Risk Consulting - Digital Risk - SAP GRC - ITAC - Manager

EY

8–12 yrs Kochi Full Time Hybrid (office + remote)
EY logo
Posted : 2 weeks ago Actively Hiring

Job description

Join EY's Risk Consulting - Digital Risk team as a SAP GRC / ITAC Manager and build a career focused on delivering impactful client engagements. This role offers the opportunity to lead digital risk initiatives across the MENA region, leveraging your expertise in SAP GRC, IT application controls, and IT general controls. You will play a crucial role in strengthening our core team, ensuring high-quality delivery, and supporting complex projects that demand deep SAP GRC and ITAC capabilities.

This position is ideal for seasoned SAP GRC professionals ready to take on leadership responsibilities, mentor junior team members, and contribute to the growth of our SAP GRC service offering. You will collaborate with diverse stakeholders across various sectors, driving innovation and excellence in risk management solutions.

Responsibilities

Lead and execute SAP GRC/ITAC and IT risk consulting engagements for SAP ECC and S/4HANA environments, managing the entire lifecycle from planning to stakeholder reporting.

Oversee SAP GRC Access Control workstreams, including Access Risk Analysis, Emergency Access Management, Access Request Management, and Business Role Management.

Conduct ITGC and ITAC assessments, reviewing risk and control matrices, performing walkthroughs, testing designs and operating effectiveness, and tracking remediation efforts.

Review SoD risk analyses, sensitive access reviews, and SAP security role assessments to ensure accuracy and audit readiness.

Drive ERP control assessments focusing on logical access, change management, backup and restoration, incident management, and automated business controls.

Guide SAP GRC solution configuration, testing, and optimization, including rule set rationalization and UAT coordination.

Manage engagement economics, timelines, deliverables, and issue resolution.

Mentor and coach senior consultants and analysts on SAP GRC, ITAC methodologies, documentation, and client communication.

Contribute to proposal development, capability building, and the creation of reusable accelerators for SAP GRC and IT controls engagements.

Coordinate with internal and external audit teams to ensure complete evidence and clear issue articulation.

Qualifications

A minimum of 8-12 years of experience in SAP GRC, SAP security, ERP controls, IT audit, internal audit, or technology risk consulting is required.

Demonstrated hands-on experience with SAP GRC Access Control and a strong understanding of SAP ECC and S/4HANA security concepts are essential.

Proficiency in RCMs, ITGC, ITAC, SoD, sensitive access reviews, control testing procedures, and issue management is expected.

Prior experience leading control testing teams and reviewing deliverables for quality and consistency is necessary.

Familiarity with audit and risk frameworks such as SOX, COSO, ICOFR, and professional IT audit practices is required.

A Bachelor's degree in Information Systems, Computer Science, Accounting, Finance, or a related field is mandatory.

Possession of a valid passport for travel is essential.

Essential Skills

SAP GRCSAP SecurityITACITGCERP ControlsInternal AuditTechnology Risk ConsultingSAP ECCSAP S/4HANARisk Control Matrix (RCM)Segregation of Duties (SoD)SOXCOSOICOFR

Good to Have

Power BIACLSAP GRC CertificationCISACRISCCIAOracle Cloud SecurityOracle Risk Management CloudServiceNow IRMArcherS/4HANA Role RedesignContinuous Controls Monitoring

More Details

RoleRisk Consulting - Digital Risk - SAP GRC - ITAC - Manager
DepartmentRisk Management, Consulting
Employment TypeFull Time, Hybrid (office + remote)

About the Company

EY Global Delivery Services ( EY GDS) logo

EY Global Delivery Services ( EY GDS)

IT Consulting

Risk Consulting - Digital Risk - SAP GRC - ITAC - Manager at EY | SkillMX | SkillMX