ABOUT THE DOYLE GROUP
The Doyle Group is a proven partner for Placement and Consulting services, headquartered in Denver, CO. Our core mission is to forge genuine partnerships with our clients who seek strategic talent solutions and to assist highly skilled candidates looking for their next career opportunity. With over 30 years of industry experience, our consultative approach allows us to provide a higher level of guidance and insight, empowering our clients to secure top IT talent that fits seamlessly into their team and culture. We look forward to collaborating to help you achieve your career goals.
POSITION SUMMARY
Our client is an industry‑leading, rapidly scaling quantum computing company that recently went public and is expanding its SAP S/4HANA footprint globally. As part of that growth, the company is redesigning its SAP security model from the ground up — replacing a legacy, brownfield structure that has grown unevenly over time, where access has been layered on for years without a clear picture of what any given user actually holds.
This is a high‑priority, highly visible hire. SAP security and Governance, Risk, and Compliance (GRC) touch nearly every part of the business, and the SAP Security Specialist will serve as the primary interface between the SAP team and stakeholders across Finance, Internal Audit, and Information Security who are managing SOX audits and access governance. The company recently went public and is in the middle of a deliberate, patient build‑out of its internal controls environment, working alongside an internal SOX compliance lead and an external audit advisory partner — this role will be a key contributor to that effort.
This is an individual contributor role reporting to the SAP Team Manager, with no direct reports. It's best suited to someone who wants full ownership of SAP security and GRC at a company that is actively building its security maturity, not simply maintaining what's already in place.
This is a hybrid position based out of Broomfield, CO (preferred) or Brooklyn Park, MN; candidates open to relocation will also be considered.
Candidates must be authorized to work in the United States without current or future visa sponsorship.
RESPONSIBILITIES
- Own the design, build‑out, and ongoing optimization of SAP security roles and authorization models across SAP applications.
- Lead the redesign of a legacy, brownfield security structure into a scalable, well‑governed role and authorization model as the company grows globally.
- Administer and support the SAP GRC solution, including Access Control workflows and Segregation of Duties (SoD) monitoring.
- Analyze access risk and recommend mitigation strategies aligned with the company's security and compliance standards.
- Serve as the primary point of contact for SOX compliance and security‑related needs across Finance, Internal Audit, and other business stakeholders.
- Generate audit evidence and documentation to support SOX compliance reviews and internal or external audits, partnering with the company's SOX compliance lead and external audit advisors.
- Coordinate periodic user access reviews and certification activities.
- Partner with business process owners to validate security requirements and approve access requests.
- Support testing and validation of security‑related changes, role modifications, and GRC configuration updates.
- Participate in SAP projects, upgrades, and implementations to ensure security and compliance requirements are built in from the start.
- Investigate and resolve SAP security incidents, access issues, and authorization errors.
- Develop and maintain security documentation, procedures, and standards as the team builds toward greater process maturity.
- Coordinate with the internal Information Security team on network, infrastructure, and data security matters that intersect with SAP access.
- Identify opportunities to automate and streamline security administration and compliance processes.
MINIMUM EXPERIENCE
- 5+ years of SAP security administration experience, including designing and maintaining SAP roles, authorizations, and user access controls.
- 2+ years administering SAP GRC Access Control or a comparable compliance solution, including:
- Access Control workflows
- Segregation of Duties (SoD) monitoring and remediation
- Access risk analysis
- Experience supporting SOX compliance activities and audit evidence collection.
- Solid understanding of Segregation of Duties (SoD) concepts and risk mitigation controls.
- Experience testing and validating SAP security and authorization changes.
- Experience with SAP S/4HANA's security model specifically — this is meaningfully different from legacy ECC security and candidates should be comfortable working within it.
- Experience with SAP Fiori security, including catalogs, groups, spaces, and pages.
- Bachelor's degree or equivalent professional experience.
- Must be legally authorized to work in the United States without sponsorship now or in the future.
ADDITIONAL PLUS
- Hands‑on experience with ControlPanelGRC (CPGRC) or a similar third‑party GRC tool used in place of SAP's native GRC.
- Experience supporting multiple SAP modules (Finance, Supply Chain, Procurement, Manufacturing).
- Experience working at a company that recently went public, or otherwise navigating a maturing internal controls environment.
- SAP Security or GRC certifications.
- Experience preparing for and directly supporting external audit engagements.
- Understanding of internal controls frameworks and regulatory compliance requirements.
- Experience with SAP Private Cloud or RISE with SAP environments.