Security Engineer IV

ViziRecruiter,LLC.

Salisbury (NC)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ahold Delhaize USA is seeking a Security Engineer IV focused on SAP Security, IAM, and GRC within the Retail Spine SAP landscape. You will design roles, implement access controls, and ensure audit readiness across S/4HANA, Fiori, and SAP BTP, collaborating with SAP teams, Audit, and InfoSec.

Ideal candidates bring 10+ years in SAP Security and GRC, strong SoD and audit experience, and the ability to partner with multi-vendor delivery teams to maintain secure, compliant SAP operations in a

Qualifications

  • Bachelor's degree in IT, cybersecurity, CS or related field.
  • 10+ years of SAP Security and SAP GRC Access Control experience.
  • Strong hands-on SAP role design, SoD, Firefighter, and audit/compliance expertise.
  • Experience with SAP S/4HANA, HANA, Fiori, and SAP BTP security.
  • Experience with multi-vendor delivery and SI partners.
  • SOX, PCI, GDPR knowledge and enterprise security standards.

Responsibilities

  • Provide SAP Security and GRC operations support across S/4HANA, BTP, Fiori, and integrated systems.
  • Own SAP role design, catalog governance, and SoD frameworks.
  • Define and govern identity and access management integration standards, including SSO, MFA, and Azure AD/Entra federation.
  • Support SAP GRC platform operations covering Access Control, Firefighter and Emergency Access Management, audits.
  • Own SOX, PCI, GDPR, and audit readiness for the SAP landscape with governance partners.
  • Ensure security across release lifecycle, transport reviews, and change controls.
  • Govern security obligations of SI and vendor partners; maintain secure design standards.
  • Partner with SAP Tech leadership to define secure patterns aligned to SAP RISE and Retail Spine.
  • Establish KPIs for SAP Security and GRC; drive continuous improvement.
  • Provide security support during go-lives and major transformation waves.

Skills

SAP Security
GRC Access Control
Role design
SoD
Firefighter access
Audit & Compliance
S/4HANA
HANA
Fiori
SAP BTP
Identity security

Education

Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field

Tools

Azure AD/Entra ID
SSO
MFA
GRC tools

Job description

Introduction

Ahold Delhaize USA, a division of global food retailer Ahold Delhaize, is part of the U.S. family of brands, which also includes five leading omnichannel grocery brands – Food Lion, Giant Food, The GIANT Company, Hannaford and Stop & Shop. Ahold Delhaize USA associates support the brands with a wide range of services, including Finance, Legal, Sustainability, Commercial, Digital and E-commerce, Technology and more.

Overview

Ahold Delhaize USA, a division of global food retailer Ahold Delhaize, is part of the U.S. family of brands, which includes five leading omnichannel grocery brands - Food Lion, Giant Food, The GIANT Company, Hannaford and Stop & Shop. Our associates support the brands with a wide range of services, including Finance, Legal, Sustainability, Commercial, Digital and E-commerce, Technology and more.

Primary Purpose

The Security Engineer IV is responsible for SAP Security, Identity & Access Management (IAM), and Governance, Risk & Compliance (GRC) operations in support of the Retail Spine transformation, a business led, IT enabled modernization initiative aimed at strengthening long term competitiveness, improving operational efficiency, and establishing future state enterprise capabilities. This engineer is responsible for role design, access controls, compliance, and audit readiness across all SAP S/4HANA and integrated systems. The Engineer partners closely with the SAP Functional teams, business process owners, Audit, InfoSec, Systems Integrator, and third party technology providers to ensure secure, compliant, and scalable SAP operations that enable Retail Spine program success.

Responsibilities
  • Provide strategic and operational support across SAP Security and GRC functions, ensuring a secure, compliant, and well-governed technical landscape spanning S/4HANA, BTP, Fiori, and all integrated systems within the RISE with SAP environment.
  • Own the SAP role design standard, including role catalog governance, authorization concept, segregation of duties (SoD) frameworks, mitigation controls, and access request workflows ensuring designs are clean core aligned and sustainable across the programme lifecycle.
  • Define and govern identity and access management integration standards, including SSO, MFA, and Azure AD/Entra ID federation, in partnership with Enterprise Security and SI architects ensuring secure, scalable identity patterns are established and enforced across the SAP landscape.
  • Support SAP GRC platform operations covering Access Control (AEM, ARM, BRM, EAM), Firefighter and Emergency Access Management processes, periodic access reviews, SoD conflict analysis, and continuous controls monitoring maintaining audit-ready posture at all times.
  • Own SOX, PCI, GDPR, and internal and external audit readiness for the SAP landscape, including access control evidence management, risk logs, mitigation plans, and remediation tracking in close partnership with Internal Audit, External Audit, and Enterprise InfoSec.
  • Ensure security is embedded across the full release lifecycle covering transport reviews, role change impact assessments, interface security validations, and landscape change controls operating consistently across agile, hybrid, and waterfall delivery models.
  • Govern the security obligations and deliverables of the SI and vendor partners, ensuring secure solution design, adherence to established standards, quality of security-related work products, and timely risk escalation and remediation
  • Partner with SAP Technology leadership and Solution Architects to define and maintain secure solution patterns, hardening standards, and security architecture aligned to the RISE with SAP shared responsibility model and Retail Spine future state architecture.
  • Establish and maintain KPIs and operational metrics for SAP Security and GRC functions including role change cycle time, access request SLA adherence, SoD remediation velocity, and audit finding closure rates and drive continuous improvement through automation and process optimization across IAM and GRC workflows.
  • Provide security support during go-lives, cutovers, system refreshes, environment provisioning, and major Retail Spine transformation waves ensuring security controls are validated, access is appropriately provisioned, and risk is formally accepted or mitigated prior to each milestone.
Requirements
  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field.
  • 10+ years of experience in SAP Security and SAP GRC Access Control.
  • Strong hands on experience with SAP role design, SoD, Firefighter, GRC Access Control, and audit/compliance frameworks.
  • Working knowledge of SAP S/4HANA, HANA, Fiori, SAP BTP, and integrated security architecture.
  • Experience partnering with System Integrators and managing multi vendor delivery models.
  • Strong understanding of SOX, PCI, GDPR, and enterprise security standards.
  • Excellent communication, stakeholder engagement, and leadership skills.
Preferred Qualifications
  • Master's degree in Cybersecurity, Technology Management, or related discipline.
  • SAP or security certifications (e.g., SAP Security, SAP GRC, CISM, CISSP, CISA).
  • Experience supporting large scale SAP transformations, including S/4HANA migrations or RISE with SAP models.
  • Knowledge of identity governance (IGA), privileged access management (PAM), and cloud security patterns.
  • Background in retail, consumer goods, or other high volume transaction environments.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager SAP Security & GRC Manager SAP Basis/Tech Platform
Manager SAP Security & GRC Manager SAP Basis/Tech Platform

ViziRecruiter,LLC. • Salisbury (NC)

On-site
USD 120,000 - 150,000
Manager SAP Security & GRC
Manager SAP Security & GRC

ViziRecruiter,LLC. • Salisbury (NC)

On-site
USD 110,000 - 140,000
Senior SAP Security & IAM Engineer
Senior SAP Security & IAM Engineer

ViziRecruiter,LLC. • Salisbury (NC)

On-site
USD 120,000 - 180,000
SAP GRC and Cloud Security Specialist
SAP GRC and Cloud Security Specialist

Variety Staffing • New Jersey

On-site
USD 110,000 - 130,000
Manager SAP Basis/Tech Platform
Manager SAP Basis/Tech Platform

ViziRecruiter,LLC. • Salisbury (NC)

On-site
USD 110,000 - 140,000
SAP Security Engineer
SAP Security Engineer

Jobtailor • Dearborn (MO)

On-site
USD 120,000 - 150,000
SAP Security / GRC - Roles, Authorizations, Compliance
SAP Security / GRC - Roles, Authorizations, Compliance

datacoresystems • Harrisburg

On-site
USD 90,000 - 120,000
Director, SAP Platform Engineering & Security
Director, SAP Platform Engineering & Security

ViziRecruiter,LLC. • Salisbury (NC)

Hybrid
USD 185,000 - 279,000
SAP Security / GRC - Roles, Authorizations, Compliance
SAP Security / GRC - Roles, Authorizations, Compliance

Data-Core System, Inc • Harrisburg

On-site
USD 90,000 - 120,000
Equal opportunity employment
SAP Security / GRC - Roles, Authorizations, Compliance
SAP Security / GRC - Roles, Authorizations, Compliance

Data-Core Systems Inc. • Middletown Township (PA)

On-site
USD 90,000 - 120,000