Consultant | SAP Security & GRC AC | Pune | SAP | DSA Oil, Gas and Utilities (Pune, IN)
Deloitte
Deloitte
Join our dynamic team as a Consultant specializing in SAP Security & GRC AC. This role is based in Pune and focuses on delivering solutions within the Oil, Gas, and Utilities sector.
You will be instrumental in designing and implementing robust SAP security and governance frameworks, ensuring compliance and optimizing access controls across various SAP environments. This is an exciting opportunity to contribute to critical projects within a leading professional services firm.
Lead functional discovery sessions and workshops to understand and document order management processes, rules, and integrations.
Translate complex business needs into clear, detailed functional requirements and acceptance criteria.
Analyze existing processes to identify and recommend improvements for future SAP Order Management models.
Collaborate with architects and integration teams to define design impacts and dependencies.
Support User Acceptance Testing (UAT) planning and execution, ensuring clarity on test scenarios and outcomes.
Maintain end-to-end traceability of requirements throughout the project lifecycle.
Mentor junior team members and support business Subject Matter Experts (SMEs).
Proven experience in designing access roles for SAP S4HANA environments across finance, supply chain, procurement, and engineering domains.
Implement best practices in role building, testing, and transport management, including strategies for complex, multi-tier environments.
Propose security best practices for SAP Business Technology Platform (BTP) solutions.
Review and advise on access controls and authentication protocols for third-party application integrations.
Define Segregation of Duties (SOD) risks and mitigation controls in collaboration with GRC teams.
Provide input for updating the SOD risk matrix with new transaction codes and Fiori apps.
Review custom code to ensure authorization checks align with organizational controls.
Update and maintain authorization defaults for transactions, Fiori apps, and Web Dynpro applications.
Experience defining audit controls and engaging with auditors for evidence gathering.
Assist in designing, documenting, and enhancing SAP security administration policies and procedures.
Support project teams with SAP transport management, including issue resolution.
Update and present procedure documentation to the team.
Propose technical governance standards and best practices.
Engage with business stakeholders to capture access control requirements.
Work closely with Business Analysts, Org Governance Teams, and SMEs.
Liaise with Cybersecurity, Audit, and Risk & Controls teams.
Collaborate with Project Managers on access control design, build, and test plans, identifying project risks.
Work with internal training and deployment teams on content development and communication.
Expertise in SAP S4HANA, Fiori, HANA, and SAP BTP, with a deep understanding of authentication, user provisioning, and role design.
Experience with Master-derived and Value-enabler technical roles, including tcodes, HANA views, and Fiori Apps.
Expertise in Fiori role building, including Pages, Spaces, Catalogs, and Groups.
Understanding of OData V2/V4 services, API security, and troubleshooting Fiori/HANA access issues.
Exposure to BTP role building in ABAP environments, HANA Cloud, IAS, IPS, and audit logging.
Solid business process understanding in core domains like Supply Chain, Logistics, Procurement, and Master Data Governance.
Experience reviewing custom transactions, updating authorization defaults, and understanding authorization objects across domains.
Experience developing attribute-based access provisioning designs, with exposure to IDM or Saviynt.
Ability to work independently in a global, distributed setting.
Self-driven, proactive, and an out-of-the-box thinker.
Flexible, reliable, and demonstrate strong ownership.
Bachelor's degree or equivalent is required, along with 1-2 end-to-end SAP implementations.
Deloitte
Oil & Gas