GMS-Senior-SAP GRC AC And PC
Job description
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
SAP Security, GRC Access Control and Identity Management Specialist
Professional Job Description for Modern SAP Landscapes
Scope: SAP S/4HANA on RISE, SAP GRC, SAP IDM, SAP BTP, Ariba, SuccessFactors, BW and integrated SAP platforms
Role Type
SAP Security, GRC, IDM and Access Governance
Seniority
Senior Analyst / Consultant / Specialist / Lead, depending on experience
Primary Focus
User access management, role lifecycle, GRC operations, IDM provisioning, risk ruleset management, audits and access reviews
Landscape
SAP S/4HANA on RISE, SAP GRC AC/PC, SAP IDM, SAP BTP, Ariba, SuccessFactors, SAP BW/BW4HANA and related integrations
Role Summary
We are looking for an experienced SAP Security, GRC and Identity Access Management professional to manage end-to-end SAP user access, role design, identity lifecycle, access governance, emergency access, risk analysis, audits and security operations across a complex SAP landscape. The role will support SAP S/4HANA on RISE, SAP GRC Access Control, SAP GRC Process Control, SAP IDM, SAP BTP, SAP Ariba, SAP SuccessFactors, SAP BW/BW4HANA and other integrated SAP applications.
The candidate will be responsible for SAP user management, SAP role design and maintenance, GRC operations, access risk analysis, SAP Firefighter governance, user access review implementation, quarterly access reviews, risk ruleset management, SoD remediation support, country rollouts, SAP native security assessments and audit support. The role requires strong process discipline, documentation quality and audit-ready execution across run, change and project activities.
Key Accountability Areas
Expected Ownership
SAP User Access Management
Create, modify, maintain and revoke SAP user access using approved access request, provisioning and governance processes.
SAP Role Management
Own role requirement gathering, role design, build, testing, transport, go-live and ongoing maintenance.
SAP GRC Access Control
Administer GRC Access Control processes across ARA, EAM, ARM and access governance workflows.
SAP GRC Process Control
Support quarterly CCM updates, control monitoring, exception validation and control evidence management.
SAP IDM
Manage identity lifecycle workflows, provisioning, deprovisioning, reconciliation and connector issue resolution.
Access Reviews and Audits
Implement and operate user access reviews, firefighter reviews, audit evidence packs and remediation tracking.
Risk Ruleset Management
Design, maintain, test and govern SoD and critical access rulesets for SAP and integrated applications.
SAP Native Security
Assess SAP authorization, user, privileged access, RFC, technical user and security configuration risks.
Detailed Responsibilities
SAP User Access Management
- Manage SAP user ID creation, modification, lock, unlock, validity updates, role assignment, termination and periodic user maintenance across SAP systems.
- Support access provisioning and deprovisioning through SAP IDM and SAP GRC Access Control workflows.
- Handle access requests, emergency requests, weekend releases and production access support activities.
- Ensure access is provisioned based on approved requests, business need, least privilege and segregation of duties requirements.
- Maintain user master data, license-relevant user classifications, technical users, communication users and validity controls.
SAP Role Management
- Design, build, test and maintain SAP security roles for SAP S/4HANA, ECC, BW, Fiori, BTP integrations and related SAP platforms.
- Perform role requirement gathering with business process owners, functional teams, control owners and country rollout teams.
- Translate business requirements into authorization concepts, role matrices, derived roles, composite roles and Fiori catalogs, groups, spaces or pages.
- Own the role lifecycle from requirement gathering, design, build and unit testing through UAT, defect remediation, transport movement, go-live and hypercare.
- Support role redesign, role cleanup, SoD reduction, access optimization and country-specific role rollout activities.
SAP GRC Access Control Management
- Administer SAP GRC Access Control modules including Access Risk Analysis, Emergency Access Management, Access Request Management and Business Role Management where applicable.
- Configure and support GRC workflows, approval paths, request types, provisioning settings, connectors and access request exceptions.
- Perform access risk analysis for users, roles, access requests and role changes.
- Monitor and resolve GRC provisioning failures, workflow issues, connector errors and control exceptions.
- Support integrated access governance across SAP S/4HANA, BW, Ariba, SuccessFactors, BTP and other connected applications.
SAP GRC ARA and Risk Ruleset Management
- Manage SAP GRC ARA risk analysis for users, roles, profiles, critical transactions and sensitive authorization combinations.
- Design, update and maintain SAP risk rulesets including risks, functions, actions, permissions and mitigating controls.
- Perform ruleset impact assessment, regression testing and approval tracking before production deployment.
- Coordinate SoD risk remediation, mitigation control assignment and risk owner sign-off.
- Maintain ruleset documentation, change history, test evidence and version control.
SAP Firefighter and Emergency Access Management
- Manage SAP Firefighter ID setup, owner assignment, controller assignment, reason codes and emergency access configuration.
