SAP GRC AC Consultant
NTT DATA
NTT DATA
Seeking a hands-on SAP GRC Access Control Consultant to manage and enhance our enterprise access governance landscape. This role involves configuring and supporting key SAP GRC Access Control modules, including Access Request Management, Access Risk Analysis, Emergency Access Management, and Business Role Management. You will collaborate with SAP Security, business stakeholders, risk, compliance, and audit teams to ensure secure, compliant, and auditable access processes across SAP and integrated applications.
Configure and enhance SAP GRC Access Control 10.1/12.0 capabilities (ARM, ARA, EAM, BRM). Support the entire lifecycle of access request workflows, from analysis to post-production support. Implement and troubleshoot MSMP workflows, BRF+ rules, agent determination, path selection, notifications, and escalation logic. Conduct Segregation of Duties (SoD) and sensitive-access risk analysis at various levels. Assist with risk remediation, mitigating control assignments, control monitoring, and evidence preparation. Administer Emergency Access Management (EAM) functions, including Firefighter IDs and review processes. Support business role creation, maintenance, and reconciliation within BRM. Monitor system connectors, synchronization jobs, and provisioning processes. Investigate incidents and service requests, perform root-cause analysis, and implement fixes. Support access governance for SAP ECC, S/4HANA, and Fiori environments. Coordinate transports across environments, including pre-deployment checks and post-implementation validation. Prepare operational reports, audit evidence, SOPs, and knowledge-transfer materials. Drive continuous improvement and automation of access management processes. Collaborate effectively within a team, communicate progress, and promptly raise risks.
Requires 6-9 years of overall experience in SAP Security and/or SAP GRC, with a minimum of 3 years dedicated to hands-on SAP GRC Access Control. Must have practical experience in at least three of the following SAP GRC Access Control modules: ARM, ARA, EAM, and BRM. Possess hands-on knowledge of MSMP workflow configuration and BRF+ rules. Demonstrate a strong understanding of SoD, sensitive access, risk analysis, mitigation strategies, and access governance principles. Familiarity with SAP role design, user administration, authorization objects, SU24 concepts, and security troubleshooting is essential. Experience supporting SAP ECC or S/4HANA environments is required; Fiori security exposure is a plus. Proven ability to analyze production issues, document root causes, and coordinate resolutions with cross-functional teams. Excellent communication skills to interact effectively with business users, auditors, and technical stakeholders. Understanding of IT General Controls (ITGC), audit evidence gathering, change control, and production support practices is expected.
NTT DATA
IT Consulting