SAP GRC Engineer, Governance & Risk
Overview
Own the design, implementation, and operation of security and access-control frameworks for complex SAP landscapes. Support SAP S/4HANA, ECC, BW/4HANA, and Fiori systems with a focus on role design, user provisioning, and segregation-of-duties analysis. Collaborate with audit and compliance teams to ensure adherence to SOX, GxP, and PCI frameworks. Operate SAP GRC Access Control suites to automate risk analysis and remediation workflows. Work 100% remote with a technology consulting firm delivering enterprise solutions across the U.S. This role offers direct impact on audit readiness and long-term security architecture.
What You'll Do9
- 1Design role-based access control models for SAP S/4HANA, ECC, and BW/4HANA to align with business processes and least privilege principles.
- 2Deploy and configure SAP GRC Access Control modules including ARA (Access Risk Analysis), ARM (Access Request Management), BRM (Business Role Management), and EAM (Emergency Access Management) to automate risk detection and user provisioning.
- 3Perform segregation-of-duties (SoD) risk analysis and remediation in collaboration with control owners to mitigate conflicts.
- 4Support internal and external audits by preparing evidence, responding to findings, and implementing corrective action plans.
- 5Secure SAP Fiori and BTP applications by configuring OAuth, role templates, and identity federation.
- 6Integrate SAP IDM or third-party IGA tools with cloud identity services like IAS and IPS to streamline provisioning and deprovisioning.
- 7Define and monitor controls using SAP Process Control and continuous controls monitoring frameworks to detect anomalies.
- 8Develop and maintain documentation for security policies, role matrices, and configuration guides.
- 9Collaborate with functional teams to resolve access-related incidents and improve user experience while maintaining compliance.
Requirements9
- 15+ years of experience in SAP Security and GRC within enterprise environments.
- 2Hands-on expertise with SAP authorization concepts and role design for S/4HANA, ECC, and Fiori.
- 3Deep knowledge of operating SAP GRC Access Control modules: ARA, ARM, BRM, EAM.
- 4Proven ability to support audit and remediation activities for SOX, GxP, and PCI frameworks.
- 5Experience securing cloud-based SAP applications, including BTP and SAP Cloud Identity services (IAS, IPS).
- 6Working knowledge of SAP IDM or third-party IGA tooling for identity lifecycle management.
- 7Familiarity with SAP HANA security and analytic privileges.
- 8Preferred: SAP Certified Security or GRC credentials.
- 9Exposure to SAP RISE and Grow security operating models is a plus.
Salary Insight
$100 - $150k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
Dechen Consulting Group
VerifiedSAP Security GRC Consultant, Production Support
You will own identity and access governance for a global SAP landscape, serving as the key liaison between client, BOBM, and SAP teams. You will provide frontline production support across integrated business applications, resolving access issues and driving compliance. This hands-on, collaborative role demands 5+ years of SAP security expertise and a deep understanding of GRC controls. You will implement and manage user roles, oversee emergency access, and ensure audit readiness in a dynamic, cross-functional environment.

Aasritha infotech Inc
VerifiedSAP GRC Senior Specialist, Access Control & S/4HANA
You will own the design and implementation of SAP GRC Access Control in a S/4HANA Greenfield environment. You will work with a cybersecurity team to configure roles, risks, and emergency access. This contract role starts with a 90-day goal to deliver a working GRC framework.

Vbeyond Corporation
VerifiedSAP Security GRC Lead, Role-Based Access Control
Own SAP role security governance for a global enterprise, ensuring user access aligns with SoD and audit standards. You will design RBAC frameworks in SAP and GRC to eliminate unauthorized access risks. Partner with IT and internal audit to enforce security policies across the organization. This role offers direct influence over compliance strategy and access control architecture.
Accenture
VerifiedSAP Platform Security Manager
Own SAP security architecture for enterprise clients, designing and deploying SAP S/4HANA role-based access, GRC controls, and vulnerability management at scale. You will lead workstreams, mentor teams, and shape client security strategies across industries. This role blends deep technical delivery with client advisory, offering exposure to BTP and Fiori ecosystems. You will drive measurable security outcomes from day one in a collaborative, growth-focused environment.
Accenture
VerifiedSAP Platform Security Manager Accenture Indianapolis
Lead platform security initiatives for SAP applications at Accenture. Oversee configuration of SAP S/4HANA security solutions and drive client success through risk mitigation strategies. Partner with stakeholders to implement robust access controls and vulnerability management frameworks.
Accenture
VerifiedSAP Platform Security Consultant Accenture
Lead and execute SAP platform security initiatives driving protection of systems and data. Own development of security roles and access controls while collaborating with cross-functional teams. Shape client engagements and influence strategy.