Job Description: This role is for an SAP GRC Engineer / Admin
The following details required and desired skills for this position:
SAP GRC Suite Expertise
• Business Process, Risk/Ruleset management, and Process Controls Development and Management
• Hands-on experience of leading the business through risk analysis and remediation
• Deep knowledge of SAP GRC components: Access Control (AC), Process Control (PC), Risk Management (RM), and Audit Management (AM)
• Experience configuring and maintaining GRC solutions (role design, SoD rules, workflow setup, remediation)
Access Control (AC)
• Designing, testing, and maintaining composite and single roles
• Managing SoD matrices, risk analysis, and remediation projects
• Using tools such as Access Risk Analyzer (ARA), Role Manager, and Business Role Builder
Engineering Methodology
• Experience with standard engineering process
• Background in doing requirements discovery and translation from business requirements to technical requirements / deliverable
• Experience with software systems design
Process Control & Risk Management
• Building internal controls, monitoring plans, and audit workpapers
• Configuring continuous control monitoring (CCM) and KPI dashboards
• Conducting risk assessments and documenting control effectiveness
Compliance & Audit
• Understanding of regulatory frameworks (SOX, GDPR, ISO 27001, FISMA, etc.)
• Ability to generate audit‐ready reports and evidence
• Coordination with internal and external auditors
SAP Basis & Integration
• Fundamentals of SAP NetWeaver, S/4HANA, and system landscape management
• Transport management (CTS) for GRC objects
• Integration with SAP Identity Management (IdM) and third‐party IAM solutions
Technical Tools & Scripting
• Proficiency with GRC configuration tools (PFCG, GRAC, GRPC, GRRM)
• Basic ABAP debugging for security‐related enhancements
• Automation scripts (PowerShell, Python, Bash) for user provisioning and report generation
Security Incident Management
• Monitoring GRC alerts, handling violations, and executing remediation steps
• Collaboration with SAP Basis and IT security teams for patches and hardening
Project & Change Management
• Experience leading GRC implementation or upgrade projects (Agile or Waterfall)
• Managing change requests, documentation, and stakeholder communication
Data Analysis & Reporting
• Building regular SoD, risk, and compliance reports (using SAP GRC reporting, Excel, Power BI)
• Analyzing large user‐role datasets to identify anomalies
Communication & Training
• Clear documentation of GRC policies, procedures, and role designs
• Conducting training sessions for functional users and auditors
• Liaising with business owners, security teams, and IT partners
Soft Skills
• Strong analytical and problem‐solving abilities
• High attention to detail and accuracy
• Proactive attitude and willingness to stay current with GRC best practices and regulatory changes