Job Description
Job role : SAP Security / GRC Analyst
Duration : 3 6 month contract to hire
Location : Remote
Primary Responsibilities:
- Security Assessment and Planning: Conducts risk assessments, develops security plans, and creates security policies for SAP systems.
- User Access Management: Configures user roles, authorizations, and permissions, ensuring appropriate access levels and adherence to segregation of duties (SOD).
- Compliance and Auditing: Ensures compliance with relevant regulations and industry standards (e.g., SOX, GDPR) and supports audit processes.
- Security Monitoring and Incident Response: Monitors system activity for potential security breaches, investigates security incidents, and implements corrective actions.
- System Security Enhancements: Implements security patches, upgrades, and enhancements to SAP systems to address vulnerabilities and improve security posture.
- Training and Knowledge Transfer: Trains in-house employees & junior resources on security best practices and the use of SAP security tools.
- Collaboration and Communication: Works with various teams, including development, infrastructure, and audit, to ensure a holistic security approach.
- Documentation and Reporting: Creates and maintains documentation related to security configurations, policies, and procedures.
- SAP GRC Implementation and Support: May implement and support SAP's Governance, Risk, and Compliance (GRC) solutions.
- Staying Current: Keeps up-to-date with the latest SAP security threats, vulnerabilities, and best practices.
Preferred Experience/Qualifications
- SAP Security Expertise: 7-10 Years of In-depth knowledge of SAP security concepts, including user administration, authorization objects, roles, and profiles.
- SAP GRC Knowledge: Experience with SAP GRC Access Control and Process Control.
- SAP System Knowledge: Familiarity with various SAP modules (e.g., ECC, BI/BW, CRM, SolMan, etc.) and their security implications.
- Security Best Practices: Understanding of security best practices, including least privilege, separation of duties, and encryption.
- Analytical and Problem-Solving Skills: Ability to analyze security risks, troubleshoot issues, and develop effective solutions.
- Communication and Interpersonal Skills: Ability to communicate effectively with technical and non-technical stakeholders.
- Project Management Skills: Ability to manage security projects, prioritize tasks, and meet deadlines.
Job Tags
Contract work, Remote work,