SAP Security & Identity Access Mgmnt Director

Amrize

Nashville (TN)

On-site

USD 180,000 - 240,000

Full time

10 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

401(k) plan
Employee Stock Purchase Plan
Medical Insurance
Paid time off
Educational Assistance Program
Dress for your day

Job summary

Amrize in Nashville, TN seeks a SAP Security & Identity Access Mgmnt Director to own SAP security and access governance across the SAP landscape, ensuring robust SOX compliance and driving IAM maturity. The role requires 10+ years of SAP security depth and strong leadership of SAP and IAM teams.

You will lead strategic governance across RBAC/ABAC, GRC, and identity platforms (Saviynt, BeyondTrust/CyberArk, Google Workspace, Azure AD), with significant interaction with auditors and business

Qualifications

  • 15+ years in SAP Security, IAM, or Cybersecurity with hands-on SAP security experience.
  • Deep expertise in SAP role design, SoD governance, GRC operations, and SOX compliance.
  • 5+ years in leadership roles managing teams and programs across SAP and IAM.
  • Hands-on experience with Saviynt IGA and at least one PAM solution (BeyondTrust or CyberArk).
  • Proven track record supporting SOX-regulated environments with audit engagement.

Responsibilities

  • Lead SAP Security and IAM teams; foster accountability and continuous improvement.
  • Provide hands-on SAP security guidance for complex role design, SoD, and GRC challenges.
  • Own demand management, prioritization, and resource planning across SAP and IAM portfolios.
  • Oversee SAP GRC operations: ARA, ARM, EAM, Process Control; drive standardization and automation.
  • Drive Saviynt IGA onboarding and governance; manage certifications and joiner/mover/leaver processes.
  • Build and mature PAM capabilities using BeyondTrust/CyberArk; enforce least-privilege policies.

Skills

SAP Security
RBAC / Role Design
SoD Governance
GRC Operations
SOX Compliance
IAM Strategy
Audit Liaison
Strategic Thinking
Executive Communication
Leadership

Education

Bachelor's degree
Master's degree (preferred)

Tools

Saviynt IGA
BeyondTrust/CyberArk PAM
Google Workspace
Azure Active Directory
SAP GRC tools

Job description

We’re seeking a SAP Security & Identity Access Mgmnt Director who’s ready to put your skills to work on projects that matter — and build a career with a company that’s building North America.

Job Title: SAP Security & Identity Access Mgmnt Director | Req ID: 18056 | Location: Chicago Office IL, Building Envelope - Corp Nashville, TN

ABOUT THE ROLE

This role sits at the heart of the Cybersecurity organization. The Director will own the SAP security and access governance strategy across the full SAP landscape, ensuring robust SOX compliance, while also providing strategic direction for the broader enterprise IAM function across Identity Governance, Privileged Access, and Access Management pillars.

The ideal candidate brings 10+ years of hands-on SAP security depth - from role design and SoD ruleset management to GRC operations and audit excellence - and has sufficient IAM breadth to drive maturity across Saviynt, BeyondTrust/CyberArk, and Google/Azure identity platforms.

WHAT YOU'LL ACCOMPLISH
  • Strategic Leadership & Team Management
  • Lead and develop high-performing SAP Security and IAM teams, fostering accountability and continuous improvement
  • Act as a player-coach: provide hands-on SAP security guidance for complex role design, SoD, and GRC challenges
  • Own demand management, prioritization, and resource planning across both SAP and IAM portfolios
  • Build team capability in both SAP security operations and IAM disciplines
  • SOX Compliance & Audit
  • Own all SAP controls supporting SOX compliance (ITGCs and application-level access controls)
  • Serve as the primary liaison for internal and external auditors on SAP access and security topics
  • Translate technical SAP controls into clear, business-aligned compliance narratives
  • Ensure high-quality, consistent audit evidence and drive remediation of any audit findings
  • Segregation of Duties (SoD)
  • Lead end-to-end SoD governance including definition, maintenance, and enforcement of SoD rule sets
  • Identify and document mitigating controls for approved SoD conflicts; own ongoing monitoring
  • Drive periodic access reviews and certification campaigns aligned to SOX requirements
  • Role Design & RBAC
  • Govern and evolve the enterprise SAP role catalog including business roles and single roles Lead transformation toward modern role-based and attribute-based access control (RBAC/ABAC) models Define and enforce role design standards, naming conventions, and governance frameworks Manage the full role lifecycle: design, testing, deployment, and ongoing maintenance
  • SAP GRC & Operations
  • Provide end-to-end ownership of SAP security across S/4HANA, ECC, BTP, and Fiori landscapes Oversee SAP GRC implementation and optimization: Access Risk Analysis (ARA), Access Request Management (ARM), Emergency Access Management (EAM), and Process Control Drive standardization, automation, and efficiency in day-to-day SAP security operations Manage transport security (STMS) implications and security patching cadence
  • Identity Governance (Saviynt)
  • Act as product owner for the Saviynt IGA platform, driving adoption, configuration, and maturity Lead onboarding of enterprise applications into Saviynt and expand governance coverage Drive automation of joiner/mover/leaver processes and access certifications
  • Privileged Access Management (BeyondTrust / CyberArk)
  • Build and mature PAM capabilities leveraging BeyondTrust and/or CyberArk Ensure privileged account discovery, vaulting, session recording, and just-in-time access controls Define PAM policies and standards aligned to least-privilege principles
  • Access Management (Google Workspace / Azure AD)
  • Oversee access management and SSO integrations across Google Workspace and Azure Active Directory Drive federation, conditional access policies, and MFA enforcement strategies Ensure access management platforms align with enterprise IAM governance standards
  • Risk Reduction & Operational Excellence
  • Reduce enterprise risk through strong access governance, SoD controls, and PAM maturity Drive automation and efficiency across SAP security and IAM operations Partner with business, IT Compliance, and audit stakeholders to balance security, compliance, and user experience Championing a zero-reportable-incidents mindset through proactive access controls and monitoring
  • Stakeholder Engagement & Influence
  • Serve as a trusted advisor to senior leadership, IT, Finance, and business teams on SAP security and IAM topics Champion SAP security and IAM as business enablers, not just compliance requirements Drive alignment between cybersecurity strategy and enterprise growth initiatives
  • Demonstrate a commitment to communicating, improving and adhering to health, safety and environmental policies in all work environments and areas. Promote a culture of safety and exhibit these behaviors.
WHAT WE’RE LOOKING FOR

