PG
SAP Security Specialist
PlanIT Group
šŗšø United States
Remote
2 months ago
- SAP
- SAP ERP
- SOX
- GDPR
- HIPAA
- ERP
- Change Management
- CCPA
- ITAR
2 months ago
SAP / ERP Risk & Controls
⢠Riskāassessment and design of SAP controls (access management, SoD, privileged access, configuration)
⢠Collaborate with functional & technical teams to identify, remediate, and monitor risks in FI, MM, SD, HR (and integrated modules)
⢠Implement and continuously improve automated & manual controls across SAP and connected systems
⢠Drive sustainable SAPāaudit remediation (vs. pointāinātime fixes)
IT General Controls (ITGC) & Application Testing
⢠Plan, execute, and document ITGC testing (access, change, operations) and applicationācontrol testing across the enterprise
⢠Maintain testing scripts, evidence collection, and testāresult signāoffs
⢠Ensure testing aligns with SOX, GDPR, HIPAA, and other regulatory expectations
Engineering Methodology
⢠Experience with standard engineering process
⢠Background in doing requirements discovery and translation from business requirements to technical requirements / deliverable
⢠Experience with software systems design
Audit & Remediation Management
⢠Assist the Team with Internal Audit and external auditors (Big 4) during walkthroughs, testing, and issue resolution
⢠Translate audit findings into clear, riskābased remediation plans with defined owners, timelines, and success criteria
⢠Track remediation progress and verify effectiveness of fixes
ERP Risk Governance & Oversight
⢠Maintain an upātoādate ERP risk register linked to enterprise risk appetite; quantify exposure and prioritize treatment
⢠Design and enforce a standardized ERP control framework (design, documentation, testing methodology)
⢠Provide oversight, challenge, and assurance on control design and operating effectiveness
Policy, Standards & Framework Development
⢠Develop, maintain, and enforce ERPāspecific policies, standards, and control frameworks
⢠Align policies with corporate GRC frameworks (nd regulatory requirements
⢠Conduct periodic policy reviews and updates
Stakeholder Communication & Influence
⢠Prepare and present riskāposture, controlāeffectiveness, and remediation status to senior leadership and business owners
⢠Translate technical risk concepts into businessāimpact language to influence decisionāmaking
⢠Build strong relationships with IT, finance, and lineāofābusiness partners
Technical SAP & Security Expertise
⢠SAP GRC (Access Control, SoD, ARA) configuration and maintenance
⢠SAP security administration (role design, provisioning, privilegedāaccess management)
⢠Understanding of SAP ERP application controls, integration points, and data flows
ITGC Technical Knowledge
⢠Access control, changeāmanagement, and operations control design and testing
⢠Knowledge of SAP Basis impact on security (client administration, transports, patches)
Audit & Assurance Experience
⢠Endātoāend audit engagement management (planning, fieldwork, reporting)
⢠Development of audit workpapers, evidence gathering, and auditāfinding remediation programs
⢠Interaction with regulators and external auditors on compliance matters
Regulatory & Compliance Acumen
⢠Deep knowledge of SOX Section 404, GDPR, CCPA, ITAR, and industryāspecific compliance frameworks
⢠Ability to map controls to regulatory requirements and produce compliance evidence
Consulting / Bigā4 Experience
⢠Advisory mindset with ability to assess client environments, propose riskābased solutions, and drive change
⢠Experience delivering projects in matrixed, fastāpaced environments
Communication & Presentation Skills
⢠Write clear policies, procedures, and risk documentation
⢠Deliver concise executive briefings, dashboards, and risk scorecards
⢠Facilitate workshops and training sessions for technical and nonātechnical audiences
SAP Security Specialist Ā· PlanIT Group