GAF

SAP GRC Lead

GAF$140K — $192K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree required
  • 8+ years of SAP security and GRC experience, including 3+ years in a lead role
  • Hands-on expertise in SAP GRC Access Control modules: ARM, ARA, EAM, BRM
  • Experience implementing SAP IAG on BTP
  • Governed security for at least two SAP SaaS platforms: SAP Ariba, SAC, IBP
  • Strong knowledge of SoD concepts and access control frameworks (SOX, ITGC)

Responsibilities

  • Define and maintain an enterprise GRC framework across SAP systems
  • Manage SoD rule-set and conflict detection across SAP environments
  • Lead access review and remediation efforts
  • Administer SAP GRC Access Control modules and manage configurations
  • Oversee SAP IAG deployment, configuration, and role assignments
  • Govern security models for SAP Ariba, SAC, and IBP
  • Engage stakeholders and mentor GRC analysts for team capability

Benefits

  • Wide range of health insurance options including medical, dental, and vision
  • Family-building benefits to support fertility and parenthood journeys
  • Robust 401K plan with employer match
  • Programs for work-life balance including wellness and financial coaching
  • Internal training and generous tuition reimbursement
  • Opportunities to engage in Employee Resource Groups for education and allyship
Full Job Description
Job Summary
The SAP GRC Lead is a senior specialist responsible for governing identity, access, risk, and compliance across the organization's SAP landscape. This role owns the end-to-end GRC strategy covering SAP GRC Access Control, SAP Identity Access Governance (IAG) on BTP, and the security models for all SAP SaaS platforms - including SAP Ariba, SAP Analytics Cloud (SAC), and SAP Integrated Business Planning (IBP). The GRC Lead acts as the primary point of accountability for SoD risk mitigation, access provisioning governance, and audit readiness across on-premise and cloud-based SAP systems.

Essential Duties
  • GRC Strategy & Governance
    • Define and maintain the enterprise GRC framework spanning SAP on-premise and cloud, aligned with internal audit, legal, and regulatory requirements
    • Own the SoD (Segregation of Duties) rule-set across all connected SAP systems; manage conflict detection, mitigation controls, and compensating control documentation
    • Lead periodic access review and certification campaigns; drive remediation to closure
    • Establish policies and procedures for privileged access, emergency access management (EAM / Firefighter), and periodic user access reviews
  • SAP GRC Access Control
    • Administer and configure SAP GRC AC modules: Access Request Management (ARM), Access Risk Analysis (ARA), Emergency Access Management (EAM), and Business Role Management (BRM)
    • Design and maintain the GRC connector landscape for S/4HANA, ECC, and connected SaaS systems
    • Manage workflow configuration, MSMP routing rules, and approval hierarchies within GRC AC
    • Perform ruleset reviews and fine-tune risk definitions to minimize false positives while maintaining SOX/audit coverage
  • SAP Identity Access Governance (IAG) on BTP
    • Own the SAP IAG deployment on BTP: tenant configuration, IAS integration, access analysis, and role assignment workflows
    • Manage BTP trust configuration between IAG and SaaS platform connectors
    • Coordinate with the BTP Integration Lead on XSUAA scoping, role collection design, and subaccount trust settings relevant to IAG
  • SaaS Platform Security Models
    • Govern the security model for SAP Ariba:
    • Procurement and sourcing role design, user provisioning, and SoD rules for Ariba Buying, Invoicing, and Contracts
    • Ariba Network realm administration and supplier access governance
    • Govern the security model for SAP Analytics Cloud (SAC):
    • Team and role model design; story, model, and data access permissions
    • Integration with CDS view security for governed data access
    • Govern the security model for SAP Integrated Business Planning (IBP):
    • Supply-chain planning user roles, keyfigure-level access, and planning area security
    • IBP-to-S/4HANA integration security and cross-system SoD alignment
    • Maintain consistent naming conventions, provisioning workflows, and access certification cycles across all three SaaS platforms
  • Stakeholder Engagement & Team Leadership
    • Partner with Business Process Owners, IT Security, and Internal Audit to align GRC priorities and risk appetite
    • Mentor GRC analysts and role administrators; build team capability on IAG, SaaS security models, and audit processes
    • Engage with SAP and third-party vendors on GRC product roadmap, patches, and best practices


