Cyber - SAP Security and GRC Access & Process Control Manager
About the role
Join our Deloitte Cyber team to help organizations address cybersecurity challenges across complex technology environments. We assist clients in navigating evolving threats, strengthening resilience, and supporting secure business transformation.
Responsibilities
- Support SAP security and GRC implementations, assessments, and transformation initiatives across client environments.
- Lead SAP ECC and SAP S/4HANA security assessments, design, and implementation activities across complex business and technology environments.
- Design, build, test, and deploy end-user and IT support security roles across SAP platforms, including Fiori, Ariba, Integrated Business Planning, Business Technology Platform, and Business Data Cloud.
- Configure and implement SAP GRC Access Control capabilities, including Access Risk Analysis, Access Request Management, Emergency Access Management, and Business Role Management.
- Support SAP GRC Process Control design and configuration, including controls, risks, subprocesses, organizations, assignments, and continuous control monitoring capabilities.
- Manage project workstreams, client stakeholders, and delivery teams while providing recommendations on SAP security role design, segregation of duties, vulnerability findings, and regulatory control requirements.
Requirements
- Ability to work independently and collaborate as part of a team.
- Meticulous attention to detail and quality of work product.
- Strong interpersonal skills and professional demeanor.
- Ability to meet deadlines.
- Ability to mentor and provide clear guidance to others.
Qualifications
- Bachelor's degree
- 8+ years of experience with SAP S/4HANA security and SAP Governance, Risk, and Compliance (GRC) Access Control
- 8+ years of hands-on experience implementing security for SAP S/4HANA, Fiori, Ariba, Integrated Business Planning (IBP), Business Technology Platform (BTP), and Business Data Cloud, including requirement gathering, security design, and deployment
- 5+ years of experience designing, configuring, and implementing SAP GRC Access Risk Analysis (ARA), Access Request Management (ARM), Emergency Access Management (EAM), and Business Role Management (BRM)
- Previous consulting experience
- Professional certification such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Information Systems Auditor (CISA)
- Experience with SAP identity and access governance
- Experience with cloud security and cloud migrations
- Experience with SAP business process controls and data protection tools such as NextLabs
- Experience with vulnerability management tools such as Onapsis
Benefits
The team at Deloitte's Enterprise Security Offering helps clients embed security across digital transformation initiatives by securing core technology environments while enabling business change. The team supports work spanning security architecture, secure development and deployment, cyber cloud capabilities, application security, and security for emerging technologies and connected products.
Pay
A reasonable estimate of the current range is $134,500 to $265,100.
Schedule
On average, 50% travel may be required based on the work you do and the clients and industries/sectors you serve.