Senior Platform Engineer
Sap · Bengaluru/Bangalore, Karnataka
Sap · Bengaluru/Bangalore, Karnataka
Senior Platform Engineer - SAP Integration Suite - Integration Cell We help the world run better At SAP, we keep it simple: you bring your best to us, and we'll bring out the best in you. We're builders touching over 20 industries and 80% of global commerce, and we need your unique talents to help shape what's next. The work is challenging -- but it matters. You'll find a place where you can be yourself, prioritize your wellbeing, and truly belong. What's in it for you? Constant learning, skill growth, great benefits, and a team that wants you to grow and succeed. WHAT YOU'LL BUILD: As a Senior Platform Engineer, you will define technical direction, drive architectural decisions across the platform, represent the team in cross-org discussions, and raise the bar for engineering quality and security. The scope is expanding to include AI Gateway capabilities and MCP server management, positioning Integration Cell as the unified runtime for both traditional integration and AI-native workloads --- making this a high-growth, forward-looking platform at the intersection of enterprise integration and AI infrastructure. Role Expectations Architect and lead the development of critical, large-scale components of Integration Cell runtime Own technical strategy --- decision making, define interfaces, set standards Drive platform-wide security, scalability, and reliability initiatives with measurable outcomes Act as a technical escalation point for complex production issues and customer-facing challenges Act as a force multiplier --- raise the technical bar through design reviews, mentorship, and establishing engineering best practices Influence product roadmap by proactively identifying gaps, risks, and opportunities Collaborate with Architects, Product Managers, and peer teams across SAP Business AI Platform WHAT YOU BRING: Core Engineering Expert-level development skills in Go / Java / Node.js Deep, proven experience designing distributed systems, microservices, and event-driven architecture at scale Ability to make and defend architectural tradeoffs; experience with system design across multiple teams Cloud \& Containerization Docker, Kubernetes, Helm --- production-grade, multi-tenant workload management Kubernetes security: RBAC, Pod Security Admission, secrets management, network policies Container security: image scanning, supply chain security (SBOM, signing) Policy-as-code: OPA / Gatekeeper for centrally enforcing security and governance rules across clusters --- pod security, image provenance, resource constraints, and tenant isolation Infrastructure \& Cloud Security AWS / Azure / GCP / OpenStack --- hands-on cloud infrastructure experience Identity \& Access: IAM, least-privilege, workload identity, federated authentication Data security: encryption at rest and in transit, key management (KMS/HSM), secrets rotation Networking security: TLS/mTLS, service mesh (Istio/Linkerd), zero-trust architecture, private endpoints Threat \& compliance: security benchmarks (CIS, NIST), vulnerability management, audit logging FIPS 140-2/140-3 awareness for cryptographic compliance in regulated environments Hybrid cloud security: secure connectivity across on-prem and multi-cloud environments Application \& Runtime Security Threat modeling --- identify and design against attack surfaces early in the SDLC Secure coding practices, OWASP awareness, input validation at service boundaries Tenant isolation security: network, compute, and data layer separation in multi-tenant environments Shift-left security: integrating security reviews and tooling into development workflows DevOps Jenkins, Concourse, Argo CD --- CI/CD pipelines and GitOps Secure pipelines: secrets scanning, SAST/DAST, dependency vulnerability checks Monitoring Dynatrace or equivalent (Prometheus, Grafana, Jaeger) Logging, tracing, alerting design for multi-tenant environments; SLO/SLI practices Integration \& API Security REST / SOAP, API gateway patterns API security: OAuth 2.0, JWT, mTLS, rate limiting API threat protection: payload inspection, schema validation, injection attack prevention at the gateway level Token lifecycle management: introspection, revocation, and refresh strategies across distributed services Audit \& non-repudiation: tamper-proof audit logs for API calls and admin actions, critical for enterprise compliance and forensic traceability Generative AI, MCP \& AI Gateway Hands-on understanding of GenAI, LLMs, and RAG --- ideally with production or near-production exposure MCP server lifecycle management: deployment, versioning, health monitoring, and security of MCP servers MCP security: authentication between AI agents and MCP servers, tool-level authorization and access control MCP observability: tracing agent-to-tool calls, auditing tool invocations for compliance AI Gateway patterns: routing, load balancing, and failover across multiple LLM providers LLM-specific security: prompt injection defense, input/output content filtering, PII redaction Token-based rate limiting and cost governance across tenants for LLM API consumption AI observability: latency, token usage, and model response quality tracking per tenant A2A (Agent-to-Agent) communication patterns and security considerations Profile Requirement 8--12 years in backend / platform / infrastructure engineering Demonstrated history of owning large-scale, cross-team technical initiatives from inception to production Experience setting technical direction and influencing architectural decisions beyond own team Strong communication skills --- comfortable engaging with senior stakeholders and customers Growth mindset, strong sense of ownership, and a collaborative attitude WHERE YOU BELONG: SAP Business AI Platform INT ABS -- API Business Services works on Integration Suite, offering services such as SAP Business Accelerator Hub and SAP API Management for seamless enterprise connectivity. Integration Cell introduces a dedicated, SAP-managed runtime architecture with impr