Salary : 85-99LPA
Role Overview :
We are seeking an experienced SAP Security and GRC professional to lead the SAP Authorizations function. You will be responsible for designing, maintaining, and governing SAP role concepts across ECC, S/4HANA, BW/4HANA, and cloud platforms. This is a hands-on leadership role requiring deep technical knowledge of SAP security combined with robust stakeholder and compliance management skills.
Key Responsibilities :
SAP Roles & Authorization Management :
- Design and maintain SAP roles Single, Composite, Derived, and AGR-based roles.
- Implement authorization concepts aligned with business requirements.
- Manage user administration (SU01), role transports, and authorization troubleshooting.
- Perform SU53, SU24, ST01, SUIM, and authorization trace analysis.
- Manage security for SAP ECC, S/4HANA, BW/4HANA, and SAP Fiori.
- Design and maintain Single, Composite & Derived roles using PFCG.
- Support S/4HANA Fiori security including Catalogs, Groups, Spaces & Pages.
- Implement security best practices and audit controls.
- Enforce least-privilege and secure role design principles.
Cloud Identity & Integration :
- Manage SAP Cloud Identity Authentication Service (IAS) and Identity Provisioning Service (IPS).
- Manage SAML/OAuth integrations with SAP BTP and cloud applications.
SAP GRC Access Control :
- Administer SAP GRC Access Control modules : ARA, ARM, BRM, and EAM.
- Perform SoD risk analysis and implement mitigation controls.
- Configure and maintain GRC rule sets.
- Manage Firefighter IDs and monitor EAM logs.
- Configure and support access request workflows and approval configurations.
- Conduct periodic access reviews and compliance reporting.
- Integrate SAP systems with GRC Access Control.
Additional Responsibilities :
- Deputy for the SAP Security Architect and other SAP Technology colleagues as required.
- Maintain up-to-date technical knowledge to drive continuous improvement aligned with IT strategy.
- Perform additional duties commensurate with the role as directed by management.
Required Qualifications :
- 5 years of hands-on SAP Security & GRC experience.
- Strong expertise in SAP Roles & Authorizations with PFCG role design methodology.
- Proven experience with SAP GRC Access Control.
- Experience with SAP Cloud Identity Services (IAS/IPS).
- Hands-on experience with S/4HANA and SAP Fiori authorizations.
- Strong knowledge of SoD controls and compliance frameworks.
- Experience integrating SAP with Active Directory / Azure AD.
- Understanding of SAP BTP security concepts.
- Experience in at least one S/4HANA implementation project.
- Experience in global, multi-system SAP environments.
- Strong English proficiency (spoken and written); German language skills are a significant advantage.
- Excellent communication skills, both technical and business-oriented.
- Strong analytical and problem-solving abilities; self-organized and result-oriented.
Preferred / Beneficial :
- SAP Security or GRC Certification.
- SAP BTP or Cloud Identity Certification.
- Experience in the manufacturing industry.
Tech Stack :
- SAP Roles & Authorizations Administration
- SAP GRC Access Control
- SAP Cloud Identity Services (IAS/IPS)
- SAP BTP
- SAP Cloud ALM
- PFCG, SoD Controls
- Azure AD Integration
📌 Manager - SAP Authorization & Security (India)
🏢 Kansoft
📍 India