Sr. Analyst, IT - SAP Security Controls

FALL CREEK FARM & NURSERY

Chicago (IL)

On-site

USD 120,000 - 150,000

Full time

28 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

FALL CREEK FARM & NURSERY is seeking a Sr. Analyst, IT - SAP Security Controls in Chicago to lead and execute SAP security, access management, and ITGC controls.

You will partner with analysts and vendor teams to mature the controls program and expand coverage to additional SAP products over time. Responsibilities include designing SAP role provisioning, maintaining SoD rules, governing Firefighter access, and ensuring evidence is audit-ready.

Qualifications

  • 7+ years of hands-on SAP Security experience with strong SAP role design, provisioning, and access-management depth.
  • Experience with SAP GRC (Access Control 12.0) is a strong plus.
  • Demonstrated hands-on experience owning and executing SAP-specific ITGCs at the control-owner level.
  • Track record of remediating SOX/ITGC audit findings systemically.
  • Experience with control evidence retention, IPE validation, reviewer sign-off standards, and defending controls in front of external auditors.
  • Experience with controls execution for other SAP products such as SAP Ariba and SuccessFactors is a huge plus.
  • Demonstrated ability to lead — mentoring junior team members, setting standards, and directing internal and external contributors.

Responsibilities

  • SAP Security & Access Management: Manage SAP role design, provisioning, and de-provisioning aligned to business roles and least-privilege principles.
  • Design and maintain the SoD ruleset within our current toolset; own SoD analysis, mitigation, and remediation across SAP applications.
  • Own Firefighter governance — request, approval, monitoring, and log review.
  • Support integration of SAP security events with the enterprise SIEM.
  • SAP ITGC Ownership and Execution: Serve as the control owner and executor for SAP-specific ITGCs, including quarterly User Access Review and other monthly reviews.
  • Ensure control execution is timely with proper reviewer approval, evidence retention, and documentation to support audit and SOX requirements.
  • Maintain and improve control templates; standardize and version-control templates across cycles.
  • Track and remediate SOX/ITGC findings; ensure remediation is systemic.
  • Partner with Internal Audit and external auditors on requests and evidence review.
  • Support expansion of controls coverage to other SAP products as they come into scope.
  • Collaboration and Delivery: Direct and validate work by external AMS partners; ensure quality and alignment.
  • Collaborate with stakeholders and vendors to ensure project delivery and system support.

Skills

SAP Security
Access Management
ITGCs
SOX compliance
SoD analysis
Vendor collaboration
Change management
Stakeholder management
Mentoring

Tools

Fastpath
CSI
Pathlock
SIEM

Job description

Career Opportunities: Sr. Analyst, IT - SAP Security Controls (16816)

Requisition ID16816-Posted09/09/2026-IT - Applications-Information Technology

This position supports SAP Security, Access Management, and IT General Controls on SAP S/4HANA. The role executes SAP-specific ITGCs, ensuring monthly and quarterly controls are performed accurately, on time, and with the evidence required to withstand internal and external audit scrutiny. As a functional expert in the domain, the Sr. Analyst partners with analysts and vendor partners and supports the maturation of the controls program as it expands to other SAP products.

Essential Duties and Responsibilities

SAP Security & Access Management

  • Manage SAP role design, provisioning, and de-provisioning aligned to business roles and least-privilege principles.
  • Design and maintain the SoD ruleset within our current toolset (e.g., Fastpath); own SoD analysis, mitigation, and remediation across SAP applications.
  • Own Firefighter (Emergency Access) governance — request, approval, monitoring, and log review.
  • Support integration of SAP security events with the enterprise SIEM.

SAP ITGC Ownership and Execution

  • Serve as the control owner and executor for SAP-specific ITGCs, including quarterly User Access Review, monthly Termination Review, monthly Privileged User Access Monitoring, monthly Firefighter Log Review, monthly Critical/Administrative Access Review, quarterly SAP Standard Accounts Review, quarterly Role Review, quarterly Audit Log Review, and quarterly Client Open Changes Review.
  • Ensure control execution is timely, within the correct review period, with proper reviewer approval, evidence retention, and documentation to support audit and SOX requirements.
  • Maintain and improve control templates to ensure accuracy of formulas, scoping, and reviewer instructions; standardize and version-control templates across execution cycles.
  • Track and remediate SOX/ITGC findings from internal and external audit; ensure remediation is systemic rather than reactive.
  • Partner with Internal Audit and external auditors on requests, walkthroughs, IPE (Information Produced by the Entity) validation, and evidence review.
  • Support the expansion of controls coverage to other SAP products (e.g., SAP Ariba, SuccessFactors) as they come into audit scope over time.

