SAP GRC Access Control Specialist – CISA Certified

DuoBridge

Chennai District

On-site

INR 3,000,000 - 5,400,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

DuoBridge in Chennai is seeking an experienced SAP GRC resource to manage and strengthen its SAP Governance, Risk, and Compliance framework. The ideal candidate will bring hands-on expertise in SAP access controls, SoD risk analysis, and IT general controls (ITGC), with a strong IT audit background.

This role is critical to ensuring the SAP environment is secure, compliant, and aligned with internal controls and regulatory requirements.

Qualifications

  • Bachelor's degree in Information Systems, Computer Science, Accounting, or a related field.
  • 8-12 years of IT audit experience with a focus on SAP access controls and GRC.
  • Hands-on SAP GRC (Access Control) experience including risk analysis and SoD rulesets.
  • Familiar with SAP modules (MM, FI, PP, QM, PM, SD) and their access risk intersections.
  • Knowledge of ITGC, application controls, and vulnerability management processes.
  • Experience with Identity & Access Management tools and privileged access reviews.
  • Audit/data analytics tools such as ACL and TeamMate; CISA certification required; ITIL a plus.

Responsibilities

  • Design, configure, and maintain SAP GRC Access Control with risk rulesets and remediation workflows.
  • Review SAP user access, role assignments, privileged access, and emergency access management for SoD conflicts.
  • Monitor SAP access controls across procure-to-pay, order-to-cash, and user access management.
  • Assess ITGC, application, and infrastructure controls within SAP; benchmark against NIST.
  • Collaborate with IT and business to investigate audit findings and drive remediation progress.
  • Support external/internals audits, including planning, fieldwork, reporting, and issue follow-up.
  • Evaluate third-party service reports (ISAE 3402/SOC) for outsourced IT functions.
  • Conduct vulnerability assessments and support broader IT security reviews.
  • Develop and deliver training on GRC processes, tools, and controls.
  • Maintain audit issue tracking systems reflecting current practices.

Skills

SAP GRC Access Control
CISA
SAP PP
SAP QM
SAP MM
SAP FI
ITGC
IT Audit
SAP SD
SAP PM

Education

Bachelor's degree in Information Systems
Bachelor's degree in Computer Science
Bachelor's degree in Accounting
Related field

Tools

ACL
TeamMate
NIST framework

Job description

SAP GRC

Location: Chennai

Department: GPO - Process Owner

About The Role

We are seeking an experienced SAP GRC resource to manage and strengthen our SAP Governance, Risk, and Compliance framework. The ideal candidate will bring hands-on expertise in SAP access controls, segregation of duties (SoD) risk analysis, and IT general controls (ITGC), combined with a strong background in IT audit. This role is critical to ensuring our SAP environment is secure, compliant, and aligned with internal control and regulatory requirements.

Key Responsibilities
  • Design, configure, and maintain SAP GRC Access Control, including access risk rulesets, mitigating controls, and remediation workflows.
  • Perform periodic reviews of SAP user access, role assignments, privileged access, and emergency access management (Firefighter) to identify and remediate segregation of duties (SoD) conflicts.
  • Review and monitor SAP access controls across key business cycles (procure-to-pay, order-to-cash, user access management) to ensure compliance with company policies and industry standards.
  • Assess IT general controls (ITGC), application controls, and infrastructure controls within SAP and related environments, benchmarking against frameworks such as NIST.
  • Partner with IT and Business stakeholders to investigate audit findings, track remediation progress, and drive continuous improvement in control effectiveness.
  • Support external and internal audit engagements, including planning, fieldwork, reporting, and issue follow-up for SAP-based systems.
  • Evaluate third-party service reports (e.g., ISAE 3402/SOC reports) for outsourced IT support functions.
  • Conduct vulnerability assessments and support broader IT security reviews in collaboration with the security team.
  • Develop and deliver training to key users, internal auditors, and auditees on GRC processes, tools, and controls.
  • Maintain and enhance audit issue tracking systems, ensuring workflows reflect current audit practices.
Required Qualifications
  • Bachelor's degree in Information Systems, Computer Science, Accounting, or a related field.
  • Minimum 8-12 years of combined experience in IT audit (internal and/or external) with a strong focus on SAP access controls and GRC.
  • Proven hands-on experience with SAP GRC (Access Control), including access risk analysis, mitigating control assignment, and SoD rulesets.
  • Working knowledge of SAP modules (MM, FI, PP, QM, PM, SD) and how they intersect with access risk.
  • Solid understanding of ITGC, application controls, and vulnerability management processes.
  • Experience with Identity & Access Management tools (e.g., CyberArk) and privileged access reviews.
  • Familiarity with audit and data analytics tools such as ACL and TeamMate.
  • Professional certification: CISA (Certified Information Systems Auditor) required; ITIL Foundation a plus.
  • Experience with vulnerability assessment tools (e.g., Nmap, Nessus) is advantageous.
  • Strong communication skills, with the ability to translate technical findings into actionable business recommendations.
  • Proficiency in Microsoft Office (Excel, Word, Visio, PowerPoint).
Preferred Attributes
  • Prior exposure to Big 4 audit methodology or large-scale internal audit functions.
  • Experience delivering GRC or access-control training to end users and auditors.
  • Fluency in English
What We Offer
  • Opportunity to lead and shape the SAP GRC function within a growing organization.
  • Exposure to cross-functional projects spanning IT, security, and business operations.
  • Competitive compensation and professional development support

Skills: sap pp,cisa,sap qm,sap materials management (sap mm),sap grc access control,sap fi,itgc,grc,it audit,sap sd,sap pm module,sap,sap module,risk

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SAP GRC Consultant
SAP GRC Consultant

VMC Soft Technologies, Inc • Hyderabad

On-site
INR 1,200,000 - 1,800,000
SAP GRC Consultant
SAP GRC Consultant

People Prime Worldwide • Bengaluru

On-site
INR 800,000 - 1,200,000
SAP GRC Lead Opportunity
SAP GRC Lead Opportunity

Uni Integrations (Opc) Private Limited • India

Hybrid
INR 2,000,000 - 2,800,000
Hiring For SAP GRC_ Access Control/Security
Hiring For SAP GRC_ Access Control/Security

Infosys BPM • Bengaluru

On-site
INR 2,800,000 - 3,600,000
Sap Grc Lead
Sap Grc Lead

Bct Consulting • Mumbai

On-site
INR 4,000,000 - 6,000,000
SAP GRC PS
SAP GRC PS

NTT DATA, Inc. • Bengaluru

Hybrid
INR 1,500,000 - 3,000,000
SAP GRC and Security Consultant
SAP GRC and Security Consultant

Acesoft Labs • Bengaluru

On-site
INR 1,800,000 - 2,400,000
SAP GRC Security
SAP GRC Security

Alexahire • Mumbai

On-site
INR 1,200,000 - 2,000,000
Governance, Risk and Compliance Consultant - Remote India
Governance, Risk and Compliance Consultant - Remote India

DXC Technology • India

On-site
USD 6,816 - 13,632
Architect - SAP Governance and Risk Compliance
Architect - SAP Governance and Risk Compliance

PepsiCo Inc. • Hyderabad

On-site
INR 2,400,000 - 3,200,000