This role is for a SAP GRC Risk Assessment Analyst.
SAP / ERP Risk & Controls
• Risk‐assessment and design of SAP controls (access management, SoD, privileged access, configuration)
• Collaborate with functional & technical teams to identify, remediate, and monitor risks in FI, MM, SD, HR (and integrated modules)
• Implement and continuously improve automated & manual controls across SAP and connected systems
• Drive sustainable SAP‐audit remediation (vs. point‐in‐time fixes)
IT General Controls (ITGC) & Application Testing
• Plan, execute, and document ITGC testing (access, change, operations) and application‐control testing across the enterprise
• Maintain testing scripts, evidence collection, and test‐result sign‐offs
• Ensure testing aligns with SOX, GDPR, HIPAA, and other regulatory expectations
Engineering Methodology
• Experience with standard engineering process
• Background in doing requirements discovery and translation from business requirements to technical requirements / deliverable
• Experience with software systems design
Audit & Remediation Management
• Assist the Team with Internal Audit and external auditors (Big 4) during walkthroughs, testing, and issue resolution
• Translate audit findings into clear, risk‐based remediation plans with defined owners, timelines, and success criteria
• Track remediation progress and verify effectiveness of fixes
ERP Risk Governance & Oversight
• Maintain an up‐to‐date ERP risk register linked to enterprise risk appetite; quantify exposure and prioritize treatment
• Design and enforce a standardized ERP control framework (design, documentation, testing methodology)
• Provide oversight, challenge, and assurance on control design and operating effectiveness
Policy, Standards & Framework Development
• Develop, maintain, and enforce ERP‐specific policies, standards, and control frameworks
• Align policies with corporate GRC frameworks (nd regulatory requirements
• Conduct periodic policy reviews and updates
Stakeholder Communication & Influence
• Prepare and present risk‐posture, control‐effectiveness, and remediation status to senior leadership and business owners
• Translate technical risk concepts into business‐impact language to influence decision‐making
• Build strong relationships with IT, finance, and line‐of‐business partners
Technical SAP & Security Expertise
• SAP GRC (Access Control, SoD, ARA) configuration and maintenance
• SAP security administration (role design, provisioning, privileged‐access management)
• Understanding of SAP ERP application controls, integration points, and data flows
ITGC Technical Knowledge
• Access control, change‐management, and operations control design and testing
• Knowledge of SAP Basis impact on security (client administration, transports, patches)
Audit & Assurance Experience
• End‐to‐end audit engagement management (planning, fieldwork, reporting)
• Development of audit workpapers, evidence gathering, and audit‐finding remediation programs
• Interaction with regulators and external auditors on compliance matters
Regulatory & Compliance Acumen
• Deep knowledge of SOX Section 404, GDPR, CCPA, ITAR, and industry‐specific compliance frameworks
• Ability to map controls to regulatory requirements and produce compliance evidence
Consulting / Big‐4 Experience
• Advisory mindset with ability to assess client environments, propose risk‐based solutions, and drive change
• Experience delivering projects in matrixed, fast‐paced environments
Communication & Presentation Skills
• Write clear policies, procedures, and risk documentation
• Deliver concise executive briefings, dashboards, and risk scorecards
• Facilitate workshops and training sessions for technical and non‐technical audiences