24 Sep
|
Duobridge
|
Chennai
SAP GRC
Location: Chennai
Department: GPO Reports to: GPO – Process Owner
About The Role
We are seeking an experienced SAP GRC resource to manage and strengthen our SAP Governance, Risk, and Compliance framework. The ideal candidate will bring hands-on expertise in SAP access controls, segregation of duties (SoD) risk analysis, and IT general controls (ITGC), combined with a strong background in IT audit. This role is critical to ensuring our SAP environment is secure, compliant, and aligned with internal control and regulatory requirements.
Key Responsibilities
- Design, configure, and maintain SAP GRC Access Control, including access risk rulesets, mitigating controls, and remediation workflows.
- Perform periodic reviews of SAP user access, role assignments, privileged access, and emergency access management (Firefighter) to identify and remediate segregation of duties (SoD) conflicts.
- Review and monitor SAP access controls across key business cycles (procure-to-pay, order-to-cash, user access management) to ensure compliance with company policies and industry standards.
- Assess IT general controls (ITGC), application controls, and infrastructure controls within SAP and related environments, benchmarking against frameworks such as NIST.
- Partner with IT and Business stakeholders to investigate audit findings, track remediation progress, and drive continuous improvement in control effectiveness.
- Support external and internal audit engagements, including planning, fieldwork, reporting, and issue follow-up for SAP-based systems.
- Evaluate third-party service reports (e.g., ISAE 3402/SOC reports) for outsourced IT support functions.
- Conduct vulnerability assessments and support broader IT security reviews in collaboration with the security team.
- Develop and deliver training to key users, internal auditors, and auditees on GRC processes,
tools, and controls.
- Maintain and enhance audit issue tracking systems, ensuring workflows reflect current audit practices.
Required Qualifications
- Bachelor's degree in Information Systems, Computer Science, Accounting, or a related field.
- Minimum 8–12 years of combined experience in IT audit (internal and/or external) with a strong focus on SAP access controls and GRC.
- Proven hands-on experience with SAP GRC (Access Control), including access risk analysis, mitigating control assignment, and SoD rulesets.
- Working knowledge of SAP modules (MM, FI, PP, QM, PM, SD) and how they intersect with access risk.
- Solid understanding of ITGC, application controls, and vulnerability management processes.
- Experience with Identity & Access Management tools (e.g., CyberArk) and privileged access reviews.
- Familiarity with audit and data analytics tools such as ACL and TeamMate.
- Qualified certification: CISA (Certified Information Systems Auditor) required; ITIL Foundation a plus.
- Experience with vulnerability assessment tools (e.g., Nmap, Nessus) is advantageous.
- Strong communication skills, with the ability to translate technical findings into actionable business recommendations.
- Proficiency in Microsoft Office (Excel, Word, Visio, PowerPoint).
Preferred Attributes
- Prior exposure to Big 4 audit methodology or large-scale internal audit functions.
- Experience delivering GRC or access-control training to end users and auditors.
- Fluency in English
What We Offer
- Chance to lead and shape the SAP GRC function within a growing organization.
- Exposure to cross-functional projects spanning IT, security, and business operations.
- Competitive compensation and professional development support
Skills: sap sd,sap,cisa,it audit,itgc,sap pp,sap qm,sap fi,grc,sap pm module,risk,sap materials management (sap mm),sap module
📌 IT Audit - SAP Governance Risk & Compliance (Chennai)
🏢 Duobridge
📍 Chennai