Access Governance: Architect, deploy, and manage SAP Cloud IAG modules including Access Request Service (ARS), Risk Analysis Service (RAS), and Role Design Service (RDS).
Cross-System Provisioning: Configure and maintain seamless integration between SAP IAG and target systems (SAP S/4HANA, SuccessFactors, Ariba, BTP, and non-SAP IdM platforms like Azure AD).
Automated Workflows: Build and optimize access request provisioning workflows, multi-stage approval paths, and emergency access management (Firefighter) policies.
Risk Management & Compliance (SoD)
Mitigation Control: Maintain and update the Segregation of Duties (SoD) Rule Architecture. Analyze access violations and design solid mitigation controls.
Audit Readiness: Coordinate internal and external IT audits. Generate compliance reports, user access reviews (UAR), and audit trails out of SAP IAG.
Role Design & Administration:
Role Engineering: Design, build, and transport structural security concepts (PFCG roles, composite roles, and derived roles) across SAP landscapes.
Troubleshooting: Provide Tier 3 technical support for complex authorization issues, security bugs, and user access blocks.
Technical Skills & Qualifications:
Education: Bachelor’s degree in Computer Science, Information Systems, Cyber Security, or a related field.
Experience: Minimum 4–6 years of hands‑on experience in SAP Security, with at least 2+ years specialized in SAP Cloud IAG implementations.
Core Technical Requirements:
Proficient in SAP IAG architecture and its cloud-to-on‑premise bridge connectivity (Cloud Connector configuration).
Deep understanding of SAP S/4HANA Security, Fiori tile authorizations, and SAP Business Technology Platform (BTP) security.
Strong knowledge of SoD / GRC concepts and experience executing User Access Review (UAR) and System Re‑certification cycles.
Experience with traditional SAP GRC (AC 10.1/12.0) is a significant plus for migration projects.
#J-18808-Ljbffr
This listing is sourced from a third-party job board. Applying will redirect you to the original posting.