Job Overview
The SAP Security/GRC Admin is responsible for the management and support of SAP Roles and Security within the Diamondback SAP environment. The position will provide technical and thought leadership in the design, development, implementation, and support of SAP role administration functions across the entire landscape. Responsibilities also include cross‑functional management, testing and support of the SAP landscape for patches, upgrades and day‑to‑day operational issues.
Responsibilities
- Design, deploy and maintain security solutions that enable the business community to achieve goals while providing proper identity and access management controls.
- Analyze processes and system user needs to deliver quality solutions that meet both business and functional end‑to‑end requirements.
- Drive overall security strategy including role design and provisioning for the S4Hana ecosystem (S/4 HANA, FIORI, GTS, Solution Manager, HANA & other databases, BTP, etc.).
- Identify security risks, determine root causes of violations, suggest mitigation and control measures, and build required procedures and controls.
- Ensure SAP security development and deployment execution align with standards, methodologies, and processes.
- Identify issues, provide permanent solutions, and collaborate with functional teams to propose stability solutions for applications.
- Daily monitor jobs necessary for GRC applications to run effectively and efficiently, including nightly risk analysis reporting.
- Provide day‑to‑day technical support and resolution of security issues, including troubleshooting SAP security problems, approval procedures, and compliance.
- Develop and maintain processes with applicable documentation related to security, coordinating with IT management and governance teams.
- Facilitate appropriate controls around user/system access with IT management and governance groups.
- Proactively interact with senior management to discuss and explain issues affecting users or systems.
- Generate SOX and ad‑hoc reports on monthly, quarterly, and semi‑annual basis.
- Provide production support and enhancement testing for existing security roles and functions.
- Work closely with SAP functional teams to create roles, profiles and authorizations that meet audit and functional requirements for end users.
- Maintain Segregation of Duties for the SAP environment (e.g., HR/Payroll, BASIS, Security Administration, and BI).
- Collaborate with a team to design, build and deploy security frameworks, devices and applications.
- Conduct regular vulnerability assessments, penetration tests and scans to identify and address potential security weaknesses in SAP S/4 environments.
- Provision and de‑provision users and roles with appropriate SAP security levels.
- Prioritize tasks effectively in a high‑speed environment.
Required Qualifications
- Bachelor's Degree in Business Management, Information Systems or related field, or equivalent experience.
- Four (4+) years of in‑depth experience in SAP GRC, role administration and security implementation and production support (ECC 6.0/S4‑HANA).
- Experience with SAP S/4 HANA security and authorizations, version 1909 or later.
- Experience creating and assigning FF IDs and extracting Firefighter logs.
- In‑depth understanding of SAP Security role design and GRC architecture.
- Very good understanding of role remediation and setting up SAP Security processes.
- Expertise in SAP Security automation and scripting for mass maintenance.
- Expertise in generating and publishing SOX reports (UAR, Critical Actions, SOD, Critical Permissions, Firefighter Log Review).
- Experience maintaining and troubleshooting structural authorizations.
Preferred Qualifications
- Experience in SAP security engagements with cloud applications, Azure, etc.
- Experience supporting end‑to‑end SAP Security projects, workshops, testing, cutover preparation and hyper‑care activities.
- Experience in role design in S/4 with catalog and group for Fiori apps and strong analytical skills in issue resolution.
- SAP GRC certification.
- In‑depth understanding of FIORI specification, design, development and testing.
- In‑depth understanding of core BASIS functions and activities.
- Minimum three (3+) years of SAP experience within a large organization, including implementation and support.
- Experience creating and maintaining GRC solutions.
- Experience creating user and security roles for Fiori applications.
- Experience with SOD development and ongoing controls.
- Role administration across multiple landscapes.
- Oil and gas experience preferred.
- Experience with system monitoring, background job and spool administration.
- Experience working with SAP GRC 10.0/10.1, SAP HCM and SAP Solution Manager.
- Experience with SAP GRC Access Control configuration (MSMP and BRFPlus).
- Experience designing, configuring and implementing SAP GRC Access Request Analysis (ARA), Access Request Management (ARM), Emergency Access Management (EAM) and Business Role Management (BRM).
- Strong knowledge of provisioning to SAP LDAP and SAP Enterprise Portal platforms for ABAP, UME and portal roles/groups.
Work Authorization
Diamondback Energy is not currently sponsoring employment visas for this position.
Equal Employment Opportunity
Diamondback Energy is an Equal Employment Opportunity Employer. Diamondback provides equal employment opportunities to all qualified applicants without regard to race, sex, sexual orientation, gender identity, national origin, color, age, religion, veteran or disability status, genetic information, pregnancy or any other status protected by law. Diamondback participates in E‑Verify.