Job Summary
Job Summary
We are looking for an experienced SAP GRC Lead to lead the design, implementation, and support of SAP Governance, Risk, and Compliance (GRC) solutions. The role will ensure strong access controls, regulatory compliance, and effective risk management across SAP landscapes, while working closely with Security, IT, Audit, and Business stakeholders.
Key Responsibilities
Key Responsibilities
- Lead end‑to‑end implementation and support of SAP GRC Access Control.
- Design and manage:
- Risk Analysis & Remediation (RAR)
- Access Request Management (ARM)
- Emergency Access Management (EAM / Firefighter)
- Role-level and user-level SoD analysis
- Define and optimize SoD rule sets, risk libraries, and mitigating controls.
- Work closely with SAP Security teams on:
- Role design and remediation
- User provisioning and de‑provisioning
- Ensure compliance with internal controls, SOX, and audit requirements.
- Integrate SAP GRC with:
- SAP ECC and S/4HANA
- SAP Fiori
- HR systems for automated provisioning
- Support audits by providing:
- Access reviews
- Compliance reports
- Risk mitigation evidence
- Lead workshops with business, audit, and compliance teams.
- Define and enforce GRC governance models, policies, and best practices.
- Oversee testing, go‑live, and post‑go‑live support of GRC solutions.
- Manage and mentor offshore/onshore GRC teams.
- Act as the GRC SME and escalation point.
Skill Requirements
Primary Skills
- SAP GRC Access Control (AC)
- Risk Analysis & Remediation (RAR)
- Emergency Access Management (EAM / Firefighter)
- Access Request Management (ARM)
- Role Design & Segregation of Duties (SoD)
Secondary Skills
- SAP Security (ECC / S/4HANA)
- SAP GRC Process Control & Risk Management (nice to have)
- SAP Audit & Compliance
- Integration with SAP Security & HR
- Fiori & GRC Reporting
Required Skills & Experience
- Strong hands‑on experience with SAP GRC Access Control.
- Proven experience in:
- SoD analysis and remediation
- Firefighter access management
- Access provisioning workflows
- Strong understanding of SAP Security concepts.
- Experience with SAP ECC and/or S/4HANA systems.
- Experience leading GRC implementations or upgrades.
- Strong stakeholder management and communication skills.
Other Requirements
Good to Have
- Experience with SAP GRC Process Control (PC) and/or Risk Management (RM).
- Exposure to S/4HANA conversions and GRC remediation.
- Knowledge of regulatory frameworks (SOX, internal audit controls).
- SAP GRC or SAP Security certification.
- Experience in global rollouts or multi‑system landscapes.
Education
- Bachelor’s degree in Information Technology, Computer Science, Business, or a related field.