Collaboration and Delivery

  • Direct and validate work performed by external AMS partners, ensuring quality and alignment with the broader SAP architecture.
  • Collaborate with business stakeholders, cross-functional teams, and vendors to ensure successful project delivery and ongoing system support.
Minimum Qualifications
  • 7+ years of hands-on SAP Security experience with strong SAP role design, provisioning, and access-management depth.
  • Experience with SAP GRC (Access Control 12.0) is a strong plus.
  • Demonstrated hands-on experience owning and executing SAP-specific ITGCs at the control-owner level — not just supporting audit teams. Direct experience with User Access Reviews, Termination Reviews, Firefighter Log Reviews, Change Management, and Audit Log Reviews required.
  • Track record of remediating SOX/ITGC audit findings systemically — closing recurring issues rather than patching them each cycle.
  • Experience with control evidence retention, IPE validation, reviewer sign-off standards, and defending controls in front of external auditors.
  • Working knowledge of Fastpath (preferred) or comparable tools such as CSI, Pathlock for automated control monitoring, access reviews, and SoD analysis.
  • Experience with controls execution for other SAP products such as SAP Ariba and SuccessFactors is a huge plus — these products will be added to the control scope over time.
  • Demonstrated ability to lead — mentoring junior team members, setting standards, and directing internal and external contributors on security and controls work.
  • Strong communication, stakeholder management, and change management skills; ability to lead through influence across all organizational levels.
Physical and Mental Demands

While performing the duties of this job, the employee is frequently required to remain in a stationary position, move and/or position oneself, communicate, operate and/or prepare, place, position objects, tools, or controls. The employee must occasionally move packages weighing up to 10 lb. Specific vision abilities required by this job include close observation and the ability to adjust focus. The mental and physical requirements described here are representative of those that must be met by an individual, with or without reasonable accommodation, to successfully perform the essential functions of this position.

Work is performed in an office environment. The noise level in the work environment is usually moderate. The work environment characteristics described here are representative of those an individual encounters while performing the essential functions of this position.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Analyst, IT - SAP Security Controls
Sr. Analyst, IT - SAP Security Controls

Verano • Chicago (IL), Northern (KY)

Hybrid
USD 130,000 - 150,000
Sap Security Specialist-NO C2C
Sap Security Specialist-NO C2C

The Doyle Group • Denver (CO)

Hybrid
USD 120,000 - 150,000
SAP GRC and Cloud Security Specialist
SAP GRC and Cloud Security Specialist

Variety Staffing • New Jersey

On-site
USD 110,000 - 130,000
SAP Security & Access Management Consultant
SAP Security & Access Management Consultant

MAM Gruppe • Chicago (IL)

On-site
USD 131,000 - 160,000
Sr Analyst SAP Security
Sr Analyst SAP Security

USEReady • Greensboro (NC)

Hybrid
USD 90,000 - 120,000
SAP S/4HANA SAP GRC Process Control
SAP S/4HANA SAP GRC Process Control

TechClub Inc • Dallas (TX)

On-site
USD 130,000 - 150,000
SAP Security Analyst
SAP Security Analyst

CFS • Chicago (IL)

Hybrid
USD 125,000 - 135,000
Health
Dental
Vision
+2
SAP GRC Administrator Consultant
SAP GRC Administrator Consultant

truData Solutions • United States

Remote
USD 110,000 - 170,000
ERP Security and GRC Analyst IV - United States (Remote) at V2X United States
ERP Security and GRC Analyst IV - United States (Remote) at V2X United States

V2X • United States

Hybrid
USD 110,000 - 175,000
Healthcare coverage
Paid time off
Retirement plan
+2
Sr. SAP Security Analyst
Sr. SAP Security Analyst

Carex Consulting Group • Madison (WI)

On-site
USD 110,000 - 150,000