Reporting to:
IS Security Specialist
Mission Statement:
Responsible for the NAS SAP GRC and security operations and project delivery, governance, risk management and various internal control & audit requirements fulfilment.
Main Accountabilities and Duties:
1. SAP GRC and security operations
GRC Strategy & Implementation:Configure, implement, and maintain the SAP GRC Access Control suite (ARA, ARM, EAM, BRM) and Process Control modules.
Risk Analysis & Mitigation: Conduct access risk analysis (SoD), identify potential conflicts, and work with business stakeholders to remediate risks.
User Access Management: Oversee and operate the user access request process, user provisioning, de-provisioning, and role changes. Manage emergency access management (Firefighter) protocols.
Troubleshooting: Investigate and resolve complex security and authorization issues reported by users.
Security Design: Design, build, and manage SAP security roles and authorizations for a diverse environment including SAP ECC, EWM, Fiori, S/4 HANA and other SAP solutions.
Training & Documentation: Create and maintain detailed technical documentation, security policies, and procedures. Provide guidance and training to business users.
2. Fulfill ITGC, Internal Control & Audit, Compliance requirements
Ensure the existing security operations are fully compliant. Take responsibility in the various IT controls, audits and compliance requirements, ensure compliance with SOX, GDPR, and other relevant regulations. Working with Internal control to implement SoD ruleset and support business to understand and remediate SoD conflicts. Working with InfoSecurity and Audit Groups to facilitate strong controls around end user/system access.
3. Deliver Security Projects
Support SAP ERP team to delivery project for security part, including design authorization solutions, authorization implementation. Delivery security project e.g. SAP GRC or other systems.
Required Knowledge, Skills, Experience:
- Bachelor’s degree or equivalent
- Above 3 years of working experience in SAP GRC and authorization management via Operations or Projects.
- SAP GRC implementation & SOD knowledge is a MUST
- Structural thinking and proactive behavior is a MUST
- ITGC implementation experience or SAP functional knowledge is preferred
- Consulting firm experience in risk management or security project delivery preferred
- SAP certified PA preferred
- Fluent in Englis