Purpose of the Job
The SAP Security & Controls Governance Lead is responsible for enterprise-wide SAP access risk management and controls governance across all SAP environments. This role owns SAP segregation of duties (SOD) governance, role design standards, access risk monitoring, and automated control integrity to ensure compliance with SOX, internal control, and enterprise risk management requirements. This role bridges IT, Finance, Internal Audit, and Business Process Owners to strengthen security design, reduce control risk, and improve system-enabled compliance.
Note: This is a contract position with a tenure of one year.
Job Responsibilities
A. SAP Segregation of Duties (SOD) Governance
- Own enterprise SAP SOD policy, standards, and governance framework.
- Design and maintain SOD ruleset aligned to financial reporting risks.
- Able to support on the cross-system SOD’s and ensuring alignment with SAP functionality (new Tcodes, Fiori apps, CDS views, custom developments).
- Oversee role design standards and naming conventions.
- Review and approve new role requests and structural role changes.
- Lead quarterly access risk review process.
- Monitor emergency access (Firefighter) governance.
- Oversee mitigation control design and documentation.
- Drive remediation of toxic combinations.
B. SAP Security Governance
- Define and enforce role ownership model (GPO alignment).
- Implement least-privilege principles and maintain global role catalog.
- Partner with IAM team on provisioning workflows.
- Lead security-related configuration reviews.
- Support audit and SOX walkthroughs.
- Oversee user access review automation.
C. SAP Controls Governance
- Own governance over:
- Automated configurable controls.
- Key system reports used as SOX controls.
- Interface controls and Workflow approvals.
- Change management security impacts.
- Validate design and integrity of automated controls.
- Coordinate with ITGC owner for change management alignment.
D. Strategic & Cross-Functional
- Act as liaison between IT, finance, internal audit, global process owners.
- Support IPO/SOX readiness.
- Identify automation opportunities in GRC and SA.
Experience & Skills
- 12-15 years SAP security and GRC experience.
- Deep expertise in SAP ECC and/or S/4HANA security architecture.
- Experience with SAP GRC Access Control (AC).
- SOX experience in public or IPO-bound company.
- Strong understanding of ITGC, Automated controls and financial reporting risk.
Preferred
- Experience in manufacturing environment.
- Experience leading global role redesign.
- Experience preparing for IPO or remediation program.
- Governance mindset (not just ticket processor).
- Strong cross-functional communication.
- Ability to challenge business leaders on risk.
- Executive presence.
- Structured documentation and policy writing.
- Data-driven analysis.