
SAP Security/GRC Expert – Access Control
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in New York.
• Conduct post-launch cleanup of the SAP GRC Access Control environment.
• Identify and address issues with broken or misconfigured workflows, including those requiring cross-organizational approval.
• Assess and resolve SoD concerns raised during internal reviews; document mitigating controls when remediation is not possible.
• Analyze and enhance role design, user provisioning, and access request workflows.
• Offer direct, hands-on knowledge transfer to the designated internal resource across all workstreams.
• Record remediation activities, design choices, and remaining risks for a seamless handoff.
• Highlight any additional scope identified during remediation for collaborative decision-making at the mid-engagement review.
• US Citizenship is mandatory.
• Must be available to work core hours in US Eastern Time.
• Senior-level practitioner with over 10 years of SAP Security experience, specifically in GRC Access Control (10.x or 12.x).
• Proficient in all GRC AC modules: Access Request Management (ARM), Business Role Management (BRM), Emergency Access Management (EAM/Firefighter), and Access Risk Analysis (ARA).
• Proven experience in resolving SoD conflicts and establishing mitigating controls.
• Strong background in SAP role design (single, composite, derived) and user provisioning.
• Familiarity with troubleshooting MSMP workflows and BRF+ rules.
• Comfortable operating in a post-go-live stabilization environment where scope is continuously revealed.
• Excellent written documentation and knowledge-transfer abilities; capable of teaching as well as delivering.
• Health insurance.
• 401(k) matching.
• Flexible work hours.
• Opportunities for professional development.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.