We’re seeking an experienced SAP GRC Security Architect to define and lead the target-state security architecture for a global ECC-to-S / 4HANA transformation under RISE with SAP . The architect will guide the redesign of roles, GRC frameworks, and compliance controls across multiple factories in Southeast Asia and the U.S. headquarters. This position requires both strategic vision and deep technical expertise in SAP Security and GRC 12.0.
The role involves defining the end-to-end security blueprint, designing and driving the migration of legacy ECC roles to S / 4HANA, and harmonizing access models across business units, regions, and environments.
Key Responsibilities
- Target-State Architecture : Own and advocate the global SAP Security architecture for S / 4HANA, Fiori, BW, and integrated systems—aligned with cloud, RISE, and Zero-Trust principles.
- Global GRC Framework : Design and implement SAP GRC Access Control 12.0, including SoD rule redesign, MSMP / BRF+ workflow optimization, and centralized access provisioning.
- S / 4HANA Role Design : Develop the new Fiori-based access methodology and HANA native security model;
oversee ECC-to-S / 4 role transition and testing .
Security Governance : Establish standards for role lifecycle management, access reviews, remediation, and ongoing compliance monitoring.Factory Security / OT Integration : Design controls for SAP and Operational Technology (OT) system interfaces to protect critical manufacturing processes.Compliance & Audit : Serve as the primary liaison for SOX and ITGC audits, ensuring control documentation, testing, and continuous readiness.Cross-Functional Collaboration : Partner with Basis, Infrastructure, and Cybersecurity teams to integrate SAP security with enterprise IAM (Azure AD, Okta) and network policies.Continuous Improvement : Define KPIs and dashboards for access governance, role performance, and audit remediation tracking.Knowledge Sharing : Document and share lessons learned, best practices, and architectural patterns with global teams.Required Skills & Experience
8–10+ years of progressive SAP Security and GRC experience across ECC and S / 4HANA landscapes.Expert-level proficiency in SAP GRC Access Control (10 / 12.0), including SoD redesign, MSMP / BRF+ configuration, and access risk remediation.Proven experience designing and deploying security for S / 4HANA, Fiori, and HANA native layers.Strong understanding of authorization concepts in core SAP modules (FI / CO, MM, SD, PP).Hands-on experience supporting SOX and ITGC compliance in a publicly traded environment.Ability to produce high-quality architectural documentation and influence senior stakeholders.Preferred Qualifications
Experience with RISE with SAP S / 4HANA Cloud (Private Edition) and SAP Cloud Identity Services.Familiarity with SAP GRC Process Control, SAP IAG, and audit automation tools (e.G., Security Weaver, Pathlock).Knowledge of manufacturing / OT system integrations and security controls for production environments.Expertise in SAP BW / BI security.SAP or security certifications (e.G., SAP Certified Technology Consultant – System Security, CISSP).Experience in Greenfield, Brownfield, or Bluefield S / 4HANA implementations.