Education: Bachelor's degree

Additional Education Preferred: Master's degree

Field of Study Preferred:

Information security, Computer Science, Finance, or related field required

Required Work Experience:
  • 15+ years in SAP Security, IAM, or Cybersecurity, with the majority of tenure in hands‑on SAP security roles
  • Deep, demonstrable expertise in SAP role design, SoD governance, GRC operations, and SOX compliance
  • 5+ years in leadership roles managing teams and programs; experience leading both SAP and IAM functions preferred
  • Hands‑on experience with Saviynt IGA and at least one PAM solution (BeyondTrust or CyberArk)
  • Proven background supporting SOX-regulated environments with direct audit engagement
Required Training/Certifications:
  • CISSP, CISM, CISA, or CRISC (preferred)
  • SAP Security or SAP GRC certifications (preferred)
  • Saviynt, CyberArk, or BeyondTrust platform certifications (preferred)

Travel Requirements : 30-40%

Required Technical Skills : SAP Security Must Have:
  • S/4HANA Security
  • ECC Security
  • BTP & Fiori
  • HANA DB Security
  • SAP GRC ARA
  • SAP GRC ARM
  • SAP GRC EAM
  • Process Control
  • SoD Rule Sets
  • Mitigating Controls
  • RBAC / Role Design
SOX / ITGC Compliance IAM Platforms - Strong Familiarity:
  • Saviynt (IGA)
  • BeyondTrust (PAM)
  • CyberArk (PAM)
  • Google Workspace
  • Azure Active Directory
  • Identity Lifecycle Mgmt
  • Access Certifications
  • Federation / SSO
Additional Requirements:
  • Strategic thinker with strong hands‑on execution in SAP security environments
  • Deep technical credibility in SAP security coupled with broad IAM awareness
  • Exceptional communication skills — able to translate SoD and access risks into business impact
  • Collaborative leader who can influence without authority across IT, Finance, and Compliance
  • Strong audit presence and composure under SOX scrutiny
  • Ability to manage complexity across a dual SAP + IAM portfolio
  • Successful candidates must adhere to all safety protocols and proper use of Amrize approved Personal Protection Equipment ("PPE"), including but not limited to respirators. Subject to applicable law, employees that are required to wear respirators must be clean shaven where the respirator seal meets the face in order to pass the qualitative and quantitative fit tests.
WHAT WE OFFER
  • Competitive salary
  • Retirement Savings: Choose from 401(k) pre-tax and/or Roth after-tax savings
  • Employee Stock Purchase Plan
  • Medical, Dental, Disability and Life Insurance
  • Holistic Health & Well-being programs
  • Health Savings Accounts (HSAs) & Flexible Spending Accounts (FSAs) for health and dependent care
  • Vision and other Voluntary benefits and discounts
  • Paid time off & paid holidays
  • Paid Parental Leave (maternity & paternity)
  • Educational Assistance Program
  • Dress for your day

#LI-SZ1

Amrize is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

We thank all applicants for their interest; however, only those selected for an interview will be contacted.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. SAP Security Analyst
Sr. SAP Security Analyst

Carex Consulting Group • Madison (WI)

On-site
USD 110,000 - 150,000
Sr. Analyst, IT - SAP Security Controls
Sr. Analyst, IT - SAP Security Controls

Verano • Chicago (IL), Northern (KY)

On-site
USD 130,000 - 150,000
Manager, Identity and Access Management (IAM)
Manager, Identity and Access Management (IAM)

American Sugar Refining • West Palm Beach (FL)

On-site
USD 150,000 - 190,000
SAP Security Manager
SAP Security Manager

CRH • Atlanta (GA)

On-site
USD 130,000 - 170,000
Competitive base pay
Comprehensive benefits package
Retirement savings program
+2
SAP Security Lead
SAP Security Lead

FCX Performance • Cleveland (OH)

Hybrid
USD 140,000 - 180,000
SAP Security Lead
SAP Security Lead

Applied Industrial Technologies • Cleveland (OH)

On-site
USD 130,000 - 180,000
ERP Security and GRC Analyst IV - United States (Remote) at V2X United States
ERP Security and GRC Analyst IV - United States (Remote) at V2X United States

V2X • United States

Hybrid
USD 110,000 - 175,000
Healthcare coverage
Paid time off
Retirement plan
+2
SAP NS2 Director, Cloud Infrastructure & DevSecOps
SAP NS2 Director, Cloud Infrastructure & DevSecOps

SAP • Austin (TX)

On-site
USD 176,000 - 374,000
SAP NS2 Sr Security Automation Engineer
SAP NS2 Sr Security Automation Engineer

SAP • Herndon (VA)

On-site
USD 131,000 - 272,000
Manager, Identity and Access Management (IAM)
Manager, Identity and Access Management (IAM)

ASR Group • West Palm Beach (FL)

On-site
USD 140,000 - 170,000