Role: SAP Security Architect
Location: US Remote
Job Description:
We are seeking a senior SAP S/4HANA Security Architect to lead the security workstream for our brownfield migration. This person will own security impact analysis, role redesign, Fiori and HANA security implementation, and SoD/risk management using Security Weaver (Pathlock) as the primary governance tool. Experience with SAP GRC Access Control is also acceptable where Security Weaver exposure is limited.
Core Requirements (Non-Negotiable)
Minimum 2–3 full lifecycle ECC → S/4HANA brownfield migration projects (hands-on conversion experience).
Direct, hands-on execution of SU25 (Phases 1–4) and role retrofit activities during conversion.
Fiori security implementation experience: catalogs, groups, business roles, OData activation, SICF.
Enterprise role redesign and remediation at scale (analysis and remediation of 1,000+ roles preferred).
SAP Readiness Check and Simplification Item Catalog impact analysis experience.
Hands-on experience with Security Weaver (Pathlock) OR SAP GRC Access Control for SoD analysis, simulation, remediation, and reporting.
Strong understanding of SoD rule design and risk mitigation strategy during ECC → S/4 transitions.
Key Responsibilities
Lead SAP security strategy and execution for ECC → S/4HANA transformation (brownfield conversion).
Perform role impact analysis, cleanup, and remediation; execute SU25 conversion steps and validate role behavior in S/4.
Design and implement a Fiori-first security model (catalogs, groups, business roles) and secure OData/SICF services.
Configure and manage Security Weaver (Pathlock) controls; alternatively align SAP GRC rule sets where applicable.
Migrate SoD rule sets and control frameworks from ECC to S/4; define interim compensating controls.
Conduct workshops with functional teams (FI/CO/MM/SD/EWM), Basis, Development, and Audit to validate security models.
Support cutover, security testing, and post-go-live authorization validation and stabilization.
Preferred Qualifications
10+ years of SAP Security experience (ECC and S/4HANA).
Proven track record in 2+ ECC → S/4HANA brownfield conversions.
Experience with Security Weaver (Pathlock) strongly preferred.
SAP GRC Access Control experience in complex enterprise environments.
Experience working in SOX/ITGC-regulated environments and preparing audit evidence.
Strong communication skills and ability to lead cross-functional workshops.
SAP Security experience across BI/BW, including analysis authorizations and reporting security.
SAP Security experience with EWM and GTS strongly preferred.
Experience with SAP BTP security, including IAS/IPS, role collections, trust/SSO, and hybrid cloud/on-premise environments.