Cybersecurity GRC Analyst – SAP Compliance & Access Controls

McKesson

Cork

On-site

EUR 56,300 - 93,800

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Total Rewards package

Job summary

McKesson is seeking a Cybersecurity GRC Analyst to support governance, risk, and compliance across our SAP environment. You will manage SAP GRC processes, perform risk assessments, and strengthen controls to ensure regulatory and internal policy compliance.

You will work with cybersecurity, SAP, audit, and business stakeholders to identify risks, monitor compliance, and drive improvements, helping reduce organizational risk and strengthen the SAP platform.

Qualifications

  • Degree in Information Security, Cybersecurity, Information Systems, Business, Risk Management, Audit, or related field, or equivalent experience.
  • 4+ years of relevant experience in cybersecurity compliance, IT audit, governance, risk management, SAP security, or GRC functions.
  • Hands-on experience with SAP GRC Suite including Access Control, Process Control, and/or Risk Management.
  • Experience performing SoD analysis and remediation.
  • Experience conducting User Access Reviews and Privileged Access Monitoring.
  • Experience supporting ITGC testing, SOX compliance, and audit activities.

Responsibilities

  • Manage and support SAP GRC processes, including Access Control, Process Control, and Risk Management.
  • Perform SoD analysis, risk assessments, and remediation activities.
  • Conduct User Access Reviews and Privileged Access Monitoring.
  • Support ITGC testing, SOX compliance, and audit readiness initiatives.
  • Identify control gaps, remediation actions, and track through completion.
  • Develop and maintain compliance documentation, process procedures, and control evidence.
  • Partner with SAP, cybersecurity, internal audit, and business teams to address security and compliance risks.
  • Monitor compliance metrics and prepare reports for management and stakeholders.
  • Support internal and external audits by gathering evidence, responding to requests, and facilitating walkthroughs.
  • Recommend improvements to governance, risk, and compliance processes, tools, and controls to enhance efficiency and effectiveness.
  • Contribute to cybersecurity and compliance initiatives that strengthen the organization's risk management framework.

Skills

SAP GRC Suite
SoD analysis
User Access Reviews
Privileged Access Monitoring
ITGC testing
SOX compliance
Audit support
Regulatory frameworks
GRC platforms
Stakeholder collaboration

Education

Degree in Information Security / related field

Tools

IRM platforms
GRC platforms
RegTech platforms

Job description

McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care.

What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow’s health today, we want to hear from you.

About the Role (Job Summary)

We're seeking a Cybersecurity GRC Analyst to support governance, risk, and compliance activities across our SAP environment. In this role, you'll help ensure compliance with internal policies, regulatory requirements, and industry standards by managing SAP GRC processes, conducting risk assessments, supporting audits, and strengthening security controls.

You will work closely with cybersecurity, SAP, audit, and business stakeholders to identify risks, monitor compliance, improve controls, and support a secure and compliant SAP platform. This position is ideal for a compliance professional who enjoys solving complex security challenges, driving process improvements, and partnering across teams to reduce organizational risk.

