Security and Compliance Expert, ERP Data Platform
The primary mission is to ensure that the organization’s technology landscape, data practices, and security measures do not expose the business to legal penalties, financial loss, or reputational damage. As a recognized expert, you will implement and maintain security, authorization, and compliance standards for SAP ERP platform systems and data products, providing leadership across both on‑premise and cloud SAP Data platform ecosystems.
Responsibilities
- Implement and maintain security, authorization, and compliance standards for SAP platforms (SAP BW 7.5 HANA, SAP BW4HANA, and SAP Datasphere).
- Develop and mature capabilities in cloud compliance and security, particularly within SAP Datasphere.
- Continuously monitor relevant regulations (e.g., GDPR, CCPA, HIPAA, SOX) and industry standards (e.g., ISO27001, SOC2, NIST) to ensure the platform remains ahead of global compliance requirements.
- Drive the creation and refinement of internal policies and data governance frameworks to maintain high standards of integrity, security, and structured data handling.
- Act as the System Owner Deputy and Control Owner, taking accountability for the end‑to‑end ICFR (Internal Control over Financial Reporting) lifecycle, GxP controls, and other relevant regulations.
- Lead weekly and monthly monitoring of SoD (Segregation of Duties) conflicts via GRC dashboards, work with SoD Champions to mitigate risks, and address non‑compliant items flagged in the SAP Security Standards documentation.
- Oversee application error reviews (e.g., failed jobs) and sign off on monitoring results in tools like ICAt to provide evidence for control checks.
- Perform quarterly reviews of critical access, GRC FireFighter roles (Controllers, Owners, Admins), and HANA DB users, initiating timely removals to maintain a "least privilege" environment.
- Lead ICFR IT audit support by defining control activities, approving auditor documentation, and acting as the primary point of contact for auditors during peak cycles (Sep/Oct).
- Set technological development directions by analyzing and implementing new solutions, tools, and IT standards, with a focus on data governance, validation, and automation.
- Annually review and update the System Risk Assessment (SRA) and Data Classification to ensure alignment with the Minimum Security Baseline.
- Actively conduct innovation projects to optimize processes, introduce new solutions, and increase efficiency through automation in Data products.
- Partner with system teams and stakeholders to ensure task ownership, bridge data privacy awareness gaps, and onboard/train new team members on ICFR control activities.
Qualifications
- Bachelor’s Degree in Computer Science, IT, or Engineering with a minimum of 5 years’ post‑secondary experience in SAP Security and a deep understanding of Compliance.
- Proven track record in IT security/authorization and compliance projects, specifically acting as a Subject Matter Expert for ICFR, GxP, and GRC environments.
- Working knowledge of SAP BW, HANA Studio, SAP BI, and SAP Datasphere. Familiarity with new trends in SAP Analytics, authorizations, and the AI space.
- Strong understanding of SoDs, critical access, access controls, and pharmaceutical industry best practices including SAP audit guidelines.
- Experience with Data Products and Data Governance principles and practices.
- Experience in IT system validation processes and conducting System Risk Assessments (SRA), including Data Privacy requirements.
- Strong ability in root cause analysis, providing solutions to complex system processes, and driving remediation to completion.
- Ability to manage an external workforce/squad, adhering to dynamic targets and timelines in an Agile (SAFe/Scrum) environment.
- English proficiency with excellent interpersonal skills to collaborate effectively with diverse teams and lead training sessions for ICFR onboarding.
- Adaptability to quickly learn new technologies and compliance frameworks in a fast‑paced, regulated global organization.
Benefits
- Salary range 14,000 – 26,000 PLN gross based on the employment contract.
- Annual bonus payment based on performance (target 15%).
- Dedicated training budget for certifications, conferences, diversified career paths, etc.
- Recharge Fridays (2 Fridays off per quarter available).
- Take Time Program (up to 3 months of leave for any purpose).
- Vacation subsidy available.
- Flex Location (possibility to perform work from different places worldwide for a certain period).
- Take Time for Charity (additional paid leave of maximum 2 weeks to engage in charity action).
- Private healthcare (LuxMed packages), group life insurance (UNUM) and Multisport.
- Stock share purchase additions.
- Yearly sales of company laptops and cars and many more!
Legal & Equal Opportunity
Roche is an Equal Opportunity Employer.
The controller of your personal data is Roche Polska Sp. z o.o., ul. Domaniewska 28, 02-672 Warsaw. The data is processed for the purpose of recruitment. You have the right to access your data, rectify it, delete it, limit processing, transfer it and - if processing is based on your consent - withdraw this consent at any time. Contact the Data Protection Officer at: ochrona.danych@roche.com. More information on the principles of processing your personal data by Roche at: https://www.roche.pl/pl/content/klauzula-informacyjna-rekrutacja-en.html Roche Polska sp. z o.o. operates in full compliance with the law and does not tolerate any violations. Roche Polska sp. z o.o. has implemented a Procedure for Reporting Violations of Law. If you wish to report any irregularities related to our activities, all necessary information regarding the reporting process can be found on our website: https://www.roche.pl/kontakt/ochrona-sygnalistow-zglaszanie-naruszen.