SAP Authorizations Architect
Listed on 2026-07-02
-
IT/Tech
Cybersecurity, IT Consultant, SAP Consultant, Information Security & Data Protection
JOB PURPOSE
The SAP Authorizations Architect will be responsible for designing, governing, and continuously improving SAP Security, Identity & Access Management (IAM), and Authorizations across the RAK Government SAP Landscape hosted on RISE with SAP (Private Cloud). This includes S/4
HANA, BW on HANA, SAP BTP, SAP Fiori, SAP CPI, SAP SAC, SAP GRC, and SAP API Management.
The role ensures end-to-end access governance, role design, SoD compliance, security audits, and enforcement of RAK Government cybersecurity and IT governance policies. The Architect will lead the definition of role concepts (Business, Composite, Technical), design and optimize Fiori & backend authorization models, coordinate identity lifecycle processes, manage OAuth/Trust configurations, review Cloud IAM entitlements, and conduct periodic access reviews.
The position requires 10–15 years of SAP Security & Authorizations expertise
, strong knowledge of cloud-based IAM, SAP GRC AC/PC, S/4
HANA role design, BTP Security, Identity Providers, Certificates, and adherence to NIST, ISO
27001, and UAE Government security standards.
ACCOUNTABILITIES & RESPONSIBILITIES
- Design and govern SAP role architecture for S/4
HANA, Fiori, BW, BTP, CPI, SAC, and API Management. - Develop and maintain Business, Composite, and Single roles with strict SoD compliance.
- Perform SU24 maintenance, SU53 analysis, STAUTHTRACE troubleshooting, and end-to-end authorization debugging.
- Implement and optimize Fiori catalogs, groups, spaces, and OData authorization concepts.
- Manage cloud IAM: IAS/IPS, Azure AD integrations, OAuth tokens, Trust configurations, and SSO (SAML2).
- Ensure compliance with RAK Government security standards, NIST, ISO
27001, and SAP Security Notes. - Conduct periodic access reviews, user attestation, and adherence to audit requirements.
- Manage SAP Identity lifecycle processes (joiner, mover, leaver) across On-Prem, Cloud, and BTP.
- Design and enforce least-privilege, zero-trust aligned authorization structures.
- Deep expertise in SAP GRC - Access & Process Control
- Review and implement SAP Security Notes, patch compliance, and vulnerability remediation.
- Perform risk assessments, mitigations, and audit-ready documentation.
- Collaborate with Basis, Functional, and Development teams to secure integrations, RFCs, and APIs.
- Support SAP BTP subaccount security (roles, entitlements, trust, connectivity).
- Manage Certificate, OAuth client, and SSO configurations.
- Provide expert consulting during releases, upgrades, new modules, and system migrations.
- Review and implement SAP Security Notes, patch compliance, and vulnerability remediation.
- Perform risk assessments, mitigations, and audit-ready documentation.
Bachelors / Master's in Computer Applications
10–15 years in SAP Security, Authorizations, GRC & IAM (including minimum 2 years in Cloud / RISE with SAP).
SAP Security/GRC Certification, Cloud IAM (Azure/Okta), Cybersecurity certifications (ISO
27001, CISSP, CISM beneficial).
English Language (spoken and written) – Essential
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).