What You'll Do (Responsibilities)
  • Manage and support SAP GRC processes, including Access Control, Process Control, and Risk Management.
  • Perform Segregation of Duties (SoD) analysis, risk assessments, and remediation activities.
  • Conduct User Access Reviews (UARs) and Privileged Access Monitoring (PAM) to ensure appropriate access controls.
  • Support IT General Controls (ITGC) testing, SOX compliance activities, and audit readiness initiatives.
  • Identify control gaps, recommend corrective actions, and track remediation efforts through completion.
  • Develop and maintain compliance documentation, process procedures, and control evidence.
  • Partner with SAP, cybersecurity, internal audit, and business teams to address security and compliance risks.
  • Monitor compliance metrics and prepare reports for management and stakeholders.
  • Support internal and external audits by gathering evidence, responding to requests, and facilitating walkthroughs.
  • Recommend improvements to governance, risk, and compliance processes, tools, and controls to enhance efficiency and effectiveness.
  • Contribute to cybersecurity and compliance initiatives that strengthen the organization's risk management framework.
Basic Requirements
  • Degree in Information Security, Cybersecurity, Information Systems, Business, Risk Management, Audit, or a related field, or equivalent combination of education and experience.
  • Typically requires 4+ years of relevant experience in cybersecurity compliance, IT audit, governance, risk management, SAP security, or governance, risk, and compliance functions.
  • Hands‑on experience with SAP GRC Suite, including Access Control, Process Control, and/or Risk Management.
  • Experience performing Segregation of Duties (SoD) analysis and remediation.
  • Experience conducting User Access Reviews and Privileged Access Monitoring activities.
  • Experience supporting ITGC testing, SOX compliance, and audit activities.
  • Experience identifying control gaps and supporting remediation efforts.
  • Strong analytical and problem‑solving skills with the ability to assess risk and recommend practical solutions.
  • Experience creating and maintaining compliance documentation, audit evidence, and reports.
Preferred Skills/Experience
  • SAP security administration experience.
  • Experience supporting regulatory frameworks and compliance requirements in highly regulated industries.
  • Knowledge of cybersecurity governance, risk management, and internal control frameworks.
  • Experience with Integrated Risk Management (IRM), Governance Risk and Compliance (GRC), or Regulatory Technology (RegTech) platforms.
  • Professional certifications such as CISA, CRISC, CISSP, SAP GRC, SAP Security, or related credentials.
  • Experience with SAP S/4HANA environments.
  • Strong stakeholder management and communication skills with the ability to influence cross‑functional teams.
  • Experience creating compliance dashboards, metrics, and executive reporting.
Travel / Work Environment / Physical Requirements
  • Minimal travel may be required based on business needs.
  • Position may follow a hybrid or in-office work model based on location and business requirements.
  • Ability to work at a computer and participate in virtual meetings for extended periods.

At McKesson, we care about the well-being of the patients and communities we serve, and that starts with caring for our people. That’s why we have a Total Rewards package that includes comprehensive benefits to support physical, mental, and financial well‑being. Our Total Rewards offerings serve the different needs of our diverse employee population and ensure they are the healthiest versions of themselves.

As part of Total Rewards, we are proud to offer a competitive compensation package at McKesson. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long‑term incentive opportunities may be offered.

Our Base Pay Range for this position

€56,300 - €93,800

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SAP GRC & SOX Compliance Analyst
Senior SAP GRC & SOX Compliance Analyst

McKesson • Cork

On-site
EUR 72,000 - 120,000
SOX & IT Compliance Analyst
SOX & IT Compliance Analyst

McKesson • Cork

On-site
EUR 56,000 - 94,000
Sr IAM Engineer – SAP Security (Integration)
Sr IAM Engineer – SAP Security (Integration)

McKesson’s Corporate • Cork

On-site
EUR 66,000 - 110,000
Total Rewards program
Competitive compensation package
Senior SAP Security Engineer – Integration
Senior SAP Security Engineer – Integration

McKesson’s Corporate • Cork

On-site
EUR 66,000 - 110,000
Operations Manager, SOX and Compliance
Operations Manager, SOX and Compliance

McKesson • Cork

Hybrid
EUR 56,000 - 94,000
Sr. IAM Engineer – SAP Security HANA
Sr. IAM Engineer – SAP Security HANA

McKesson’s Corporate • Cork

On-site
EUR 66,000 - 110,000
SAP GRC Analyst: SoD, Access & ITGC Compliance
SAP GRC Analyst: SoD, Access & ITGC Compliance

McKesson • Cork

Hybrid
EUR 56,000 - 94,000
Total Rewards package
Sr. IAM Engineer – SAP Security HANA
Sr. IAM Engineer – SAP Security HANA

McKesson • Cork

On-site
EUR 66,000 - 110,000
Comprehensive benefits
Competitive compensation package
Sr IAM Engineer – SAP Security (Integration)
Sr IAM Engineer – SAP Security (Integration)

McKesson • Cork

On-site
EUR 66,000 - 110,000
Sr IAM Engineer - SAP Security (Integration)
Sr IAM Engineer - SAP Security (Integration)

McKesson Corporation • Ireland

On-site
EUR 66,000 - 110,000
Comprehensive benefits package
Performance-based bonuses
Long-term incentive opportunities