Lead the end to end implementation of SAP Cloud IAG including setup configuration and integration with SAP and non SAP systems
Configure and customize IAG modules
Access Request
Role design
Access Analysis
Privileged Access Management
User Access Review Campaigns UAR
Additional IAG activities
Design and implement integration of SAP Cloud Identity Services Identity Authentication IAS and Identity Provisioning Service IPS with SAP Cloud IAG
Set up and manage IAG Bridge for integration with on premise SAP GRC Access Control where needed
Assist in mapping connectors to various applications like S4HANA ECC SuccessFactors Concur Ariba SAP BTP etc
Configure provisioning workflows approval matrices and automated access rules
Develop and maintain standard operating procedures SOPs and support documentation for IAG operations
Troubleshoot integration issues between IAG and connected systems
Perform Periodic reviews UAR Campaigns and adjust access based on business needs
Designing building and implementing SAP Security Authorisation solutions
Design and manage SAP security roles profiles and authorizations for SAP environments including ECC S4HANA Fiori BW SRM CRM Solman HCM etc
Lead the implementation configuration of SAP GRC Access Control including the following activities
Configure and manage rule sets for SOD risk analysis across on premise environments
Define and implement business roles and access governance policies
Configure MSMP workflows and notifications for user provisioning access requests and role design
Perform risk assessments remediation of access violations and continuous improvement initiatives in SoD and security controls
Support automated control monitoring and audit functions for SAP business processes and mitigate financial and operational risks
Conduct training sessions and knowledge transfer for business stakeholders and support teams
Stay updated on the latest trends in SAP security GRC IAG and cloud technologies recommending improvements to systems and processes
5 years of experience in SAP Security and SAP GRC Access Control strong expertise required
2 years of hands on experience in implementing and managing SAP Cloud IAG
Deep understanding of Identity and Access Management IAM concepts
Practical experience with
SAP IAG setup and administration
SAP IASIPS integration
IAG Bridge configuration
Customizing Access Request Forms and Workflows
Rule Set management and SOD risk analysis
User Access Review Campaigns UAR configuration and management
SAP SaaS applications security SuccessFactors Ariba Concur
Strong knowledge of SAP Fiori SAP S4HANA security concepts
Good understanding of audit compliance and SOX controls related to SAP Security
Familiarity with SAP Business Technology Platform BTP security configurations and integration with on premise systems
Strong analytical and troubleshooting skills
Excellent communication skills to interact with technical and business stakeholders
PFB JD for cloud security:-
Job Overview
We are seeking an experienced SAP Cloud security consultant with exposure on BTP & Cloud identity Services (IAS/IPS) for the below requirement.
1. Migration of identity authentication from BTP Neo to BTP Cloud Foundry.
2. Migrate from Basic authentication for Onboarding (External users) within SuccessFactors to Cloud identity services (IAS/IPS).
Required Skills
- Valuable hands-on experience with SAP BTP architecture, specifically handling both Neo and Cloud Foundry environments.
- Deep technical knowledge of SAP Cloud Identity Services (IAS) and Identity Provisioning Service (IPS).
- Configuring SuccessFactors security settings, API permissions, and communication arrangements.
- Prior experience executing successful Neo-to-Cloud Foundry platform migrations is an added advantage.
Key Responsibilities
- Transition Cloud identity services from the SAP BTP Neo workplace to the BTP Cloud Foundry environment.
- Replace existing Basic Authentication for external users in SuccessFactors with modern single sign-on (SSO) and federation via SAP Identity Authentication Service (IAS).
- Configure SAP Identity Provisioning Service (IPS) and setting up trust configuration between SuccessFactors, IAS, and BTP CF.
- Configure Corporate IDP and MFA with IAS tenant to avoid local authentication.
- Modify Transformation logic and conduct end-to-end testing for successful user replication.