Full-Time

Software Engineer II

Java, m/f/d

Posted on 10/31/2025

Onapsis

Onapsis

201-500 employees

Protects ERP security with real-time compliance

No salary listed

Bellheim, Germany

Hybrid

Must be commutable to Heidelberg for hybrid work.

Category
Software Engineering (3)
, ,
Required Skills
Agile
Python
Java
GraphQL
Maven
Redis
REST APIs
Linux/Unix
Hibernate
Requirements
  • Bachelor’s Degree in Systems Engineering, Computer Science or related field, or relevant work experience
  • 2+ years of professional software engineering experience
  • 1+ years of programming experience with Java
  • 1+ years of experience contributing to the system design or architecture (architecture, design patterns, reliability, and scaling) of new and current systems
  • 1+ years of experience in OO Programming and OO Design concepts
  • 2+ years of experience with Springboot Framework
  • Experience with databases, ORM frameworks (e.g., Hibernate), and building automation tools such as Ant and Maven
  • Experience building APIs (REST, GraphQL)
  • Experience developing in Linux environment
  • Knowledge of test-driven development (TDD), CI / CD tooling, and Agile methodologies
  • Experience with Asynchronous tasks/queues. ( AMQ, Redis)
  • Experience troubleshooting production environments using observability and monitoring tools
Responsibilities
  • Working with leadership, product management, and the Onapsis research team. You will be engaged in evaluating, scoping, proposing, and building features to fulfill business solution requirements and protect our customers.
  • Work collaboratively with a team of cybersecurity researchers, engineers, and product managers to iterate toward product definition and realization.
  • Additionally, you will be working with the Architecture team to take the platform to the next level of maturity in terms of technologies and architecture design while advancing our quality engineering processes to deliver high-quality products and services while also working closely with security and IT professionals to ensure safe and secure systems architectures are followed.
Desired Qualifications
  • Security software development best practices
  • Cloud-native application development and Cloud Technologies
  • Experience taking a leading role in building complex software systems that have been successfully delivered to customers
  • Knowledge of professional software engineering practices & best practices for the full software development life cycle, including coding standards, code reviews, source control management, build processes, testing, and operations
  • Experience with distributed computing and enterprise-wide systems
  • Experience in communicating with users, other technical teams, and senior management to collect requirements, describe software product features, technical designs, and product strategy

Onapsis provides cybersecurity compliance software that protects mission-critical cloud and on-premises business apps like SAP and Oracle. It automates compliance and IT control audits and delivers real-time visibility and threat alerts for ERP, CRM, PLM, HCM, SCM, and BI systems. The platform continuously monitors code changes, configurations, and maintenance to detect unauthorized changes and misconfigurations, enabling rapid response. Its goal is to help large enterprises reduce operational risk and improve security and compliance across critical business applications.

Company Size

201-500

Company Stage

Series D

Total Funding

$115.6M

Headquarters

Boston, Massachusetts

Founded

2009

Simplify Jobs

Simplify's Take

What believers are saying

  • SAP Notes Command Center and Rapid Controls address 2025 zero-day vulnerability wave, driving enterprise demand surge.[1]
  • Expanded SAP BTP security capabilities capture growing cloud migration market as enterprises accelerate RISE with SAP.[1]
  • Strategic executive hires and deepened CrowdStrike, Microsoft partnerships accelerate go-to-market expansion and enterprise integration.[1]

What critics are saying

  • SAP's native S/4HANA Cloud security features commoditize Onapsis vulnerability management within 12–24 months.[1]
  • Microsoft Copilot for Security natively queries SAP Sentinel data, bypassing Onapsis Agentic Gateway within 3–6 months.[1]
  • Pathlock's integrated GRC and access governance erodes Onapsis Assess market share within 6–12 months.[1]

What makes Onapsis unique

  • Only SAP-endorsed cybersecurity and compliance platform with Gartner Magic Quadrant recognition for three consecutive years.[3]
  • Agentic AI gateway integrates SAP threat intelligence with enterprise AI agents for autonomous vulnerability remediation workflows.[1]
  • Unified platform covers entire SAP lifecycle: vulnerability management, threat detection, compliance automation, and application security testing.[7]

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

401(k) Company Match

401(k) Retirement Plan

Unlimited Paid Time Off

Hybrid Work Options

Remote Work Options

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

1%

2 year growth

0%
Yahoo Finance
Mar 18th, 2026
Onapsis launches industry-first agentic AI gateway for autonomous SAP cybersecurity workflows

Onapsis, a leader in SAP cybersecurity, has unveiled the Onapsis Agentic Gateway, introducing what it calls "Agentic AI for SAP Cybersecurity". The technology enables organisations to integrate SAP security data with enterprise AI agents for autonomous risk management. The gateway uses the Model Context Protocol to connect corporate-approved AI platforms—including Microsoft Copilot, Anthropic Claude, Google Gemini and OpenAI ChatGPT—with Onapsis's threat intelligence. Users can query SAP security data through natural language and receive actionable insights, such as remediation plans for vulnerabilities. The platform will be previewed at the upcoming SAPinsider and RSA Conference 2026. Onapsis CEO Mariano Nunez said the technology aims to integrate SAP risk intelligence directly into autonomous enterprise workflows whilst maintaining enterprise-grade privacy standards.

