Consultant / Senior Consultant - Digital Risk (SAP and GRC Technology), Risk Consulting,
Job description
At EY, we develop you with future-focused skills and equip you with world-class experiences. We empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams.
We work together across our full spectrum of services and skills powered by technology and AI, so that business, people and the planet can thrive together.
We’re all in, are you?
Join EY and shape your future with confidence.
We help organisations strengthen performance by embedding risk awareness into decision-making. Our teams support clients in identifying significant risks, designing practical frameworks and improving the effectiveness and efficiency of risk management. In this role, you may work on a range of client priorities, including business performance variability; business and process controls transformation; application security and integrity; governance, risk and control (GRC) technology enablement; business and IT GRC; continuous monitoring; third-party and contract risk management; and IT risk management. You will join an international network of specialists who help clients transform risk functions and implement technology solutions that support effective risk management and governance.
We provide ongoing training, coaching and development opportunities to help you build skills in risk strategy, risk function design, risk management and performance improvement. You will work in a collaborative, global environment alongside colleagues with varied perspectives and experience, with opportunities to contribute, learn and develop throughout your career.
The opportunity
As a Consultant or Senior Consultant in Digital Risk, you will work with clients to strengthen technology risk management, controls and governance, with a focus on SAP and GRC technology. Consultants will contribute to defined workstreams, analysis, testing, documentation and client discussions with guidance from more experienced team members. Senior Consultants will take greater ownership of workstreams, coordinate day-to-day delivery, review work, facilitate client discussions and coach junior colleagues. At both levels, you will build trusted relationships and develop your capabilities through formal learning, coaching and collaboration.
Your key responsibilities
You will contribute to engagements involving SAP security and authorisations, business and IT controls, GRC technology enablement, continuous controls monitoring and related risk transformation. Typical activities include analysing requirements and data, assessing risks and controls, configuring or testing solutions, preparing clear deliverables, facilitating workshops and communicating with stakeholders. Senior Consultants will additionally plan and coordinate workstreams, manage progress against agreed budgets and timescales, review team outputs, address delivery risks and support proposals or other market activities. Some travel may be required, depending on client and project needs; reasonable adjustments can be discussed during the recruitment process.
Skills and attributes for success
- Contribute to client engagements by completing analysis, testing, documentation and agreed deliverables to a high standard.
- Apply knowledge of technology risks, controls, SAP or GRC solutions to client situations, seeking guidance where appropriate.
- Collaborate with colleagues and client stakeholders, communicate progress clearly and contribute constructively to workshops and meetings.
- Manage assigned priorities and deliver work within agreed timescales.
- For the Senior Consultant level, plan and coordinate workstreams, monitor scope, risks, budgets and timelines, and keep stakeholders informed.
- For the Senior Consultant level, review team outputs, coach junior colleagues and contribute to engagement planning and business development.
- Maintain professional knowledge, exercise sound judgement and act with integrity.
To qualify for the role, you should have
- A degree in information technology, engineering, mathematics, accounting, business, or another relevant discipline, or equivalent practical experience.
- For the Consultant level, typically up to two years of relevant experience in technology risk, IT audit, internal controls, SAP security, GRC technology or a comparable field. Applications from candidates with relevant internships, placements, project experience or transferable skills are welcome.
- For the Senior Consultant level, typically three to five years of relevant experience, including responsibility for delivering defined workstreams, coordinating junior team members and engaging directly with client stakeholders.
- For the Senior Consultant level, relevant experience in one or more of the following: business process risks and controls; SAP security, roles and authorisations; SAP BASIS security configuration review; GRC technology; IT audit; or technology risk management.
- The ability to analyse information, communicate clearly and work collaboratively with colleagues and client stakeholders.
Ideally, you will also have
- Hands-on experience with SAP GRC Access Control, SAP GRC Process Control or other recognised GRC platforms.
- Project management experience, including familiarity with agile methods.
- Data analysis, data processing or visualisation experience using databases, visualisation tools or spreadsheet applications.
- Relevant professional certifications, such as Certified Internal Auditor (CIA), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Information Systems Security Professional (CISSP), PRINCE2 Practitioner, Project Management Professional (PMP) or SAP functional certifications. Equivalent qualifications and relevant practical experience will also be considered.
What we look for
We’re interested in flexible professionals with excellent problem-solving skills and the ability to prioritise shifting workloads in a rapidly changing industry. You’ll also need the confidence to give professional advice and guidance to colleagues and clients from a diverse range of cultures, often with limited information – both verbally and in writing. If you’re a fast learner, with strong influencing skills and a genuine passion for information system security, this role is for you.