SAP
India
Contract
Start date: 1 Jul 2026
Job Title: SAP Security and GRC consultant
Job Summary:
We are looking for an experienced SAP Security and GRC Consultant with 7+ years of hands-on experience in SAP Security, SAP GRC Access Control, user administration, role design, authorization troubleshooting, and compliance support. The candidate should have strong knowledge of SAP authorization concepts, Segregation of Duties, risk analysis, access request management.
Key Responsibilities
- Participate in SAP implementation, rollout, upgrade, and support projects.
- Design, build, modify, and maintain SAP roles and authorizations based on business requirements.
- Work on SAP security for ECC, S/4HANA, BW, Fiori, and other SAP systems as applicable.
- Perform authorization troubleshooting using standard SAP transactions and traces.
- Work with functional teams to understand access requirements and provide appropriate security solutions.
- Maintain and update SAP security documentation, role matrices, access control documents, and audit evidence.
- Support SAP GRC Access Control modules such as:
- Access Risk Analysis
- Access Request Management
- Emergency Access Management
- Business Role Management
Required Skills:
SAP Security:
- Strong knowledge of SAP Security concepts including users, roles, profiles, authorization objects, and organizational level restrictions.
- Experience with role design concepts such as single roles, composite roles, derived roles, and business roles.
- Knowledge of SAP Fiori security, catalogs, groups, spaces, pages, and OData services is preferred.
- Basic understanding of SAP S/4HANA security concepts.
- Ability to analyze authorization issues and provide timely resolution.
- Hands on experience on SAP Security transactions.
SAP GRC:
- Experience in SAP GRC Access Control configuration and support.
- Good understanding of SoD risks, mitigating controls, and remediation processes.
- Configuration and support experience in SAP GRC Access Control.
- User and role risk analysis using Access Risk Analysis.
- Access request workflow support using Access Request Management.
- Firefighter ID setup, assignment, log review, and reporting using Emergency Access Management.
- Rule set understanding, risk maintenance, function maintenance, and mitigation control assignment.
- Experience in generating and reviewing GRC reports.
- Support for SoD remediation and mitigation activities.
- Knowledge of MSMP workflow, BRFplus rules, connectors, and synchronization jobs is an advantage.
Back