- Support emergency access request, approval, usage monitoring, log review and closure processes.
- Perform SAP GRC Firefighter log reviews and coordinate timely controller review and sign-off.
- Investigate unauthorized, excessive or inappropriate firefighter usage and track remediation actions.
- Maintain audit-ready evidence for firefighter assignment, usage, review, exceptions and approvals.
SAP User Access Review Implementation and Quarterly Reviews
- Implement SAP user access review campaigns using SAP GRC or approved access certification tools.
- Prepare user, role, critical access, SoD, privileged access and firefighter review datasets.
- Coordinate quarterly access reviews with managers, role owners, process owners and control owners.
- Track review completion, access retention, revocation, exceptions, remediation actions and management approvals.
- Maintain complete evidence for internal audit, external audit and compliance reporting.
SAP GRC Process Control and Quarterly CCM Updates
- Support SAP GRC Process Control operations, control mapping, monitoring rules and issue tracking.
- Perform quarterly Continuous Control Monitoring updates based on process, configuration, risk and control changes.
- Maintain CCM business rules, monitoring schedules, exception logic and control owner assignments.
- Coordinate with process owners to validate CCM exceptions, control failures and remediation actions.
- Prepare control evidence, deficiency documentation and management reporting.
SAP IDM and Identity Lifecycle Management
- Manage identity lifecycle processes in SAP IDM including joiner, mover, leaver, role assignment, provisioning and deprovisioning workflows.
- Support integrations between SAP IDM, HR source systems, SAP GRC, SAP systems and downstream applications.
- Maintain IDM workflows, connectors, provisioning rules, approval logic and reconciliation processes.
- Troubleshoot provisioning failures, access synchronization issues and identity data inconsistencies.
- Support future-state IAM planning involving SAP Cloud Identity Services, SAP IAG or enterprise identity platforms where applicable.
Country Rollouts and Release Support
- Support SAP security activities for new country rollouts, company code rollouts, business process deployments and regional templates.
- Gather local access requirements and align them with global role design, control standards and SoD requirements.
- Prepare access matrices, role mapping, test scripts, cutover plans and go-live readiness evidence.
- Support unit testing, UAT, defect resolution, transport movement, weekend release and hypercare activities.
- Ensure country-specific access is secure, approved, tested and audit-ready before production use.
SAP Native Security Assessment and Audit Support
- Perform SAP native security assessments across S/4HANA, ECC, BW, GRC, Solution Manager, BTP-integrated applications and other SAP platforms.
- Review SAP authorization objects, critical transactions, privileged users, RFC users, communication users, generic IDs and sensitive access.
- Identify excessive access, weak role design, unused roles, shared IDs, control gaps and configuration weaknesses.
- Support SAP internal audit, external audit, SOX, ITGC and compliance reviews.
- Prepare audit evidence packs, management responses, remediation plans and closure validation evidence.
SAP Application Scope
- SAP S/4HANA on RISE / Private Cloud Edition
- SAP GRC Access Control
- SAP GRC Process Control
- SAP IDM
- SAP BTP
- SAP Ariba
- SAP SuccessFactors
- SAP BW / BW4HANA
- SAP Fiori Launchpad
- SAP Solution Manager
- SAP Cloud Identity Services / IAS / IPS, where applicable
- Integrated non-SAP systems connected to SAP access governance
Required Skills and Experience
- Strong hands-on experience in SAP Security, SAP GRC Access Control and SAP user administration.
- Experience in SAP role design, role build, UAT support, transport movement and production deployment.
- Working knowledge of SAP GRC ARA, EAM, ARM and risk ruleset management.
- Experience with SAP Firefighter ID management, log review and emergency access governance.
- Experience implementing and operating SAP user access reviews and quarterly access certification processes.
- Experience with SAP IDM provisioning, workflows, connectors and identity lifecycle management.
- Knowledge of SAP S/4HANA security, Fiori security, authorization objects and business role concepts.
- Understanding of SAP GRC Process Control and Continuous Control Monitoring.
- Experience supporting SAP internal audits, external audits, SOX, ITGC and compliance reviews.
- Strong documentation, stakeholder management, evidence management and issue resolution skills.
Preferred Skills
- Experience with SAP S/4HANA on RISE or hybrid SAP cloud landscapes.
- Knowledge of SAP BTP security, role collections, identity provider integration and cloud authorization concepts.
- Experience with SAP Ariba and SAP SuccessFactors access governance.
- Experience with SAP Cloud Identity Services, IAS, IPS, SAP IAG or Microsoft Entra ID integration.
- Awareness of cross-application SoD risks across SAP and cloud applications.
- Experience in global SAP template rollouts and country-specific security deployments.
- Knowledge of SOX, ITGC, NIST, ISO 27001 or internal control frameworks.
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.