SAP Security Specialist

PlanIT Group LLC

$95K — $115K *
Enterprise Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in SAP GRC or related risk assessment roles
  • Proven expertise in SAP access control, segregation of duties (SoD), and application security
  • Strong technical knowledge of ITGC and compliance regulations (SOX, GDPR, HIPAA)
  • Hands-on experience with audit management and remediation processes
  • Background in stakeholder communication and mentoring with an advisory mindset

Responsibilities

  • Conduct risk assessments and design SAP security controls
  • Collaborate with teams to identify and rectify risks across various SAP modules
  • Implement automated and manual controls for SAP and associated systems
  • Oversee and manage internal and external audit processes
  • Maintain and update ERP risk registers aligned with enterprise risk profiles
  • Develop and enforce ERP-specific policies and compliance frameworks
  • Communicate risk statuses and influence decision-making with senior leadership

Benefits

  • Comprehensive health and wellness programs
  • Opportunities for professional development and training
  • Work-life balance with flexible scheduling
  • Collaborative work environment that values input and innovation
  • Access to cutting-edge technology and resources
Full Job Description
This role is for a SAP GRC Risk Assessment Analyst.

SAP / ERP Risk & Controls
• Risk-assessment and design of SAP controls (access management, SoD, privileged access, configuration)
• Collaborate with functional & technical teams to identify, remediate, and monitor risks in FI, MM, SD, HR (and integrated modules)
• Implement and continuously improve automated & manual controls across SAP and connected systems
• Drive sustainable SAP-audit remediation (vs. point-in-time fixes)

IT General Controls (ITGC) & Application Testing
• Plan, execute, and document ITGC testing (access, change, operations) and application-control testing across the enterprise
• Maintain testing scripts, evidence collection, and test-result sign-offs
• Ensure testing aligns with SOX, GDPR, HIPAA, and other regulatory expectations

Engineering Methodology
• Experience with standard engineering process
• Background in doing requirements discovery and translation from business requirements to technical requirements / deliverable
• Experience with software systems design

Audit & Remediation Management
• Assist the Team with Internal Audit and external auditors (Big 4) during walkthroughs, testing, and issue resolution
• Translate audit findings into clear, risk-based remediation plans with defined owners, timelines, and success criteria
• Track remediation progress and verify effectiveness of fixes

ERP Risk Governance & Oversight
• Maintain an up-to-date ERP risk register linked to enterprise risk appetite; quantify exposure and prioritize treatment
• Design and enforce a standardized ERP control framework (design, documentation, testing methodology)
• Provide oversight, challenge, and assurance on control design and operating effectiveness

Policy, Standards & Framework Development
• Develop, maintain, and enforce ERP-specific policies, standards, and control frameworks
• Align policies with corporate GRC frameworks (nd regulatory requirements
• Conduct periodic policy reviews and updates

Stakeholder Communication & Influence
• Prepare and present risk-posture, control-effectiveness, and remediation status to senior leadership and business owners
• Translate technical risk concepts into business-impact language to influence decision-making
• Build strong relationships with IT, finance, and line-of-business partners

Technical SAP & Security Expertise
• SAP GRC (Access Control, SoD, ARA) configuration and maintenance
• SAP security administration (role design, provisioning, privileged-access management)
• Understanding of SAP ERP application controls, integration points, and data flows

ITGC Technical Knowledge
• Access control, change-management, and operations control design and testing
• Knowledge of SAP Basis impact on security (client administration, transports, patches)

Audit & Assurance Experience
• End-to-end audit engagement management (planning, fieldwork, reporting)
• Development of audit workpapers, evidence gathering, and audit-finding remediation programs
• Interaction with regulators and external auditors on compliance matters

Regulatory & Compliance Acumen
• Deep knowledge of SOX Section 404, GDPR, CCPA, ITAR, and industry-specific compliance frameworks
• Ability to map controls to regulatory requirements and produce compliance evidence

Consulting / Big-4 Experience
• Advisory mindset with ability to assess client environments, propose risk-based solutions, and drive change
• Experience delivering projects in matrixed, fast-paced environments

Communication & Presentation Skills
• Write clear policies, procedures, and risk documentation
• Deliver concise executive briefings, dashboards, and risk scorecards
• Facilitate workshops and training sessions for technical and non-technical audiences

Similar Jobs

More Jobs at PlanIT Group LLC

More Enterprise Technology Jobs

Find similar SAP Security Specialist jobs: