
SAP Security Lead
Posted Jul 25

Posted Jul 25
This is a fully remote position, open to applicants in United States.
• Oversee SOX walkthrough activities as the primary Subject Matter Expert (SME) for all SAP ITGC controls, creating evidence packages for both internal and external auditors (e.g., Deloitte, PwC, KPMG).
• Manage and address audit observations; ensure continuous auditor approval across review cycles.
• Establish structured SOX audit readiness frameworks, supporting AuditBoard or similar Governance, Risk, and Compliance (GRC) platforms.
• Administer SAP GRC Access Control, including Access Request Management, Role Management, and Emergency Access Management (Firefighter).
• Develop and automate quarterly User Access Review (UAR) programs with approval workflows and escalation procedures for role owners.
• Enhance and sustain CPGRC or SAP GRC rulesets encompassing custom Z-transactions and Fiori applications for thorough Segregation of Duties (SoD) monitoring.
• Design and implement SAP security roles across S/4HANA, SAP Cloud Products, and PI/PO Java systems.
• Apply SAP Best Practices, IT governance standards, and risk management principles in all role designs.
• Execute SU25 and PFCG role modifications during system upgrades and changes in the landscape.
• Create detailed roles for Technical Administrators, Developers, Power Users, and Business Users.
• Implement and manage System IDs and service accounts utilizing GRC AC workflows.
• Assist with SAP system upgrades, landscape migrations, and security initiatives for cloud platforms.
• Collaborate with Basis, Functional, Audit, and Business teams throughout the Software Development Life Cycle (SDLC).
• Design and conduct SAP training programs and internal workshops to enhance organizational capabilities.
• Provide comprehensive documentation and knowledge transfer to ensure operational continuity.
• Over 12 years of experience in SAP Security and Basis, with numerous full-lifecycle implementations.
• Proven leadership experience as an SAP Security Lead on large-scale enterprise initiatives.
• Practical expertise with GRC Tools such as CPGRC, SAP GRC Access Control (Versions 10.x / 12.x), including ARM, EAM, UAR, and BRM.
• Extensive knowledge of SAP HANA Security, S/4HANA role architecture, and SAP Fiori authorization concepts.
• Strong comprehension of SOX ITGC controls, Segregation of Duties (SoD) principles, and requirements for audit evidence.
• Experience with S/4HANA upgrades.
• Proficient in PFCG, SU25, SUIM, and other related SAP security administration tools.
• Acquainted with SAP Cloud security and authorization group design.
• Medical
• Dental
• Vision
• Life insurance
• Disability insurance
• Vacation
• 401k
• Equity program
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.