Qualifications Required
  • Bachelor's Degree is required
  • 8+ years of SAP security and GRC experience, with at least 3 years in a lead or architect capacity
  • Deep hands-on expertise with SAP GRC Access Control (AC 12.x): ARM, ARA, EAM, BRM modules
  • Proven experience implementing and administering SAP IAG on BTP
  • Demonstrated experience governing the security model for at least two of the three key SaaS platforms: SAP Ariba, SAP Analytics Cloud, or SAP IBP
  • Strong understanding of SoD concepts, audit principles, and access control frameworks (SOX, ITGC)


General Knowledge, Skills and Abilities
  • Proficient level: Strategic and Visionary Leadership: Strategic Thinking, innovation driving, Decision making
  • Proficient level: Change Management and Adaptability: Managing resistance, adaptability, resilience
  • Proficient level: People and Relationship Management: Emotional Quotient, Communication, collaboration
  • Proficient level: Technical and Business Acumen: Digital Literacy, Business/Finance Acumen, Process Design
  • Proficient level:: Personal Drive and Mindset: Growth mindset, action oriented, courage


Technical Knowledge, Skills and Abilities
  • SAP authorization concepts: authorization objects, PFCG role design, structural profiles, and S/4HANA role design
  • SCIM API integration for automated provisioning across SaaS platforms
  • Working knowledge of SAP BTP XSUAA and role collections
  • GRC reporting: exposure to SAP GRC dashboards, custom ABAP reports, or BI-based access reporting


Qualifications Preferred
  • SAP Certified Application Associate - SAP GRC Access Control or equivalent certification
  • Experience with SAP Identity Authentication Service (IAS) and Identity Provisioning Service (IPS) for automated lifecycle management
  • Experience integrating GRC workflows with ITSM platforms (ServiceNow, Jira) for automated access requests
  • Knowledge of S/4HANA CDS view-level access control and ABAP-level authorization debugging (SU53, ST01, SU24)
  • Flexibilty to travel: Travel may be extensive at times to accommodate program needs, including support for program activities, vendor meetings, and site visits as necessary.


Base salary and/or rate of pay ranges listed are exclusive of fringe benefits and potential bonuses. Individual compensation offers will be determined based on a variety of factors, including but not limited to geographic location, relevant candidate experience and skill, education, and/or qualifications.

Base Salary Range: $140,000-$192,500

How We Protect What Matters Most:
1. We offer a wide range of health insurance options that include medical, dental, and vision for you and your family. 2. Our Family-Building benefits support the many different journeys to fertility and parenthood. 3. Our robust 401K plan includes an employer match contribution with your pre-tax and/or Roth contributions. 4. Other exciting programs and perks are available to help employees achieve work-life balance, including (but not limited to) a wellness program, free financial coaching, a referral program, and product rebates when purchased for an employee's primary residence. 5. Professional growth and development are very important to us! We offer internal training programs and courses, as well as a generous tuition reimbursement program. 6. We're committed to fostering a culture that reflects our values to connect, empower, evolve, and inspire. We offer many opportunities for employees to connect with one another, including through our Employee Resource Groups who focus on education and allyship for all of our employees.

About GAF

GAF is a building materials manufacturing company that produces roofing materials, insulation, and other products for residential and commercial buildings. The company was founded in 1886 and is headquartered in Parsippany-Troy Hills, New Jersey. GAF has a long history of innovation and has developed many industry-leading products over the years. The company's products are known for their quality and durability, and are used by builders and homeowners across the country. GAF is committed to sustainability and has implemented many environmentally-friendly practices in its operations.
Learn more about GAF
Size
3,000 employees
Industry
Founded
1886

Similar Jobs

More Jobs at GAF

More Information Technology Jobs

Find similar SAP GRC Lead jobs: