10 Sep
|
HCLTech
|
Lucknow
Job Description
Experience
n
15+ years SAP experience with 10+ years in SAP Security & GRC and at least 5 years in Architect / Advisory roles.
n
Role Summary
n
We are seeking a highly experienced and dynamic SAP Security & GRC Architect to lead enterprise-wide SAP Security, Governance, Risk, and Compliance strategy initiatives for global customers. This role is not a support or administration position. The successful candidate will act as a trusted advisor Customer and business leadership teams, helping define security roadmaps, governance frameworks, target operating models, and transformation strategies across SAP landscapes.
n
The ideal candidate should possess deep expertise across SAP ECC, S/4HANA, SAP BTP, SAP Fiori, SAP GRC, Cloud Platforms, Identity Governance, and emerging SAP security technologies while being capable of translating business and regulatory requirements into scalable and secure SAP architectures.
n
Key Responsibilities
n
Security Strategy & Architecture
n
n
- Define enterprise SAP Security and GRC strategy aligned with business and cyber-security objectives.
n
- Design target-state SAP Security architectures for ECC, S/4HANA, RISE with SAP, SAP BTP, SAP SAC, Ariba, SuccessFactors, MDG, IBP and other SAP solutions.
n
- Develop security transformation roadmaps for SAP modernization programs.
n
- Lead SAP Security assessments, maturity reviews, and governance workshops.
n
- Establish SAP Security standards, policies, and enterprise design principles.
n
n
Governance, Risk & Compliance
n
n
- Define enterprise Segregation of Duty (SoD)
frameworks and risk strategies.
n
- Design and govern SAP GRC Access Control solutions (ARA, ARM, EAM, BRM).
n
- Establish SAP controls aligned with SOX, ITGC, GDPR, ISO27001, NIST, and internal audit requirements.
n
- Lead compliance and audit engagements with internal and external auditors.
n
- Provide strategic recommendations for risk reduction and governance optimization.
n
n
S/4HANA & Cloud Security
n
n
- Design security models for S/4HANA transformations and RISE with SAP environments.
n
- Define security architecture for SAP BTP services, cloud integrations, APIs, and extensions.
n
- Develop Fiori security concepts, catalog design strategy, and role architecture.
n
- Drive SAP Identity and Access Management transformation initiatives.
n
n
Advisory & Consulting
n
n
- Serve as Security Design Authority for customer programs.
n
- Conduct executive-level workshops with customer leadership.
n
- Translate regulatory requirements into practical SAP security controls.
n
- Provide thought leadership on industry trends, SAP roadmap direction, and emerging risks.
n
- Support RFPs, solutioning, estimations, due diligence, and customer presentations.
n
n
Operating Model & Governance
n
n
- Design enterprise SAP Security operating models.
n
- Establish governance structures, RACI matrices, and control ownership.
n
- Define KPIs, compliance reporting, and security health frameworks.
n
- Implement continuous improvement programs across SAP Security and GRC functions.
n
n
Leadership
n
n
- Mentor architects, leads, and security consultants.
n
- Build reusable frameworks, accelerators, and best practices.
n
- Collaborate with Cyber Security, IAM, Audit, Risk, Infrastructure, and SAP Platform teams.
n
n
Required Qualifications
n
n
- 15+ years SAP experience with 10+ years in SAP Security & GRC and at least 5 years in Architect / Advisory roles.
n
- Deep expertise in SAP authorization concepts (PFCG, SU24, org-level design), Fiori/S/4HANA catalog- and space-based security, and HANA DB security.
n
- Strong hands-on background (past or current) with SAP GRC Access Control 10.x/12.x (ARA, ARM, EAM, BRM) and exposure to SAP IAG / Cloud Identity services.
n
- Proven experience designing SoD rulesets, role architectures, and access governance models at enterprise scale.
n
- Demonstrated experience in at least one full-cycle S/4HANA security design (greenfield, brownfield, or bluefield).
n
- Solid understanding of audit and compliance frameworks: SOX, ITGC, ISO 27001, NIST; comfortable owning audit conversations.
n
- Ability to communicate complex security concepts to executives and non-technical stakeholders; solid documentation and presentation skills.
n
📌 SAP Security & GRC Architect (Strategic Design & Transformation) (Lucknow)
🏢 HCLTech
📍 Lucknow