeholders

You're told the business wants to cut SAP license costs by reducing named users, but security wants to maintain least-privilege access. How do you handle that tension?

ability to negotiate competing priorities between cost, compliance, and access design

How do you evaluate a new SAP security advisory or vulnerability note and decide how urgently it needs remediation, given you're not the one applying the patch?

how they collaborate with Basis teams on vulnerability triage without owning the infrastructure directly

Practice this interview out loud.

Offer builds a real interview for this exact role at Mondelez International from your resume and this job description, asks the questions one at a time, and tells you what landed. The first one is free.

Practice this out loud

The full job description

As published by Mondelez International.

Job Description Are You Ready to Make It Happen at Mondelēz International? Join our Mission to Lead the Future of Snacking. Make It Uniquely Yours. You work with the information security team as a competent and experienced information security and compliance specialist. How you will contribute  This role will be responsible for the design, engineering, governance, and continuous optimization of SAP security and access controls, with a strong focus on S/4HANA role architecture, business process alignment, automation, SAP GRC, Segregation of Duties (SoD), vulnerability management, compliance, and integration with enterprise IAM capabilities. The ideal candidate combines deep SAP Security and S/4HANA technical expertise with a strong understanding of business processes, internal controls, IAM, and large-scale transformation programs. This person will partner closely with SAP Basis, functional teams, IAM, Cybersecurity, Internal Audit, Compliance, and business stakeholders to build secure and sustainable solutions. What you will bring SAP S/4HANA Security & Transformation • Lead and execute SAP Security activities supporting S/4HANA transformation and modernization initiatives. • Design and implement scalable SAP security architecture for a multi-operating-company / multi-region environment. • Lead SAP role redesign and rationalization, including business-role architecture, composite/single roles, derived roles, organizational values, and authorization objects. • Translate business process requirements into secure and appropriately segregated SAP access models. • Identify opportunities to simplify, standardize, and harmonize security roles across operating companies while accommodating legitimate local requirements. • Support SAP cutover, migration, testing, UAT, and go-live security activities. Role Engineering & Access Controls  Design and engineer SAP roles based on least privilege, business need, and risk-based access principles. • Perform role analysis, remediation, rationalization, and optimization across existing SAP environments. • Establish and maintain role design standards, naming conventions, ownership models, and approval processes. • Identify and eliminate excessive, conflicting, dormant, and unnecessary access. • Design controls for privileged and sensitive SAP access, including emergency/firefighter access. • Partner with IAM teams to integrate SAP access with enterprise IGA, SSO, MFA, PAM/PIM, and identity lifecycle processes. • Act as a security SME during business process transformation and operating-model changes. • Support SAP license-rightsizing initiatives while maintaining required security and business functionality. SAP GRC & SoD   • Configure, administer, and optimize SAP GRC Access Control capabilities, including: • Access Risk Analysis • Business Role Management • Access Request Management • Emergency Access Management • SoD and critical-access analysis • Perform SoD risk analysis during role design, remediation, provisioning, and business transformation. • Partner with Internal Audit, Compliance, and business control owners to define appropriate mitigating controls. • Support periodic access reviews and certification activities. SAP Security Operations • Partner with SAP Basis and infrastructure teams on SAP vulnerability management, security hardening, patching, and remediation. • Assess SAP security advisories, SAP Notes, vulnerabilities, and configuration risks and coordinate remediation with appropriate technical teams. • Collaborate with Cybersecurity/SOC teams on SAP logging, monitoring, alerting, and security operations. Automation & Continuous Improvement :  • Evaluate and leverage SAP Joule and SAP Business AI capabilities to automate and streamline SAP Security activities, including access analysis, role design, security operations, risk identification, troubleshooting, and security-related user support. • Identify opportunities to apply AI to SAP role engineering, SoD analysis, access certification, vulnerability management, and security monitoring, while maintaining appropriate human oversight and control validation. • Partner with SAP and enterprise AI teams to ensure AI-enabled SAP capabilities follow security, privacy, authorization, and governance requirements. Compliance & Controls • Ensure SAP security controls meet applicable SOX, internal control, audit, regulatory, and corporate cybersecurity requirements. • Provide evidence and support for internal and external audits. • Design sustainable security controls that are embedded into SAP processes rather than dependent on manual intervention. • Maintain security documentation, control procedures, risk assessments, and remediation plans. Required Qualifications • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field, or equivalent experience. • 8+ years of SAP Security experience, with significant hands-on experience in SAP S/4HANA. • Strong experience designing and implementing SAP roles and authorization models. • Demonstrated experience with S/4HANA transformation, role redesign, and security modernization. • Experience working in a large, global, multi-operating-company environment. • Demonstrated experience implementing AI based automation for operational efficiency. • Strong analytical, problem-solving, and communication skills. Preferred Qualifications • Experience with SAP Joule, SAP Business AI, or AI-enabled SAP security and automation capabilities. • Understanding of AI security, authorization, data protection, and governance considerations within SAP environments. • Experience with SAP Fiori security and embedded analytics. • Experience with SAP Cloud / BTP security and hybrid SAP environments. • Experience with SAP Identity Management or integration with IGA platforms such as SailPoint. • Experience with SAP license optimization. • Experience supporting large-scale global SAP transformations. • Experience with security architecture, Zero Trust, and risk-based access models. Salary and Benefits: The base salary range for this position is $86,900 to $119,515; the exact salary depends on several factors such as experience, skills, education and location. In addition to base salary, this position is eligible for participation in a highly competitive bonus program with possibility for overachievement based on performance and company results. In addition, Mondelez International offers the following benefits: health insurance, wellness and family support programs, life and disability insurance, retirement savings plans, paid leave programs, education related programs, paid holidays and vacation time. Some of these benefits have eligibility requirements. Many of these benefits are subsidized or fully paid for by the company. No Relocation support available Business Unit Summary The United States is the largest market in the Mondelēz International family with a significant employee and manufacturing footprint. Here, we produce our well-loved household favorites to provide our consumers with the right snack, at the right moment, made the right way. We have corporate offices, sales, manufacturing and distribution locations throughout the U.S. to ensure our iconic brands—including Oreo and  Chips Ahoy! cookies, Ritz, Wheat Thins and Triscuit crackers, and Swedish Fish and Sour Patch Kids confectionery products —are close at hand for our consumers across the country.   Mondelēz Global LLC is an Equal Opportunity Employer/Protected Veterans/Persons with Disabilities. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected Veteran status, sexual orientation, gender identity, gender expression, genetic information, or any other characteristic protected by law. Applicants who require accommodation to participate in the job application process may contact 847-943-5460 for assistance. For more information about your Federal rights, please see  eeopost.pdf ; EEO is the Law Poster Supplement ; Pay Transparency Nondiscrimination Provision ; Know Your Rights: Workplace Discrimination is Illegal Job Type Regular Information Security Technology & Digital

Apply at Mondelez International

Related jobs

Maintenance Mechanic

Mondelez International · Chicago, IL

Posted Sep 18 · Verified Sep 20

Repack Associate

Mondelez International · Chicago, IL

Posted Sep 17 · Verified Sep 20

Full-time Nabisco Merchandiser/Order Writer

Mondelez International · Green Bay, WI

Posted Sep 16 · Verified Sep 20

Full-time Nabisco Merchandiser/Order Writer

Mondelez International · Marshfield, WI

Posted Sep 16 · Verified Sep 20

Retail Territory Manager

Mondelez International · Waukesha, WI

Posted Sep 15 · Verified Sep 20

Full-time Nabisco Merchandiser/Order Writer

Mondelez International · Paris, IL

Posted Sep 15 · Verified Sep 20