×
Register Here to Apply for Jobs or Post Jobs. X

SAP GRC Lead

Job in Parsippany, Morris County, New Jersey, 07054, USA
Listing for: GAF
Full Time position
Listed on 2026-08-07
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, SAP Consultant, Systems Analyst
Job Description & How to Apply Below
Location: Parsippany

SAP GRC Lead

At GAF, we cover more than buildings. We cover each other. No matter what role, tenure, or track, under this roof you are empowered to be there for your teammates, your customers, and especially your community. Under this roof, we don't back down from hard work– we support one another in pursuit of something bigger. We define the future while leading the present.

And under this roof, we own our opportunities. Becoming the market leader only happens when everyone feels they have the opportunity, and the support, to thrive. We are GAF. And under this roof, we protect what matters most.

Job Summary The SAP GRC Lead is a senior specialist responsible for governing identity, access, risk, and compliance across the organization's SAP landscape. This role owns the end-to-end GRC strategy covering SAP GRC Access Control, SAP Identity Access Governance (IAG) on BTP, and the security models for all SAP SaaS platforms — including SAP Ariba, SAP Analytics Cloud (SAC), and SAP Integrated Business Planning (IBP).

The GRC Lead acts as the primary point of accountability for SoD risk mitigation, access provisioning governance, and audit readiness across on-premise and cloud-based SAP systems.

Essential Duties

  • GRC Strategy & Governance
    • Define and maintain the enterprise GRC framework spanning SAP on-premise and cloud, aligned with internal audit, legal, and regulatory requirements
    • Own the SoD (Segregation of Duties) rule-set across all connected SAP systems; manage conflict detection, mitigation controls, and compensating control documentation
    • Lead periodic access review and certification campaigns; drive remediation to closure
    • Establish policies and procedures for privileged access, emergency access management (EAM / Firefighter), and periodic user access reviews
  • SAP GRC Access Control
    • Administer and configure SAP GRC AC modules:
    Access Request Management (ARM), Access Risk Analysis (ARA), Emergency Access Management (EAM), and Business Role Management (BRM)
    • Design and maintain the GRC connector landscape for S/4

    HANA, ECC, and connected SaaS systems
    • Manage workflow configuration, MSMP routing rules, and approval hierarchies within GRC AC
    • Perform ruleset reviews and fine-tune risk definitions to minimize false positives while maintaining SOX/audit coverage
  • SAP Identity Access Governance (IAG) on BTP
    • Own the SAP IAG deployment on BTP: tenant configuration, IAS integration, access analysis, and role assignment workflows
    • Manage BTP trust configuration between IAG and SaaS platform connectors
    • Coordinate with the BTP Integration Lead on XSUAA scoping, role collection design, and subaccount trust settings relevant to IAG
  • SaaS Platform Security Models
    • Govern the security model for SAP Ariba:
    • Procurement and sourcing role design, user provisioning, and SoD rules for Ariba Buying, Invoicing, and Contracts
    • Ariba Network realm administration and supplier access governance
    • Govern the security model for SAP Analytics Cloud (SAC):
    • Team and role model design; story, model, and data access permissions
    • Integration with CDS view security for governed data access
    • Govern the security model for SAP Integrated Business Planning (IBP):
    • Supply-chain planning user roles, keyfigure-level access, and planning area security
    • IBP-to-S/4

    HANA integration security and cross-system SoD alignment
    • Maintain consistent naming conventions, provisioning workflows, and access certification cycles across all three SaaS platforms
  • Stakeholder Engagement & Team Leadership
    • Partner with Business Process Owners, IT Security, and Internal Audit to align GRC priorities and risk appetite
    • Mentor GRC analysts and role administrators; build team capability on IAG, SaaS security models, and audit processes
    • Engage with SAP and third-party vendors on GRC product roadmap, patches, and best practices

Qualifications Required

  • Bachelor's Degree is required
  • 8+ years of SAP security and GRC experience, with at least 3 years in a lead or architect capacity
  • Deep hands-on expertise with SAP GRC Access Control (AC 12.x): ARM, ARA, EAM, BRM modules
  • Proven experience implementing and administering SAP IAG on BTP
  • Demonstrated experience governing the…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary