SAP Security and GRC Access Control
Skills
About the role
SAP Security and GRC Access Control Specialist/Senior
We are seeking a highly skilled SAP Security and GRC Access Control Specialist to join our IT Security & Compliance team. This role is responsible for designing, implementing, and maintaining secure access across SAP systems, ensuring alignment with internal control frameworks, regulatory compliance (e.g., SOx), and best practices in identity and access governance.
Key Responsibilities
support the manage SAP user access process, roles, and authorizations across SAP environments (ECC, S/4HANA, BW, Fiori, etc.).
Design and maintain security roles in line with segregation of duties (SoD) and least privilege principles.
Operate and optimize SAP GRC Access Control components (ARA, BRM, CUP, EAM).
Perform risk analysis, access request workflow configuration, and firefighting management.
Support SOx audits, providing evidence and remediation plans for access-related findings.
Collaborate with business owners, internal auditors, and IT teams to define and enforce access governance standards.
Monitor SAP security logs and perform regular reviews of sensitive access and elevated privileges.
Contribute to the continuous improvement of SAP security policies, procedures, and role design methodology.
Assist in the delivery of SAP security controls during projects, system changes, or M&A integrations.
Provide training and support to users and stakeholders on access requests and GRC workflows.
It would be a significant advantage if the candidate possesses advanced knowledge of Salesforce access management as well.
Qualifications
Bachelor’s degree in Information Technology, Computer Science, or a related field.
Minimum 7-10 years of experience in SAP Security and GRC Access Control.
Strong knowledge of SAP authorization concepts (PFCG), role design, and user administration.
Hands-on experience with SAP GRC Access Control (especially ARA and EAM).
Understanding of compliance requirements such as SOx, GDPR, and ITGC controls.
Familiarity with audit processes and remediation practices.
Strong analytical, communication, and problem-solving skills.
SAP certifications (e.g., SAP Certified Technology Associate – System Security Architect or GRC Access Control) are an asset.
Preferred Skills
Experience with S/4HANA security concepts, including Fiori and HANA DB authorizations.
Exposure to other GRC tools or Identity Management platforms.
Project experience in SAP security design, migrations, or role redesign.
Ability to work in a global, multicultural environment.
More than 7 years' experience
Fluent in English
Questions about this role
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.