Sap Security Specialist-NO C2C
Listed on 2026-09-13
-
IT/Tech
Information Security & Data Protection, IT Consultant, Cybersecurity, SAP Consultant
ABOUT THE DOYLE GROUP
The Doyle Group is a proven partner for Placement and Consulting services, headquartered in Denver, CO. Our core mission is to forge genuine partnerships with our clients who seek strategic talent solutions and to assist highly skilled candidates looking for their next career opportunity. With over 30 years of industry experience, our consultative approach allows us to provide a higher level of guidance and insight, empowering our clients to secure top IT talent that fits seamlessly into their team and culture.
We look forward to collaborating to help you achieve your career goals.
Our client is an industry‑leading, rapidly scaling quantum computing company that recently went public and is expanding its SAP S/4
HANA footprint globally. As part of that growth, the company is redesigning its SAP security model from the ground up — replacing a legacy, brownfield structure that has grown unevenly over time, where access has been layered on for years without a clear picture of what any given user actually holds.
This is a high‑priority, highly visible hire. SAP security and Governance, Risk, and Compliance (GRC) touch nearly every part of the business, and the SAP Security Specialist will serve as the primary interface between the SAP team and stakeholders across Finance, Internal Audit, and Information Security who are managing SOX audits and access governance. The company recently went public and is in the middle of a deliberate, patient build‑out of its internal controls environment, working alongside an internal SOX compliance lead and an external audit advisory partner — this role will be a key contributor to that effort.
This is an individual contributor role reporting to the SAP Team Manager, with no direct reports. It's best suited to someone who wants full ownership of SAP security and GRC at a company that is actively building its security maturity, not simply maintaining what's already in place.
This is a hybrid position based out of Broomfield, CO (preferred) or Brooklyn Park, MN; candidates open to relocation will also be considered.
Candidates must be authorized to work in the United States without current or future visa sponsorship.
RESPONSIBILITIES- Own the design, build‑out, and ongoing optimization of SAP security roles and authorization models across SAP applications.
- Lead the redesign of a legacy, brownfield security structure into a scalable, well‑governed role and authorization model as the company grows globally.
- Administer and support the SAP GRC solution, including Access Control workflows and Segregation of Duties (SoD) monitoring.
- Analyze access risk and recommend mitigation strategies aligned with the company's security and compliance standards.
- Serve as the primary point of contact for SOX compliance and security‑related needs across Finance, Internal Audit, and other business stakeholders.
- Generate audit evidence and documentation to support SOX compliance reviews and internal or external audits, partnering with the company's SOX compliance lead and external audit advisors.
- Coordinate periodic user access reviews and certification activities.
- Partner with business process owners to validate security requirements and approve access requests.
- Support testing and validation of security‑related changes, role modifications, and GRC configuration updates.
- Participate in SAP projects, upgrades, and implementations to ensure security and compliance requirements are built in from the start.
- Investigate and resolve SAP security incidents, access issues, and authorization errors.
- Develop and maintain security documentation, procedures, and standards as the team builds toward greater process maturity.
- Coordinate with the internal Information Security…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).