SAP GRC and HANA Security Consultant

Kyndryl Inc.

Singapore

On-site

SGD 120,000 - 180,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Kyndryl is seeking an SAP GRC and HANA Security Consultant to design, implement, and govern access controls across our SAP landscape. This hands-on role covers GRC Access Control, HANA security, and SAP application security, with a strong emphasis on audit readiness and SOX ITGC.

You will build and maintain role architecture for S/4HANA, HANA, and Fiori, manage GRC end-to-end, and interact with auditors and business owners to ensure compliant access controls.

Qualifications

  • Bachelor's degree in CS, IS, or related field or equivalent experience.
  • 5+ years hands-on SAP security experience, incl. at least 3 years with SAP GRC Access Control 10.x/12.0.
  • Hands-on HANA security administration: roles, privileges, analytic privileges, and audit policies.
  • Strong PFCG role design, authorization objects, SU24 maintenance, and trace-based troubleshooting.
  • Experience with S/4HANA and Fiori security concepts.
  • Experience supporting SOX ITGC or equivalent audits in an SAP environment.
  • Proven ability to remediate segregation-of-duties conflicts and design mitigating controls.
  • Clear written and verbal communication to explain risk to stakeholders.

Responsibilities

  • Configure, administer, and support SAP GRC Access Control across modules ARA, ARM, BRM, and EAM.
  • Maintain and customize SoD ruleset; apply updates and assess landscape impact.
  • Design MSMP workflows, BRF+ rules, and approval paths for access requests and role changes.
  • Perform periodic risk analysis at user, role, and profile levels; drive remediation and mitigating controls.
  • Administer User Access Reviews, SoD Review, and Firefighter log reviews; track completion.
  • Support GRC Process Control, Risk Management, and Audit Management; evaluate migration to IAG.
  • Administer HANA security: catalog/roles, privileges, auditing, and encryption.
  • Configure and monitor HANA audit policies; provide forensic trails.
  • Set up SSO and authentication methods (SAML 2.0, Kerberos, X.509).
  • Lead security workstreams for S/4HANA implementations; role redesign and remediation.
  • Troubleshoot authorization failures and provide L3 security incident support.

Skills

GRC Access Control
HANA Security
PFCG Role Design
S/4HANA Security
SoD & Audit
SOX ITGC
Communication Skills

Education

Bachelor's degree in Computer Science, Information Systems, or related field

Job description

Who We Are

At Kyndryl, we run and reimagine the mission-critical technology systems that drive advantage for the world’s leading businesses. We are at the heart of progress; with proven expertise and a continuous flow of AI-powered insight, enabling smarter decisions, faster innovation, and a lasting competitive edge. For our people—Kyndryls—that means doing purposeful work that powers human progress. Join us and experience a flexible, supportive environment where your well-being is prioritized and your potential can thrive.

The Role

We are looking for an SAP GRC and HANA Security Consultant to design, implement, and govern access controls across our SAP landscape. This role sits at the intersection of technical security administration and compliance: you will build and maintain role architecture across S/4HANA, HANA database, and Fiori, run our GRC Access Control platform end to end, and act as the primary technical contact for internal and external auditors on SAP access matters. This is a hands‑on position for someone who is equally comfortable writing an analytic privilege in HANA Studio, remediating a segregation-of-duties conflict in ARA, and explaining both to a non-technical control owner.

