Stand out for this role — generate a tailored resume and cover letter in about a minute.
Orcapod Consulting Services in Pune seeks a SAP GRC Security Senior Consultant to own end-to-end SAP GRC Access Control in an AMS environment. The role covers configuration, operations, risk management, and audit-aligned security improvements.
Responsibilities include designing and maintaining GRC workflows, supporting role management across SAP ECC/S4HANA/Fiori, and ensuring compliance with SOX ITGC and client requirements.
Role Summary - The SAP GRC Security Senior Consultant (B2) is responsible for end-to-end SAP Security and GRC Access Control support in an AMS environment. The role involves configuration, operations, risk management, and continuous improvement of SAP security landscapes while ensuring compliance with audit and business requirements.
SAP GRC Access Control (Primary Responsibility) Configure and support SAP GRC Access Control 10.x / 12.x modules (ARA, ARM, EAM, BRM) Manage Access Risk Analysis (ARA), Emergency Access Management (EAM), and Access Request Management (ARM) Design and maintain GRC workflows, mitigation controls, and approval processes Build and maintain custom rulesets for SoD (Segregation of Duties) analysis
SAP Security & Role Management Perform end-to-end role design, creation, and maintenance (Single, Composite, Derived roles) Support user provisioning across SAP ECC, S/4HANA, Fiori, and other systems Manage user access requests, role assignments, and authorization issues Ensure roles are aligned with business processes (O2C, P2P, R2R)
AMS Support & ITIL Processes Provide L2/L3 support for incidents, service requests, and problem management Handle ticket lifecycle using ITSM tools (e.g., ServiceNow) Participate in change management, release deployment, and CAB activities Work in AMS support model with SLA/KPI adherence
Risk, Compliance & Audit Management Perform SoD analysis, risk identification, and mitigation planning Support internal/external audits by providing evidence and reports Ensure compliance with SOX ITGC and security policies Monitor Firefighter IDs (Emergency Access) usage and logs
GRC Configuration & Optimization Perform initial setup and configuration of GRC Access Control components Maintain rulesets, connectors, mitigation controls, and BRF+ workflows Optimize security processes and GRC performance
Stakeholder & Business Engagement Work closely with business users, auditors, and IT teams Understand business processes and translate into security roles and controls Proactively suggest service improvements and automation opportunities
Reporting & Documentation Generate reports on: Risk analysis, Mitigation controls, Firefighter usage, Maintain SOPs, security policies and documentation, Support RCA for security incidents