Cyber - Sap Security and Grc Access & Process Control Manager

This role is for a Cyber - SAP Security and GRC Access & Process Control Manager at Deloitte. The primary responsibilities involve delivering SAP ECC and S/4 HANA security implementations and assessments, including end-user security and SAP GRC Access Control. The role requires extensive experience in SAP security, GRC Access Control, Segregation of Duties (SOD) risk analysis, and workflow management, as well as experience in designing and implementing security for SAP reporting and analytics solutions. The manager will also be responsible for leading workstreams, managing teams, and collaborating with stakeholders. Experience with data protection strategies and vulnerability scans is also required.

What you'd actually do

  1. As a Manager, you will be part of our SAP practice and will be responsible for delivering SAP ECC and S/4 HANA security implementations and assessments.
  2. Responsibilities will include assessment, design and implementation of end user security, and/or SAP GRC 10.x/12.0 Access Control.
  3. The teamOur Enterprise Security offering embeds security in all aspects of digital transformation by securing a client’s technical backbone while enabling secure digital transformation.
  4. Includes security architecture, secure development and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected products.

Skills

Required

  • SAP S/4 HANA Security and GRC Access & Process Control
  • SAP GRC 10.x/12.0 Access Control
  • SAP S/4 HANA security implementations
  • SAP GRC process control implementations
  • SAP S/4 HANA, Fiori, Ariba, IBP, BTP, BDC security
  • Security design workshops
  • Business end user and IT support roles
  • Fiori applications, Spaces and Pages concepts
  • SAP reporting and analytics solutions (SAP Business Objects, SAP BDC, SAP Cloud Analytics and BW/4HANA)
  • Collaborating with stakeholders
  • SAP GRC Access Request Analysis (ARA)
  • SAP GRC Access Request Management (ARM)
  • SAP GRC Emergency Access Management (EAM)
  • SAP GRC Business Role Management (BRM)
  • Segregation of Duties (SOD) ruleset
  • SOD risk analysis
  • GRC AC request workflows
  • SAP GRC Process Control design and configuration
  • Controls, risks, subprocesses, organizations, and assignments within SAP GRC Process Control
  • Automated/continuous controls
  • Continuous Control Monitoring (CCM)
  • Data protection strategies for regulatory controls (privacy, GDPR)
  • SAP UI masking tool
  • Executing vulnerability scans
  • Workstream lead experience
  • Team management and oversight

Nice to have

  • Previous consulting or Big 4 experience
  • CISSP, CISM, or CISA certifications
  • SAP identity and access governance (IAG)
  • Cloud security and cloud migrations
  • SAP business process controls
  • Data protection tools (NextLabs)
  • Vulnerability management tools (Onapsis)
  • Identity access management tools
  • Leading practices in SAP Security
  • Technical understanding of SAP configurations

What the JD emphasized

  • 8+ years of experience with SAP S/4 HANA Security and GRC Access & Process Control
  • Demonstrated delivery of three to five full cycle GRC Access Control implementation projects along with SAP S/4 HANA security implementations and at least two SAP GRC process control implementations
  • 8+ years of hands-on experience implementing security for SAP S/4 HANA, Fiori, Ariba, IBP, BTP, BDC security including requirement gathering, security design and deployment
  • 8+ years of experience in conducting security design workshops and designing, building, testing, and deploying business end user and IT support roles with In-depth knowledge on Fiori applications, Spaces and Pages concepts
  • 3+ years of experience in designing and implementing security for SAP reporting and analytics solutions such as SAP Business Objects, SAP BDC, SAP Cloud Analytics and BW/4HANA
  • 5+ years of experience in collaborating with various stakeholders (business process, development and organization change management workstreams, etc.) to gather business requirements for security
  • 5+ years of experience in designing, configuring and implementing SAP GRC Access Request Analysis (ARA), Access Request Management (ARM), Emergency Access Management (EAM), and Business Role Management (BRM)
  • 5+ years of experience in building and updating Segregation of Duties (SOD) ruleset, configuring ruleset in SAP GRC 12.0 systems and performing SOD risk analysis at user and role level
  • 5+ years of hands-on experience of GRC AC request workflows (e.g., Access Request Management)—request intake, approvals, risk checks, provisioning steps, and evidence trail
  • 3+ years of experience in SAP GRC Process Control design and configuration, Clear understanding of controls, risks, subprocesses, organizations, and assignments within SAP GRC Process Control.
  • 2+ years of experience with the concept of automated/continuous controls and how PC can support monitoring using Continuous Control Monitoring (CCM) - creating business rules, data sources, and scheduling jobs to monitor controls and risks
  • 3+ years of experience with data protection strategies for regulatory controls like privacy, GDPR etc. including implementation of SAP UI masking tool
  • 4+ years of experience with executing vulnerability scans, analyzing the scan results and providing recommendations
  • 3+ years of prior workstream lead experience (plan/budget/staffing, status reporting, team management, stakeholder management)
  • 3+ years of experience with managing and providing oversight for team