Key Responsibilities
SAP GRC Access Control
  • Configure, administer, and support SAP GRC Access Control 10.1/12.0 across all four modules: Access Risk Analysis (ARA), Access Request Management (ARM), Business Role Management (BRM), and Emergency Access Management (EAM/Firefighter).
  • Maintain and customize the SoD ruleset — add custom risks, functions, and organizational rules; apply SAP-delivered ruleset updates and assess landscape impact.
  • Design and maintain MSMP workflows, BRF+ rules, and approval paths for access requests and role change management.
  • Perform periodic risk analysis at user, role, and profile level; drive remediation and design compensating/mitigating controls with business process owners.
  • Administer User Access Reviews (UAR), SoD Review, and Firefighter log reviews; track completion and elevate exceptions.
  • Support GRC Process Control, Risk Management, and Audit Management where in scope, and evaluate migration to SAP Cloud Identity Access Governance (IAG).
SAP HANA Security
  • Administer HANA database security: catalog and repository roles, users, system/object/analytic/package/application privileges, and privilege inheritance design.
  • Implement row‑and column‑level security through analytic privileges, and configure static and dynamic data masking for sensitive data.
  • Manage HDI container security and XS Advanced (XSA) roles, role collections, and OAuth/UAA configuration.
  • Configure and monitor HANA audit policies; produce audit trails for privileged activity and support forensic review.
  • Manage encryption (data volume, redo log, backup), certificate management, and TLS/SSL configuration.
  • Set up and support SSO and authentication methods including SAML 2.0, Kerberos, and X.509 certificates.
  • Administer security through HANA Cockpit and HANA Cloud Central, including HANA Cloud tenant security where applicable.
SAP Application Security
  • Design, build, and maintain PFCG roles for S/4HANA, ECC, BW/4HANA, and Solution Manager using SU24, SUIM, and authorization trace analysis (STAUTHTRACE/ST01).
  • Build and maintain Fiori security: catalogs, groups, spaces and pages, tile‑to‑role mapping, and front‑end/back‑end role pairing.
  • Support security for connected platforms — SAP BTP, SuccessFactors, Ariba, SAC, and CUA‑managed systems.
  • Lead security workstreams for S/4HANA implementations, upgrades, and greenfield/brownfield conversions, including role redesign and remediation of legacy authorization concepts.
  • Troubleshoot authorization failures and performance issues, and provide L3 support for security incidents.
Compliance, Audit, and Governance
  • Serve as SAP security subject matter expert for SOX ITGC, internal audit, and external audit walkthroughs; prepare evidence and respond to audit requests and findings.
  • Enforce and improve access governance policy, including provisioning, deprovisioning, privileged access, and emergency access procedures.
  • Support data privacy requirements (GDPR and equivalent) as they apply to SAP access and data exposure.
  • Produce documentation: role design specifications, security concepts, runbooks, and control narratives.
Delivery and Collaboration
  • Work with Basis, functional, development, and infrastructure teams on cross‑functional design decisions.
  • Partner with business process owners to translate compliance requirements into workable role and control design.
  • Mentor junior security analysts and contribute to team standards and knowledge base.
Who You Are
Required Qualifications
  • Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent practical experience.
  • 5+ years of hands‑on SAP security experience, including at least 3 years with SAP GRC Access Control 10.x or 12.0.
  • Demonstrated hands‑on experience with SAP HANA security administration — roles, privileges, analytic privileges, and audit policies — not solely at the application layer.
  • Strong working knowledge of PFCG role design, authorization objects, SU24 maintenance, and trace‑based troubleshooting.
  • Experience with S/4HANA and Fiori security concepts, including catalog and space/page design.
  • Practical experience supporting SOX ITGC or equivalent audit and compliance requirements in an SAP environment.
  • Proven ability to analyze and remediate segregation‑of‑duties conflicts and design mitigating controls.
  • Clear written and verbal communication, with the ability to explain technical access risk to business and audit stakeholders.
Preferred Qualifications
  • Experience with SAP Cloud Identity Access Governance (IAG) or migration from GRC AC to IAG.
  • Experience with SAP Identity Management (IDM), SAP Cloud Identity Services (IAS/IPS), or third‑party IGA tools such as SailPoint or Saviynt.
  • Exposure to SAP BTP security, including role collections, trust configuration, and destination security.
  • Experience with HANA Cloud, HDI, and XSA‑based development security.
  • Full lifecycle S/4HANA implementation or conversion experience in a security lead capacity.
  • Scripting or automation experience (ABAP, Python, PowerShell) for reporting and provisioning tasks.
  • Certifications such as SAP Certified Application Associate – GRC Access Control 12.0, SAP Certified Technology Associate – SAP HANA, CISA, CISSP, or CRISC.
Being You

