Minimum 5+ years of SAP security experience, including at least 2 years in SAP BTP security.
Hands-on experience establishing trust between SAP Identity Authentication Service (IAS) and Azure AD or other Identity Providers (IdPs).
Expertise in IAS integration with applications like SuccessFactors and Joule.
Skilled in implementing conditional authentication rules in IAS.
Experienced in configuring IAS trust with multiple IdPs and SAP applications.
Proficient in user provisioning via Identity Provisioning Service (IPS) to both SAP on-premise and SAP Cloud applications such as Ariba and SuccessFactors.
Capable of configuring Role Collections, Group-to-Role mappings, and managing roles on the BTP platform.
Experienced in designing and maintaining complex provisioning jobs for varied user lifecycle scenarios.
Skilled in creating custom transformation rules in IPS for attribute mapping and filtering.
Proficient in integrating IPS with non-SAP systems using SCIM or REST APIs.
Experienced in monitoring, troubleshooting provisioning logs, and handling errors within IPS.
Implemented role-based provisioning and dynamic group assignments.
Strong knowledge of OAuth, SAML, and OIDC authentication protocols.
Expertise in SAP Identity and Access Management.
Deep understanding of SAP BTP security architecture.