Risk Consulting - Digital Risk - SAP GRC - ITAC - Manager
Job description
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
Role : SAP GRC / ITAC Manager
Primary skill : SAP GRC Access Control, SAP ITAC, ITGC
Role overview
As part of Risk Consulting, the Manager will lead and deliver client engagements related to SAP GRC, SAP IT application controls, IT general controls, internal audit and risk management for clients across the MENA region. The role is designed for experienced SAP GRC professionals who can strengthen the local core team, manage delivery quality and support high-demand engagements requiring deep SAP GRC and ITAC capability.
The opportunity
We are looking for experienced professionals with strong SAP GRC Access Control, SAP security, ITAC and ITGC experience to join the Risk Consulting - Digital Risk team. This role provides an opportunity to lead SAP GRC and IT controls engagements, mentor offshore teams, support growth of the SAP GRC service offering and work with stakeholders across sectors.
Your key responsibilities
- Lead SAP GRC/ITAC and IT risk consulting engagements across SAP ECC and SAP S/4HANA environments, including planning, execution, quality review and stakeholder reporting.
- Manage SAP GRC Access Control workstreams covering Access Risk Analysis, Emergency Access Management, Access Request Management and Business Role Management as applicable to client scope.
- Lead ITGC and ITAC assessments including risk and control matrix review, walkthroughs, Test of Design, Test of Operating Effectiveness and remediation tracking.
- Review SoD risk analysis, sensitive access reviews, SAP security role assessments and remediation plans for quality, accuracy and audit readiness.
- Drive ERP control assessments covering logical access, change management, backup and restoration, incident management and automated business controls.
- Guide SAP GRC solution configuration, testing and optimization activities, including rule set rationalization, workflow validation and UAT coordination.
- Manage engagement economics, timelines, deliverables, issue logs and status updates in coordination with client stakeholders and internal leadership.
- Mentor seniors, consultants and analysts, provide coaching on SAP GRC, ITAC testing methodology, documentation standards and client communication.
- Support proposal inputs, capability building, knowledge sharing and development of reusable accelerators for SAP GRC and IT controls engagements.
- Coordinate with internal audit, external audit and client teams to ensure evidence completeness, clear issue articulation and timely follow-up.
Skills and attributes for success
- Strong command of spoken and written English with the ability to communicate complex SAP GRC and audit matters clearly.
- Excellent project management, engagement leadership and stakeholder management skills.
- Highly analytical, organised and meticulous consulting approach with strong attention to detail and quality assurance.
- Ability to manage multiple priorities, work under pressure and deliver high-quality outputs within tight deadlines.
- Strong team leadership skills with a focus on coaching, accountability and collaborative problem solving.
- Proficiency in MS Office, working knowledge of Excel-based analysis, data validation and reporting tools such as Power BI or ACL are preferred.
- Flexibility to travel to onsite locations at short notice, based on client and engagement requirements.
To qualify for the role, you must have
- 8-12 years of experience in SAP GRC, SAP security, ERP controls, IT audit, internal audit or technology risk consulting.
- Hands-on experience in SAP GRC Access Control and strong understanding of SAP ECC, S/4HANA security and authorization concepts.
- Strong understanding of RCMs, ITGC, ITAC, SoD, sensitive access, control testing procedures and issue management.
- Experience leading control testing teams and reviewing deliverables for quality, accuracy and consistency with professional standards.
- Knowledge of audit and risk frameworks such as SOX, COSO, ICOFR and professional IT audit practices.
- Bachelor’s degree in Information Systems, Computer Science, Accounting, Finance or a related discipline.
- A valid passport for travel.
Ideally, you will also have
- Certifications such as SAP GRC, CISA, CRISC, CIA, Oracle Cloud Security or other relevant risk/technology credentials.
- Experience with Oracle Risk Management Cloud, ServiceNow IRM, Archer or other risk technology platforms.
- Experience in S/4HANA role redesign, SoD rule set rationalization, user access reviews, access provisioning workflows or continuous controls monitoring.
- Prior consulting experience supporting MENA clients or multi-entity SAP landscapes.
What working at EY offers
At EY, you will work on meaningful and varied client engagements while developing through coaching, practical experience and structured feedback. You will be part of an interdisciplinary environment that values quality, knowledge sharing and professional growth.
- Support, coaching and feedback from engaging colleagues.
- Opportunities to develop new SAP GRC, IT risk and audit skills.
- The freedom and flexibility to handle your role in a way that is right for you.
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.