Warm Greetings!!
Urgent hiring in BIG6 for Gurugram Location.
Role:-SAP Security and GRC
Senior Associate
Exp-5+yrs
Budget-15LPA
Supervisor
Exp-8+yrs
Budget-25LPA
Contract to Hire Prospect with BIG6
6 Months but Extendable
Note:-E2E Implementation experience is mandatory.
About the Role
We are seeking an experienced SAP Security, GRC, and Controls Integration professional to help lead and scale the SAP Security and GRC capability within the BARS practice. The role will involve leading client engagements, overseeing delivery quality, developing team capability, supporting practice growth, and working closely with U.S. and India leadership.
The ideal candidate should be able to think strategically about risk, controls, and access governance, while also being hands-on and delivery focused. This role requires experience scoping, supervising, and executing SAP implementation risk assessments, SAP Security, SAP GRC, segregation of duties, controls transformation, process automation, data analytics, continuous controls monitoring, and managed services engagements.
Qualification and Minimum Entry Requirements
Bachelors or masters degree in Engineering, Technology, Information Systems, Business, Finance, or a related discipline.
5+ years of professional experience in SAP Security, SAP GRC and IT controls.
Prior experience with a public accounting firm, large consulting organization, or global delivery environment is preferred.
Deep expertise in SAP Security across SAP ECC and SAP S/4HANA, including authorization concepts, role design, authorization object analysis, access troubleshooting, Fiori authorizations, and access remediation.
Strong hands-on experience with SAP GRC Access Control, including ARA, ARM, EAM, BRM, MSMP workflows, BRF+, connectors, synchronization jobs, ruleset maintenance, risk analysis, and mitigation controls.
Practical experience with SAP GRC Process Control, including control design, automated monitoring, business rules, data sources, control testing, and continuous controls monitoring is a plus.
Experience leading complex SAP Security and GRC engagements across implementation, transformation, assessment, optimization, controls, and managed services programs.
Experience managing delivery teams, reviewing work products, mentoring resources, and building technical capability within SAP Security and GRC teams.
Exposure to other GRC, identity governance, access management, compliance, control monitoring,
or risk management tools will be an added advantage.
Exposure to SAP Joule, SAP BTP, SAP IAG, SAP Cloud Identity Services, automation, analytics, AI-enabled controls, and emerging SAP technologies would be beneficial.
Experience with SAP HANA, BW/BI, Ariba, IBP, MDG, SuccessFactors, BDC, SAC, or other SAP public cloud and integrated applications will be preferred.
Experience with SOX, COSO, COBIT, ISO, NIST, HIPAA, FDA, and other IT controls methodologies and frameworks is a plus.
Strong project management, stakeholder management, communication, analytical thinking, problem-solving, and leadership skills.
- Demonstrated ability to work in high-pressure client delivery environments while managing competing priorities and maintaining quality standards.
- Relevant certifications such as SAP Security, SAP GRC, CISA, CRISC, CISSP, CISM, or equivalent certifications will be preferred.
Position and Key Responsibilities
Help lead the SAP Security and GRC team within the Business Application Risk Solutions practice and support capability growth across delivery, people development, methodologies, and market-facing initiatives.
Lead end-to-end SAP Security and GRC engagements across implementation, transformation, assessment, optimization, controls transformation, and managed services programs.
Manage SAP Security workstreams in SAP ECC and SAP S/4HANA environments, including requirements gathering, solution design, role build, testing, deployment, cutover, hypercare, and post-go-live support.
Lead SAP Security design and access governance activities, including role design, role redesign, authorization troubleshooting, Fiori authorizations, SoD analysis, sensitive access reviews, emergency access management, user access reviews, and access remediation.
Lead SAP GRC Access Control implementation and enhancement activities across ARA, ARM, EAM, BRM, MSMP workflows, BRF+, ruleset design, risk analysis, mitigation controls, connectors, synchronization jobs, and related GRC configuration activities.
Support SAP GRC Process Control initiatives,
including control framework mapping, risk and control configuration, automated monitoring, business rules, data sources, control testing, and continuous controls monitoring.
Translate business process, compliance, audit, and internal control requirements into practical SAP Security and GRC solutions aligned with client risk and regulatory requirements.
Advise clients on SAP Security and access governance considerations across integrated SAP landscapes, including Fiori, HANA, BW/BI, BTP, Ariba, IBP, MDG, SuccessFactors, and other SAP applications, as applicable.
Manage client stakeholders, engagement plans, project timelines, issue resolution, deliverable quality, and team performance across multiple concurrent engagements.
Provide a first-choice advisor experience to clients by delivering practical recommendations, maintaining strong client relationships, and ensuring high-quality engagement outcomes.
Develop reusable methodologies, solution accelerators, delivery templates, training materials, knowledge repositories, and other practice assets to support consistent and scalable delivery.
Maintain awareness of emerging SAP technologies, including SAP Joule, SAP BTP, SAP IAG, SAP Cloud Identity Services, automation, analytics, and AI-enabled risk and controls solutions.
Ensure engagement documentation, deliverables, and work products are compliant with firm quality standards and demonstrate sound professional judgment.
Experience working with a team to provide services to numerous clients simultaneously.
- Must exhibit and have demonstrated excellent organization and project management, communication, interpersonal, and team collaboration skills.
Professional Conduct and Firm Expectations
Successfully integrate the strategy and core values of the firm.
Heighten the firm brand by demonstrating thought leadership and embracing the firm's marketing campaigns and related programs supported by the firm.
Professionally presents themselves at all times at the office and the clients meetings. This includes but is not limited to appearance, communication, and actions.
Exercise professional skepticism, maintain confidentiality, and adhere to applicable professional standards, firm policies, and code of ethics while delivering client engagements.
Interested Candidates please share CV on
[email protected] or whatsApp CV on (phone hidden)
📌 SAP GRC and Security Consultant (Gurugram)
🏢 Gudah Consultants
📍 Gurugram