.406 Ventures
Mar 5th, 2026
Onapsis CEO Joins Industry Leaders on the Main Stage at SAPinsider Las Vegas 2026

Onapsis CEO joins industry leaders on the Main Stage at SAPinsider Las Vegas 2026. Onapsis is a proud double platinum sponsor, hosting sessions with Siemens Healthineers and Microsoft that highlight the importance of proactive SAP security BOSTON, MA - March 5, 2026- Onapsis, the global leader in SAP cybersecurity and compliance, today announced its premier Double Platinum sponsorship of SAPinsider Las Vegas 2026, taking place March 16-19 at the Bellagio Resort & Hotel. As a cornerstone of this year's event, Onapsis will lead the conversation on securing the modern SAP landscape through a mainstage keynote, deep-dive technical sessions and real-world customer case studies. The cornerstone of Onapsis' presence is a panel keynote featuring Mariano Nunez, Onapsis' CEO and Co-Founder; Steve Lucas, Chairman and CEO of Boomi; Wael ElKabbany, Microsoft's Vice President of Product and Data Management, SAP; and Steve Birgfeld, VP, Information Technology and Services at Blue Diamond Growers, on March 17, titled "The New Architecture of Intelligence: Securing and Connecting the Future SAP Ecosystem." The panel discussion will explore how organizations can navigate the intersection of AI, cloud transformation and cybersecurity to build a resilient foundation for their SAP applications. "The rapid evolution of AI and the shift toward the cloud have fundamentally changed the SAP security perimeter," said Mariano Nunez, CEO and Co-founder of Onapsis. "We are excited to demonstrate how the Onapsis Platform provides the visibility and automated protection required to secure these complex, intelligent ecosystems at SAPinsider. From pre-conference education to our mainstage sessions with industry leaders like Siemens Healthineers and Microsoft, we are helping the SAP community defend their applications with confidence." Onapsis Speaking Sessions at SAPinsider 2026: * CEO Panel Keynote: The New Architecture of Intelligence: Securing and Connecting the Future SAP Ecosystem-Join Mariano Nunez and leaders from across the SAP ecosystem on the Main Stage to discuss the future of securing SAP systems. * Case Study: Siemens Healthineers' New SAP Security Approach: Onapsis' Ashlee Fisher and Siemens Healthineers' Nagarajan Nallaiah share a blueprint for modernizing SAP security. Additionally, Siemens Healthineers and Onapsis are finalists for the 2026 SAPinsider Awards in the Cybersecurity Project of the Year category for their work on a centralized, scalable platform that provides visibility across on-premises environments and cloud services. * Case Study: Protecting Mission-Critical SAP Systems in Aerospace & Defense: A Unified Enterprise Risk Strategy: Onapsis' Mariano Nunez and RTX's Anand Kotti discuss the journey of developing a unified picture and real-time visibility into their SAP landscape. * Impact 20: Smarter Incident Response with Onapsis and Microsoft Sentinel for SAP: A look at how the collaboration with Microsoft streamlines SAP threat detection and response. * Pre-Conference Deep Dive: A two-part intensive session, "Cybersecurity for SAP: Understanding and Preventing Real Attacks to SAP Applications," led by Juan Perez-Etchegoyen, Onapsis CTO and co-author of SAP Press Best Seller, "Cybersecurity for SAP," to learn more about this event, visit his speaker page. Attendees are invited to visit the Onapsis booth (#430) for live demonstrations of the Onapsis Platform, including its latest capabilities in vulnerability management and threat detection for RISE with SAP and S/4HANA. For more information about Onapsis at SAPinsider Las Vegas 2026 or to schedule a private meeting with the executive team, please visit this Onapsis SAPinsider event page. About Onapsis Onapsis is the global leader in SAP cybersecurity and compliance, helping the world's leading organizations reduce business risk, protect revenue, and keep critical operations running as they accelerate their SAP Cloud and AI initiatives. Built for and by SAP defenders, the SAP-endorsed Onapsis Platform enables Cybersecurity and SAP teams to proactively prevent breaches, accelerate audits, and respond faster to threats across RISE with SAP, S/4HANA Cloud, and hybrid environments. Powered by intelligence from the Onapsis Research Labs, Onapsis delivers rapid time to value, measurable risk reduction, and the confidence enterprises need to innovate faster.

Business Wire
Jan 28th, 2026
Onapsis appoints three executives to accelerate SAP cybersecurity growth and partner expansion

Onapsis, a leader in SAP cybersecurity and compliance, has appointed three executives to strengthen its go-to-market operations: Mark Francetic as Global Head of Partners & Alliances, John LoVerme as Head of North America Sales, and Nadine Rahman as Head of International Go-To-Market. Francetic brings over 25 years of experience building alliances across cloud and cybersecurity markets, most recently serving as SVP of Global Alliances at Saviynt. LoVerme previously led global sales at Prevalent through its acquisition by Mitratech in 2024. Rahman brings more than 20 years of global leadership experience across industrial automation and the SAP ecosystem. The appointments follow increased demand for SAP security solutions, driven by a wave of zero-day vulnerabilities in 2025. Onapsis has raised $295 million to date and recently expanded partnerships with CrowdStrike and Microsoft.

Help Net Security
Sep 25th, 2025
Onapsis enhances SAP security with latest platform updates

Onapsis announced updates to its Onapsis Platform, including the launch of three new capabilities: the SAP Notes Command Center, Rapid Controls for Dangerous Exploits, and Alert on Anything for SAP Business Technology Platform (BTP).

ERP News
Sep 25th, 2025
Onapsis Raises the Bar for SAP Security with Major Platform Enhancements

Onapsis has rolled out major updates to its SAP Application Security Platform, introducing the SAP Notes Command Center, Rapid Controls, and new BTP monitoring features.

INACTIVE