SAP GRC and HANA Security Consultant

Kyndryl

Santo Niño 1st

On-site

PHP 1,800,000 - 2,400,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Kyndryl, a leading IT infrastructure services provider, seeks a senior SAP security specialist to configure and support GRC across multiple modules and to drive remediation and SoD reviews. You will implement HANA security, PFCG roles, and Fiori access concepts while ensuring SOX ITGC compliance.

You will partner with BASIS, functional, and development teams to translate regulatory mandates into technical controls and mentor junior security analysts.

Qualifications

  • Bachelor’s degree in Computer Science, Information Systems, or equivalent practical experience.
  • 5+ years of SAP security experience, including 3+ years dedicated to SAP GRC Access Control (10.x/12.0).
  • Hands-on experience with SAP HANA DB security (privileges, analytic privileges, audit policies), PFCG role design, SU24, and Fiori access concepts.
  • Direct experience supporting SOX ITGC audits and executing SoD conflict remediation.
  • Strong written and verbal communication skills to translate complex access risks to non-technical stakeholders.

Responsibilities

  • Configure and support SAP GRC Access Control across ARA, ARM, BRM, and EAM (Firefighter) modules.
  • Maintain and customize SoD rulesets and configure MSMP workflows and BRF+ approval paths.
  • Perform user and role risk analyses, drive remediation, and design mitigating controls with business process owners.
  • Oversee User Access Reviews (UAR), SoD Reviews, and Firefighter log audits; track compliance and evaluate migration to SAP Cloud IAG.
  • Oversee SAP HANA security administration and SSO/authentication protocols; manage policies and encryption.
  • Design and maintain PFCG roles for S/4HANA, ECC, BW/4HANA, using SU24, STAUTHTRACE/ST01.
  • Build Fiori security architecture and support connected platforms (BTP, SAC, Ariba, SuccessFactors).
  • Lead security workstreams for S/4HANA conversions and provide L3 incident support.

Skills

SAP security
GRC Access Control
HANA DB security
PFCG role design
SU24
Fiori access concepts
SOX ITGC audits
ABAP scripting
Python scripting
PowerShell scripting
S/4HANA security
SAP IAG (IAG)
BTP security
HDI/XSA

Education

Bachelor’s degree in Computer Science/Information Systems

Tools

HANA
STAUTHTRACE/ST01

Job description

Configure and support SAP GRC Access Control 10.1/12.0 across ARA, ARM, BRM, and EAM (Firefighter) modules.

Maintain and customize SoD rulesets (custom risks, functions, org rules) and configure MSMP workflows and BRF+ approval paths.

Perform user and role risk analyses, drive remediation, and design mitigating controls with business process owners.

Oversee User Access Reviews (UAR), SoD Reviews, and Firefighter log audits; track compliance and evaluate migration to SAP Cloud IAG.

SAP HANA & Application Security:

Administer HANA DB security, including catalog/repository roles, analytic privileges, static/dynamic data masking, HDI containers, and XSA role collections.

Manage HANA audit policies, data encryption, certificate management, and SSO/authentication protocols (SAML 2.0, Kerberos).

Design and maintain PFCG roles for S/4HANA, ECC, BW/4HANA, and Solution Manager using SU24 and trace tools (STAUTHTRACE/ST01).

Build Fiori security architecture (catalogs, spaces, pages, and front-end/back-end role mappings) and support connected platforms (BTP, SAC, Ariba, SuccessFactors).

Lead security workstreams for S/4HANA conversions and provide L3 incident support for authorization failures.

Compliance, Governance & Collaboration:

Serve as SME for SOX ITGC, internal, and external audits; prepare documentation, evidence, and control narratives.

Enforce access governance policies (provisioning, deprovisioning, privileged access, GDPR data privacy compliance).

Partner with Basis, functional, and development teams to translate regulatory mandates into technical controls.

Mentor junior security analysts and maintain team knowledge bases and standards.

Qualifications
Required:

Education: Bachelor’s degree in Computer Science, Information Systems, or equivalent practical experience.

Experience: 5+ years of SAP security experience, including 3+ years dedicated to SAP GRC Access Control (10.x/12.0).

Technical Expertise: Hands-on experience with SAP HANA DB security (privileges, analytic privileges, audit policies), PFCG role design, SU24, and Fiori access concepts.

Compliance: Direct experience supporting SOX ITGC audits and executing SoD conflict remediation.

Soft Skills: Strong written and verbal communication skills to translate complex access risks to non-technical stakeholders.

Preferred:

Experience with SAP Cloud Identity Access Governance (IAG), SAP Cloud Identity Services (IAS/IPS), or IGA tools (SailPoint, Saviynt).

Exposure to SAP BTP security, HANA Cloud, HDI/XSA development, and automation scripting (ABAP, Python, PowerShell).

Lead security experience in a full lifecycle S/4HANA implementation or conversion.

Certifications: SAP Certified Application Associate (GRC AC 12.0), SAP Certified Technology Associate (HANA), CISA, CISSP, or CRISC.

As the world's largest provider of IT infrastructure services, Kyndryl is committed to the health and continuous improvement of the vital systems at the heart of the digital economy. With our partners and thousands of customers worldwide, we co-create solutions to help enterprises reach their peak digital performance.

"Kyn" comes from "kin." It represents the strong bonds we form with customers and with each other. "-dryl" is coined from "tendril," evoking new growth and connections. By working together, we are growing.

As the world's largest provider of IT infrastructure services, Kyndryl is committed to the health and continuous improvement of the vital systems at the heart of the digital economy. With our partners and thousands of customers worldwide, we co-create solutions to help enterprises reach their peak digital performance.

"Kyn" comes from "kin." It represents the strong bonds we form with customers and with each other. "-dryl" is coined from "tendril," evoking new growth and connections. By working together, we are growing.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior SAP GRC & HANA Security Consultant
Senior SAP GRC & HANA Security Consultant

Kyndryl • Santo Niño 1st

On-site
PHP 1,800,000 - 2,400,000
SAP Security Consultant
SAP Security Consultant

UST • Taguig

On-site
PHP 1,200,000 - 2,400,000
GDS Consulting_SAP GRC IAG Senior Consultant
GDS Consulting_SAP GRC IAG Senior Consultant

EY • Taguig

On-site
PHP 2,405,000 - 3,608,000
Senior SAP Security Consultant
Senior SAP Security Consultant

IBM • Quezon City

On-site
PHP 1,400,000 - 2,100,000
SAP Security & GRC Analyst
SAP Security & GRC Analyst

Sony Pictures Entertainment, Inc • Hinoba-an

On-site
INR 1,200,000 - 2,200,000
SAP Security - Consultant (Makati) - Hybrid, morning shift
SAP Security - Consultant (Makati) - Hybrid, morning shift

TASQ Staffing Solutions • Makati

On-site
PHP 1,116,000 - 1,674,000
SAP Security & GRC Analyst
SAP Security & GRC Analyst

Sony Pictures Entertainment • Hinoba-an

On-site
INR 1,500,000 - 2,500,000
SAP Security & GRC Analyst
SAP Security & GRC Analyst

Sonypictures • Hinoba-an

On-site
INR 900,000 - 1,300,000
SAP Security Consultant - AMS
SAP Security Consultant - AMS

DyFlex Pty Ltd • Manila

On-site
PHP 900,000 - 1,500,000
SAP Security Consultant
SAP Security Consultant

Capgemini • Metro Manila

On-site
PHP 1,500,000 - 2,300,000