Risk Consulting - Digital risk - SAP GRC
EY
EY
Join our dynamic Risk Consulting team at EY and embark on a career path tailored to your unique strengths. Leverage EY's global reach, supportive culture, and cutting-edge technology to achieve your full potential. Your distinct perspective is crucial in helping us shape a better world of work. This role focuses on SAP GRC and ITAC within the Digital Risk practice, serving clients across the MENA region.
We are seeking experienced SAP GRC, SAP security, ITAC, and ITGC professionals to contribute to our growing practice. This is an excellent opportunity to engage in diverse SAP GRC, VAPT, and IT controls projects, hone your consulting acumen, and bolster our SAP GRC delivery capabilities.
Engage in network and web application penetration testing for IT and Cyber risk consulting projects. Conduct comprehensive risk assessments and vulnerability analyses within cloud environments, proposing effective mitigation strategies. Perform detailed configuration reviews for operating systems, servers, databases, applications, networks, and security devices against industry benchmarks like CIS. Evaluate secure cloud configurations against best practices and assess DevSecOps implementations to integrate security into CI/CD pipelines and cloud deployments.
Support SAP GRC, SAP ITAC, and IT risk consulting initiatives across SAP ECC and SAP S/4HANA systems. Execute control walkthroughs, review evidence, and perform testing for ITGC, ITAC, and automated business controls according to project methodologies. Assist in the assessment, design, and documentation of SAP IT application controls and automated controls. Conduct Segregation of Duties (SoD) and sensitive access reviews, including data analysis, rule set review, exception validation, and remediation follow-up.
Support SAP GRC Access Control testing, encompassing workflow validation, access risk analysis, emergency access procedures, and user access review activities. Prepare and maintain project deliverables, including risk control matrices (RCMs), testing workpapers, issue logs, evidence trackers, and status updates. Assist with data extraction and analysis for access management, control monitoring, process compliance, and audit support. Collaborate with internal teams, client stakeholders, and audit teams to gather system/process information and address documentation gaps.
Adhere to firm quality standards for testing, documentation, and deliverable preparation. Effectively translate complex technical details into clear, business-understandable language for stakeholder communication. Produce high-quality report writing, conveying observations to senior management in layman's terms, emphasizing business risks. Communicate proactively and clearly to facilitate issue resolution, follow-up, and successful project delivery.
Demonstrate strong spoken and written English with excellent business communication skills. Approach testing, documentation, and evidence review with an analytical, organized, and detail-oriented mindset. Excel in working under pressure to deliver quality outputs within deadlines. Possess strong collaboration skills, fostering effective teamwork with internal teams, clients, and auditors. Maintain a good understanding of project discipline, task ownership, and quality expectations.
Acquire hands-on experience with security testing tools and frameworks such as Burp Suite, Nessus, or Qualys. Possess good knowledge of OWASP and Secure Software Development Lifecycle (SDLC) standards. Develop a solid understanding of cloud services (AWS, Azure, GCP), their architectures, potential attack vectors, and mitigation strategies. Gain hands-on experience with programming languages like Python, Perl, PowerShell, or C#. Proficiency in MS Office, with working knowledge of Excel, Power BI, ACL, or similar data analysis tools, is preferred.
This role requires 3-6 years of experience in SAP GRC, SAP security, SAP ECC, SAP S/4HANA, IT audit, compliance testing, or technology risk consulting. Exposure to SAP is mandatory; experience with SAP ECC/S/4HANA security, Oracle security, or other ERP security models is advantageous. Understand ERP system landscapes, access control concepts, SoD, sensitive access, and user access review processes. Knowledge of ITGC, ITAC, RCM documentation, testing methodologies, and issue documentation is essential. Familiarity with SOX, ICOFR, internal audit, or IT risk standards is required. Strong Excel and documentation skills with a focus on evidence completeness and workpaper quality are critical.
A Bachelor's degree in Information Systems, Computer Science, Accounting, Finance, or a related discipline is necessary to qualify for this role.
EY Global Delivery Services ( EY GDS)
Management Consulting