SAP GRC  Security

People Prime Worldwide

Job Summary

We are looking for an experienced SAP GRC Security Consultant with strong expertise in SAP GRC Access Control and SAP Security. The candidate will be responsible for designing, implementing, configuring, and supporting SAP security and GRC solutions across SAP ECC and S/4HANA environments.

The role will focus on Access Risk Analysis, Access Request Management, Emergency Access Management, Segregation of Duties, role design, user access management, workflows, compliance, and audit support.

Key Responsibilities

Implement, configure, and support SAP GRC Access Control solutions.

Manage GRC Components Including

Access Risk Analysis (ARA)

Access Request Management (ARM)

Emergency Access Management (EAM / Firefighter)

Business Role Management (BRM)

User Access Review (UAR)

Design, configure, and maintain SoD rules, risk rulesets, functions, actions, and permissions.

Perform user-level and role-level risk analysis and identify critical access and SoD conflicts.

Support risk remediation through role redesign, access removal, and mitigating controls.

Configure and manage MSMP workflows and BRF+ rules for access request approvals.

Configure and maintain Firefighter IDs, owners, controllers, assignments, and log reviews.

Design and maintain SAP security roles including single, composite, derived, business, and Fiori roles.

Perform SAP user administration, provisioning, de-provisioning, role assignments, and validity management.

Troubleshoot authorization issues using tools such as SU53, ST01, STAUTHTRACE, SUIM, and SM20.

Support SAP ECC, S/4HANA, Fiori, and related SAP applications.

Conduct periodic access reviews and support user access certification activities.

Support internal and external audits, SOX/ITGC compliance, and provide audit evidence.

Analyze security requirements and work with business and functional teams to implement appropriate access controls.

Monitor GRC interfaces, connectors, synchronization jobs, and provisioning processes.

Prepare technical documentation, security procedures, risk reports, and operational runbooks.

Participate in SAP GRC implementations, upgrades, enhancements, and production support activities.

Required Skills

5+ years of experience in SAP Security and SAP GRC.

Strong hands-on experience with SAP GRC Access Control 10.x/12.x.

Expertise in ARA, ARM, EAM/Firefighter, BRM, and UAR.

Strong understanding of Segregation of Duties (SoD) and access risk management.

Experience in configuring GRC workflows, MSMP, and BRF+.

Strong SAP Security and authorization concepts.

Experience with SAP role design and authorization management.

Hands-on experience with SU24, SU53, SUIM, ST01, STAUTHTRACE, and PFCG.

Experience with SAP ECC and/or S/4HANA security.

Good understanding of SAP Fiori security and authorization concepts.

Experience with Firefighter ID setup, monitoring, and log review.

Knowledge of access provisioning and user lifecycle management.

Strong understanding of audit and compliance requirements.

Good to Have

Experience with SAP GRC Process Control (PC) and/or Risk Management (RM).

Knowledge of SAP BTP security.

Experience with SAP IAS/IPS or SAP Identity Management.

Exposure to S/4HANA transformation or migration projects.

Knowledge of SOX, ITGC, GDPR, and other compliance frameworks.

SAP GRC / SAP Security certification.

Experience working in global SAP landscapes.

How to apply

To apply for this job you need to authorize on our website. If you don't have an account yet, please register.