Risk Consulting - Risk Tech - SAP GRC & Security - Manager
Listed on 2026-01-06
-
IT/Tech
IT Consultant, Cybersecurity
SAP Security and GRC AC Manager
Location:
Atlanta, Chicago, Cleveland, Dallas, EY-Pitts ONE (Pittsburg), Hoboken, Los Angeles, New York, Philadelphia
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
OpportunityOur Risk Technology practice is expanding as our client’s needs grow and because SAP is a strategic investment focus area for EY. For this reason, opportunities with the Risk Technology practice lead to tremendous career progression potential. You won’t find a culture like this anywhere else, so if you are looking to work with knowledgeable, people‑oriented colleagues, this is a great place to be.
Whatwe look for
We’re interested in SAP Application security and GRC professionals with an in‑depth understanding of, and willingness to become proficient in, our standard tools and practices. If you have a genuine passion for helping businesses achieve leading‑practice risk functions alongside some of the most knowledgeable individuals in the business, then this role is for you.
Your key responsibilitiesYou’ll likely spend most of your time connecting with clients to design and implement their processes into the SAP ERP through transformation journeys with Application security, GRC Access Control or similar such SaaS offerings. To make that happen, you’ll need a strong team and internal network to leverage our intellectual property and lessons learned. You’ll also need to draw upon your implementation and client experiences to help our clients implement a proficient design and to understand how to effectively manage the organizational change in their environment.
We will also look to you to build strong relationships with our clients to help them effectively address their complex issues.
- Experience in deploying large scale, cross‑functional, globally distributed and complex SAP transformation projects with in-depth knowledge of Application Security and SAP GRC Access Control solution that supports access management compliance.
- Design, Develop SAP Security solutions across all SAP applications (On‑prem/ Cloud/ Saas) in accordance with business requirements and security/ compliance, regulatory standards.
- Leadership experience with effectively managing onshore and offshore teams throughout the project life cycle.
- Participate in SAP audit discussions (Internal & External), questions and help resolve governance, compliance issues.
- Communication across functions (internal and external to EY) to identify and document functional requirements.
- Confidence in your reputation as an authoritative SAP Security and GRC expert by keeping abreast of industry developments, practices, and trends.
- Focus on the importance of coaching and developing teams and colleagues, by taking their ideas and giving them the knowledge, skills, and opportunities, they need to deliver.
- Energy and ambition to identify and manage business development opportunities.
- 6+ years of experience in an SAP Security and GRC lead role
- A bachelor's or master’s degree in computer science, Information security, Information management systems, or related field is preferred.
- Extensive hands‑on experience with Design, Build, Test and Deploy Application security framework across various SAP applications i.e. SAP S/4, FIORI, ECC, ARIBA, HCM and Success Factors is required.
- SAP HANA DB security is preferred.
- Strong SAP GRC Access Control implementation experience (version 12.0 or other GRC AC technologies) with Integration knowledge of IAM tools (Saviynt, SailPoint, SAP IAG etc.) is required.
- Experience designing process to support review of Segregation of Duties (SOD) s and Critical Actions (CA); temporary emergency management, and user provisioning.
- Working experience of risk framework/ruleset design to comply with Segregation of Duties (SOD) s and Critical Actions (CA) for various business processes.
- An understanding how to assess, define and align SAP application security to the risk and controls framework.
- Experience…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).