Competencies: 8+ years experience
SAP Governance Risk & Compliance (GRC) : Access Controls
Job Description - Senior SAP GRC Consultant (8+ Years)
Senior SAP GRC Access Control Consultant (SAP Security & Compliance)
Experience: 8+ Years
Location Onsite - Jersey City
____
Job Summary
We are seeking an experienced SAP GRC Access Control Consultant with 8+ years of SAP Security and GRC implementation experience to lead the end-to-end implementation of SAP GRC Access Control across our on-premise SAP landscape.
The consultant will be responsible for implementing and configuring SAP GRC Access Control modules, integrating them with SAP ECC, SAP SRM, and SAP BI/BW systems, designing Segregation of Duties (SoD) rules, automating access management workflows, and ensuring compliance with internal and external audit requirements.
The ideal candidate should have completed multiple end-to-end SAP GRC implementations in large enterprise environments.
____
Key Responsibilities
SAP GRC Implementation
- Lead complete SAP GRC Access Control implementation.
- Gather business and security requirements.
- Conduct Fit-Gap Analysis.
- Prepare Solution Design Document.
- Configure SAP GRC environment.
- Perform system integration.
- Support testing and production deployment.
- Provide hypercare support.
____
GRC Access Control Modules
Hands-on implementation experience in:
- Access Risk Analysis (ARA)
- Emergency Access Management (EAM / Firefighter)
- Access Request Management (ARM)
- Business Role Management (BRM)
- User Provisioning
- Role Management
- Risk Management
- Compliance Reporting
____
SAP Security
Design and implement:
- Role Design Strategy
- Single Roles
- Composite Roles
- Derived Roles
- Organizational Level Security
- Authorization Objects
- SU24 Proposal Maintenance
- SU25 Upgrade Activities
- Role Optimization
____
Segregation of Duties (SoD)
Responsible for
- SoD Rule Set Design
- Risk Analysis
- Critical Access Analysis
- Critical Permission Analysis
- Mitigation Controls
- Risk Owners
- Control Owners
- Risk Remediation
- Periodic Risk Review
____
Access Management
Configure and automate
- User Access Request Workflow
- Role Approval Workflow
- Firefighter Workflow
- Provisioning Workflow
- Password Reset Workflow
- Role Owner Approval
- Business Owner Approval
- Security Team Approval
____
Firefighter (Emergency Access)
Configure
- Firefighter IDs
- Controllers
- Owners
- Log Review
- Firefighter Reporting
- Emergency Access Monitoring
____
Business Role Management
Design
- Business Roles
- Technical Roles
- Role Hierarchy
- Role Approval Process
- Role Lifecycle
- Role Ownership
____
Integration
Integrate SAP GRC with
- SAP ECC
- SAP SRM
- SAP BI/BW
- SAP NetWeaver AS ABAP
- SAP Solution Manager (preferred)
- LDAP / Active Directory (preferred)
____
Connectors
Configure GRC connectors for
Experience with
- RFC Connections
- Trusted RFC
- Plug-ins
- Connector Synchronization
____
Compliance
Support
- SOX Compliance
- Internal Audit
- External Audit
- User Access Review
- Quarterly Access Certification
- Compliance Reporting
____
Workflow Configuration
Hands-on experience configuring
- MSMP Workflow
- BRF+
- Approval Paths
- Multi-level Approval
- Escalation
- Notifications
____
Reporting
Develop reports for
- SoD Violations
- Critical Access
- Firefighter Usage
- User Access Review
- Risk Analysis
- Compliance Dashboard
____
Documentation
Prepare
- Functional Specification
- Configuration Documents
- Security Design
- Solution Design
- Test Scripts
- User Manuals
- Deployment Documents
____
Technical Skills
Must Have
- SAP GRC Access Control 10.1 / 12.0
- SAP ECC Security
- SAP SRM Security
- SAP BI/BW Security
- SAP NetWeaver Security
- SAP Authorization Concept
- Role Design
- SU01
- PFCG
- SU24
- SU25
- STMS
- Transport Management
- RFC Configuration
- MSMP Workflow
- BRF+
- Firefighter Configuration
- SoD Rules
- Access Risk Analysis
____
Preferred Skills
- SAP Solution Manager Integration
- SAP Identity Management (IDM)
- SAP Cloud Identity Services
- Active Directory Integration
- LDAP Integration
- SAP Fiori Security
- SAP Gateway Security
- SAML
- Single Sign-On (SSO)
- SAP Audit Log
- SAP Read Access Logging
____
Implementation Experience
Candidate must have completed
- Minimum 3 full-cycle SAP GRC Access Control implementations
- Multiple rollout/support projects
- Security redesign projects
- Audit remediation projects
- SoD remediation projects
____
SAP Landscape Experience
Mandatory experience with
- SAP ECC 6.0
- SAP SRM 7.0
- SAP BI/BW
- SAP NetWeaver
- SAP on-premise architecture
____
Audit & Compliance Experience
Experience supporting
- SOX Audits
- Internal Audit
- External Audit
- Segregation of Duties Review
- User Access Review
- Security Compliance
- Risk Assessment
____
Required Qualifications
- Bachelor''s degree in Computer Science, Information Technology, Engineering, or related field.
- 8+ years of SAP Security and GRC experience.
- At least 3 end-to-end SAP GRC implementations.
- Strong communication and stakeholder management skills.
____
Preferred Certifications
- SAP Certified Application Associate - SAP Access Control
- SAP Certified Technology Associate - System Security Architect
- SAP Security Certification (preferred)
____
Nice to Have
- Experience in Government or Public Sector implementations.
- Experience working with highly regulated environments.
- Knowledge of ITGC, COBIT, ISO 27001, and NIST security frameworks.
- Experience supporting SOC 1 / SOC 2 audits and compliance initiatives.
____
Key Deliverables
- SAP GRC Access Control implementation for ECC, SRM, and BI/BW.
- Connector configuration and integration across all SAP systems.
- SoD ruleset design and risk remediation.
- MSMP workflow configuration for access requests and approvals.
- Firefighter (EAM) setup and monitoring.
- Business role design and lifecycle management.
- User provisioning automation.
- Compliance dashboards and audit reporting.
- Knowledge transfer, documentation, and post-go-live support.
Diverse Lynx LLC is an Equal Employment Opportunity employer. All qualified applicants will receive due consideration for employment without any discrimination. All applicants will be evaluated solely on the basis of their ability, competence and their proven capability to perform the functions outlined in the corresponding role. We promote and support a diverse workforce across all levels in the company.