Job Title: SAP Joule AI Security Architect
Location: Houston, TX | Onsite
Employment Type: Contract
Duration: 6-12 months
Pay: $80/hr
About:
VLink, founded in 2006, is a leading global provider of software engineering services with next-gen technologies and best-in-class talent. Our Headquarters are in the U.S, and we have offices in 7+ countries from North America-Europe to APAC, with expansion plans in the Middle East. With over 1,000 employees working globally, VLink has helped SMBs, and large enterprises achieve their business goals, and gained the trust of Fortune-250 companies. VLink is 'Great Place to Work® Certified™' and has been a consistent winner as- Best Places to Work in CT. Trust, collaboration, and accountability are the three elements that are at the core of VLink's work culture. We value our professionals, providing comprehensive benefits and the opportunity for growth.
Job Description:
Hands-on security architecture role responsible for the security posture of Joule deployments — access control, data governance, and risk — working directly with the business and IT to clear use cases for POC and production.
Key Responsibilities:
- Define and implement security architecture for Joule deployments, including authentication, authorization, and role-based access
- Design role-based access controls, least-privilege access, segregation of duties (SoD), and privileged/emergency access processes for AI administrators, developers, business users, and service accounts
- Assess data sensitivity and enforce data governance controls for each Joule use case
- Define controls to prevent unauthorized data exposure through prompts, AI agents, and integrations, and review AI use cases for data leakage and privacy concerns
- Partner with GRC to map Joule skills and access against governance, risk, and compliance requirements
- Define and maintain SAP AI security policies, standards, and governance frameworks, including approval and review processes for AI use cases before production deployment
- Perform hands-on security reviews and risk assessments for each POC prior to business rollout
- Conduct security reviews of custom AI agents, establish secure development lifecycle requirements, and define testing procedures for AI agent deployment and production release
- Design and implement monitoring, logging, and audit trails for Joule usage
- Validate secure configurations of AI services, APIs, integrations, and connectors, and support vulnerability management and remediation activities for SAP AI solutions
- Drive security, observability, performance, compliance, and operational excellence standards for enterprise AI solutions across POC and production environments
- Work directly with business stakeholders to explain and resolve security requirements without slowing delivery
- Partner with the functional and technical roles throughout qualification, POC, and deployment
- Keep IT informed of security risks, exceptions, and remediation status
- Educate SAP teams on AI security risks and governance requirements, running workshops for developers, administrators, and business users, and developing guidance for secure prompt engineering and AI agent development
- Maintain security documentation and support internal and external audits
Qualifications:
- Hands-on security architecture experience in enterprise SAP or cloud environments
- Experience with SAP GRC and access control frameworks
- 5+ years of SAP Security and GRC experience, including SAP S/4HANA Security, SAP GRC Access Control, and SAP Identity Services
- Familiarity with AI/copilot-specific security risks, such as data leakage and prompt-based access issues
- Knowledge of AI security principles, machine learning risks, generative AI technologies, and AI governance frameworks, with experience implementing them in enterprise environments
- Experience with SAP BTP security model and Integration Suite security
- Experience securing cloud-native AI platforms using SAP BTP, SAP AI Core, Kubernetes, hyperscalers, DevSecOps practices, observability controls, and distributed system security patterns
- Familiarity with MCP Server environments hosted on SAP BTP, and the security implications of SAP AI Core, SAP AI Hub, and SAP AI Gateway integrations
- Experience with SAP Business AI, Joule, SAP AI Core, SAP AI Launchpad, and SAP BTP AI services, along with cloud platform experience such as Microsoft Azure
- Strong understanding of data governance and compliance requirements in an enterprise setting
- Ability to work directly and collaboratively with business and technical teams, not just in a gatekeeping capacity
- SAP Security, SAP GRC, CISSP, CISM, or cloud security certification
Employment Practices:
VLink is an equal opportunity employer committed to fostering an inclusive environment where diversity is celebrated. All qualified applicants will be considered for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status. Employment is contingent upon successful completion of a background check.
This job application process may use AI-powered tools to assist in screening and evaluating applications based on objective, job-related qualifications. AI is used solely to support the recruitment process and all final hiring decisions are made exclusively by our human recruitment team.
Applicant information will be handled in accordance with VLink's privacy policy.