More jobs:
Job Description & How to Apply Below
Full Time
Posted 2 weeks ago
Consultant | SAP Security & GRC AC | Pune | SAP
Deloitte
Location
Pune, Maharashtra, India
Vacancies: 1
Posted: 14-05-2026
Experience:
3 to 6
Skills:
SAP S4H
Description:
Senior Consultant | Senior OMS Business Analyst | Gurgaon | TST Job requisition
Location:
Gurgaon Entity:
Deloitte Touche Tohmatsu India LLP The team Enterprise technology must do much more than keep the wheels turning; it is the engine that drives functional excellence and the enabler of innovation and long-term growth. Learn more about ET&P Your work profile Lead functional discovery and workshops for order management processes, rules, and integrations. Translate business needs into detailed functional requirements and acceptance criteria.
Analyze current state processes and identify improvement opportunities applicable to the future OMS model. Partner with architects and integration teams to clarify design impacts and dependencies. Support UAT planning and execution, including clarifying test scenarios, expected outcomes, and sign-off criteria. Drive end-to-end traceability of requirements throughout the delivery lifecycle. Mentor junior BAs and support readiness of business SMEs. Key skills required Designing access roles for the SAP S4H environments across multiple domain such as finance, supply, procurement, engineering etc.
▪ Implement best practices in the area of Role build, testing and transport. ▪ Define Role Transport strategy for a highly complex multi-tier environments with separate Sustain and Project Tier. ▪ Propose security best practices for Solutions built on SAP BTP. ▪ Review and share access controls, authentication protocols for 3rd party apps integrations. ▪ Define SOD Risks and mitigation controls by collaborating with process experts, GRC Teams.
▪ Provide input to GRC technical teams to update SoD risk matrix with new transaction codes/Fiori apps etc. ▪ Review custom code, and propose the authorization check to ensure the Organization level controls can be implemented via roles. ▪ Review and update authorization defaults for transactions, Fiori apps, Web-dynpros etc.
▪ Experience of defining audit controls, engage with auditors to drive internal and external audit evidence gathering. ▪ Assist in design, document and continually enhance SAP security administration policies, processes, and procedures for the SAP environment. Support the project teams on SAP Transports using during major releases, dual maintenance/retrofit and object conflict issue resolution ▪ Update and maintain procedure documentation, present to larger team.
▪ Propose technical governance (standards, best practices, etc.), document and present to Larger team. Engage with the Business Process Owners, Product Owners, and internal stakeholders to capture access control requirements. ▪ Work closely with Business analysts, Org Governance Teams and SMEs ▪ Liaise with Cyber Security Teams, Internal/External Audit and Internal Risk & controls teams. ▪ Work closely with Project managers, define Access controls Design, Build, Test Plans identify risks to the projects.
▪ Work with internal Training team, deployment teams closely on content development, delivery and communications. Expertise in application security S4H, Fiori, HANA, SAP BTP with deep understanding of authentication, user provisioning, role design management.
▪ Experience of Master – derived, Value – Enabler technical roles with inclusion of tcodes, Hana views, Fiori Apps etc. ▪ Expertise in Fiori role build, especially Pages, Spaces, Catalogue, Groups, apps etc. ▪ Understanding of OData V2, V4 services, API Security, and troubleshooting complex Fiori and Hana access issues. ▪ Exposure to BTP role build in Abap Environment, HANA Cloud (XSA apps), IAS, IPS, Audit logging, Credential store services etc.
▪ Business process understanding on Core Domains like Supply, logistics, procurement, Trade Controls and Master Data Governance. ▪ Possess experience reviewing custom transactions, updates authorization defaults, with good understanding of authorization objects across domains, including sensitive admin transaction codes.
▪ Experience of developing attribute-based access…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×