The “Kyn” in Kyndryl means kinship, which represents the strong bonds we have with each other, our customers and our communities. We focus on ensuring all Kyndryls feel included and we welcome people of all cultures, backgrounds, and experiences. Even if you don’t meet every requirement, we encourage you to apply. We believe in growth, and we’re excited to see what you can bring. At Kyndryl, employee feedback has told us that our number one driver of employee engagement is belonging. That sense of belonging - being a valued, respected, trusted member of the team - is fundamental to our culture and fueling great experiences for our customers. This dedication to welcoming everyone into our company means that Kyndryl gives you the ability to thrive and contribute to our culture of empathy and shared success. That’s The Kyndryl Way.

What You Can Expect

Your career with us isn’t just a job—it’s an adventure with purpose. We offer a dynamic, hybrid‑friendly culture that supports your well‑being and empowers you to grow. Our Be Well programs are thoughtfully designed to support your financial, mental, physical, and social health - because we know that when you feel your best, you do your best. From your very first day, you’ll dive into impactful work that powers the systems our customers rely on every day. You won’t just contribute—you’ll make a difference, tackling meaningful projects that sharpen your skills and fuel your growth. We’re here to champion your journey. With powerful tools to chart your career path, personalized development goals aligned with your ambitions, and continuous feedback to keep you inspired and on track, you’ll have everything you need to thrive and evolve. You’ll develop in‑demand skills to grow your career and achieve your ambitions with access to cutting‑edge learning opportunities - from certifications with Microsoft, Google, and Amazon to coaching and hands‑on experiences. And through it all, you’ll be part of a culture that values empathy, restless learning, and a devotion to shared success. We want you to thrive here—and we’re committed to helping you do just that.

At Kyndryl, we achieve progress the world depends on, with purpose. Beginning with the purpose that matters to you. Because here, you will be part of a culture designed with purpose. One that is restless, empathetic and devoted. Where we are committed to sustainable progress for our customers and supporting the communities where we work and live. All of you is what we want. And what we need. Join us, and together, we can advance the vital systems that power human progress.

Ready to make an impact? Join us and help shape what’s next.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SAP GRC and HANA Security Consultant at Kyndryl
SAP GRC and HANA Security Consultant at Kyndryl

Kyndryl • Singapore

On-site
SGD 160,000 - 210,000
SAP GRC and HANA Security Consultant
SAP GRC and HANA Security Consultant

Kyndryl • Singapore

Hybrid
SGD 120,000 - 180,000
Cloud Security Engineer
Cloud Security Engineer

Kyndryl • Singapore

On-site
SGD 120,000 - 160,000
Be Well program
Hybrid-friendly culture
Solution Architect
Solution Architect

Kyndryl Inc. • Singapore

On-site
SGD 180,000 - 260,000
Project Manager
Project Manager

Kyndryl Inc. • Singapore

Hybrid
SGD 90,000 - 150,000
Be Well program
Hybrid-friendly culture
Certification opportunities (Microsoft
+2
Senior Linux & Cloud Platform Engineer
Senior Linux & Cloud Platform Engineer

Kyndryl Inc. • Singapore

Hybrid
SGD 70,000 - 95,000
Senior Linux & Cloud Platform Engineer
Senior Linux & Cloud Platform Engineer

Kyndryl • Singapore

Hybrid
SGD 60,000 - 100,000
Full Stack Engineer (GenAI )
Full Stack Engineer (GenAI )

Kyndryl • Singapore

Hybrid
SGD 90,000 - 130,000
Project Manager
Project Manager

Kyndryl • Singapore

Hybrid
SGD 120,000 - 180,000
Quality Automation Engineer
Quality Automation Engineer

re-zoo-me • Singapore

Hybrid
SGD 90,000 - 150,000
Be Well program
Hybrid-friendly culture