Search Jobs

Search by job, company or skills

SAP GRC Access Control Specialist CISA Certified

SAP GRC Access Control Specialist CISA Certified

Duobridge
Early Applicant
  • Posted 14 hours ago
  • Be among the first 10 applicants

Job Description

SAP GRC

Location: Chennai

Department: GPO Reports to: GPO – Process Owner

About The Role

We are seeking an experienced SAP GRC resource to manage and strengthen our SAP Governance, Risk, and Compliance framework. The ideal candidate will bring hands-on expertise in SAP access controls, segregation of duties (SoD) risk analysis, and IT general controls (ITGC), combined with a strong background in IT audit. This role is critical to ensuring our SAP environment is secure, compliant, and aligned with internal control and regulatory requirements.

Key Responsibilities

  • Design, configure, and maintain SAP GRC Access Control, including access risk rulesets, mitigating controls, and remediation workflows.
  • Perform periodic reviews of SAP user access, role assignments, privileged access, and emergency access management (Firefighter) to identify and remediate segregation of duties (SoD) conflicts.
  • Review and monitor SAP access controls across key business cycles (procure-to-pay, order-to-cash, user access management) to ensure compliance with company policies and industry standards.
  • Assess IT general controls (ITGC), application controls, and infrastructure controls within SAP and related environments, benchmarking against frameworks such as NIST.
  • Partner with IT and Business stakeholders to investigate audit findings, track remediation progress, and drive continuous improvement in control effectiveness.
  • Support external and internal audit engagements, including planning, fieldwork, reporting, and issue follow-up for SAP-based systems.
  • Evaluate third-party service reports (e.g., ISAE 3402/SOC reports) for outsourced IT support functions.
  • Conduct vulnerability assessments and support broader IT security reviews in collaboration with the security team.
  • Develop and deliver training to key users, internal auditors, and auditees on GRC processes, tools, and controls.
  • Maintain and enhance audit issue tracking systems, ensuring workflows reflect current audit practices.

Required Qualifications

  • Bachelor's degree in Information Systems, Computer Science, Accounting, or a related field.
  • Minimum 8–12 years of combined experience in IT audit (internal and/or external) with a strong focus on SAP access controls and GRC.
  • Proven hands-on experience with SAP GRC (Access Control), including access risk analysis, mitigating control assignment, and SoD rulesets.
  • Working knowledge of SAP modules (MM, FI, PP, QM, PM, SD) and how they intersect with access risk.
  • Solid understanding of ITGC, application controls, and vulnerability management processes.
  • Experience with Identity & Access Management tools (e.g., CyberArk) and privileged access reviews.
  • Familiarity with audit and data analytics tools such as ACL and TeamMate.
  • Professional certification: CISA (Certified Information Systems Auditor) required; ITIL Foundation a plus.
  • Experience with vulnerability assessment tools (e.g., Nmap, Nessus) is advantageous.
  • Strong communication skills, with the ability to translate technical findings into actionable business recommendations.
  • Proficiency in Microsoft Office (Excel, Word, Visio, PowerPoint).

Preferred Attributes

  • Prior exposure to Big 4 audit methodology or large-scale internal audit functions.
  • Experience delivering GRC or access-control training to end users and auditors.
  • Fluency in English

What We Offer

  • Opportunity to lead and shape the SAP GRC function within a growing organization.
  • Exposure to cross-functional projects spanning IT, security, and business operations.
  • Competitive compensation and professional development support

Skills: sap pp,cisa,sap qm,sap materials management (sap mm),sap grc access control,sap fi,itgc,grc,it audit,sap sd,sap pm module,sap,sap module,risk

More Info

Key Skills

SAP GRC Access Control

About Company