Onapsis has been operating since 2009 in a niche that matters more than most people realize: SAP and ERP application security. The attack surface is real - these systems run payroll, supply chains, financials - and Onapsis Research Labs has surfaced more than 1,000 zero-day vulnerabilities across that surface. The U.S. Department of Homeland Security has relied on their findings. That's the threat model: business-critical applications that weren't built for the modern threat landscape, now exposed to attackers who understand their value.
The Onapsis Platform covers vulnerability management, threat detection and response, change assurance, and continuous compliance for SAP, Oracle, and other SaaS enterprise applications. The technical domains span deep ERP security work - think ABAP-level analysis, misconfiguration detection, and real-time threat intelligence mapped to actual exploit chains in production environments. This is not generic endpoint tooling; it's specialized, protocol-aware, and built for systems where downtime means stopped factories or failed financial closes.
The client base skews heavy-industry and Fortune-scale: roughly 300 organizations, including 20% of the Fortune 100, six of the top ten automotive companies, and three of the top ten oil and gas firms. The engineering footprint runs through Boston (HQ), Heidelberg, Buenos Aires, and Bucharest - a distributed operation that suggests follow-the-talent hiring across security research and platform engineering. If you want to work on infrastructure that attackers are actively targeting and most security tools barely understand, this is the stack.






