ERP security roles are quietly becoming SAP leadership roles

A client in Frankfurt recently asked us to find an SAP Basis administrator who could also chair their quarterly security review. The role had existed for years as a pure infrastructure position. The security review was an afterthought, something the administrator attended but did not run. That changed after an external audit flagged how quickly AI tools can now map privilege escalation paths in an S/4HANA environment. The same audit noted that their manual patching cycle took longer than the average time-to-exploit for known vulnerabilities.

Companies across the DACH region are making similar adjustments to their SAP org charts. The technical skills for Basis administration remain in demand, and the seniority and scope of those roles are expanding. Companies want someone who can sit in a room with the CISO and argue about agent identities, excessive permissions, and zero-trust architecture. They also want that person to have hands-on SAP knowledge, because the generic cybersecurity specialist cannot always translate threats into specific system configurations.

The candidate pool for this combination is shallow. Most experienced Basis administrators built their careers before AI-accelerated threats became a board-level concern. Most cybersecurity specialists have never configured an SAP authorisation object. Salary expectations for profiles that bridge both disciplines have moved up roughly 20% in Zurich and Munich over the past year.

Hiring managers looking to fill these roles should expect longer searches and higher compensation bands than a traditional Basis vacancy. The people who can translate zero-trust principles into SAP authorisation objects are fielding multiple offers, and they will choose the company that gives them genuine decision-making authority over the one that treats security as a compliance checkbox.

Prompted by reporting from ERP Today.

Facebook
LinkedIn