Our Ontario based client is seeking an experienced Senior SAP Security GRC Consultant to join their immediately and will run for 6 months with possibility of an extension. The ideal candidate should have 10+ years of experience in the design, configuration, development, and support of role-based authorization concepts, enablers, and derived role design and implementation for S/4HANA, ERP, Solutions, and GRC systems, plus 3+ years of SAP S/4HANA experience with deep knowledge of SAP security architecture and modules including ECC, S/4HANA, and BW. The candidate must also have multiple full-lifecycle GRC implementations across sub-modules. This will be a fully remote work setting.
Key Responsibilities:
- Collect and identify requirements for SAP Security / GRC configurations and Governance, Risk, and Compliance (GRC) of SFGs SAP and non-SAP systems using Best Practices. Engage the business and functional teams to ascertain requirements and implement technical objects like BRF+, Multi Step Multi Process (MSMP) workflow configuration, LDAP connections, etc.
- Create, configure, enhance, and maintain SAP GRC solutions for access control and user access reviews, including SAP GRC Access Control – Access Request Management (ARM), Access Risk Analysis (ARA), Emergency Access Management (EAM), ensuring they meet security and compliance standards. Develop, advise, construct, and maintain Fiori Catalogs, Tiles, Pages, Spaces, User Roles, and Authorizations in accordance with Audit requirements. Establish and implement technical and corporate controls within the scope of SAP to align with our organization’s information security policy.
- Draft documentation for the project, including Technical Design documents (with workflows), operation manuals, troubleshooting guides, recurring activity guides, etc. Support internal and external audits related to SAP systems and generate reports detailing compliance and risk assessment results.
- Create testing scenarios to support the packaged solutions and collaborate with the business/functional teams for testing and defect resolution across Integration, Regression, and User Acceptance Testing. Oversee and optimize the performance of SAP GRC solutions to ensure they run efficiently and effectively. Resolve technical issues related to SAP GRC solutions.
- Partner with business stakeholders to understand their security risk and compliance requirements and translate these into technical solutions. Coordinate with functional and technical teams, such as SAP Basis and Security, to ensure that SAP GRC solutions are integrated seamlessly into the overall SAP landscape.
- Implement and maintain security controls to protect sensitive data and ensure compliance with requirements. Address security incidents, lead investigations, and implement measures to prevent future occurrences. Propose new SAP GRC features and functionality that can improve the organization’s risk and compliance posture. Increase awareness about security and compliance issues among business stakeholders and SAP users.
- Experience with the implementation of mitigation controls for SAP SoD violations and remediation. Experience in design and development of SAP security policies
- Experience in SAP SaaS security applications including IAS and IPS
- Experience in SAP BTP Security and Role Management.
- Excellent troubleshooting skills, superior written and oral communication skills, excellent interpersonal abilities, and a strong ability to think logically.
- Strong leadership and project management abilities.
- SAP certification or CISA (Certified Information Systems Auditor) is an asset
- Experience in the manufacturing industry is preferred.
- Bilingual (French/English) is an asset.