We provide IT Staff Augmentation Services!

Sap Grc/security Consultant Resume

4.00/5 (Submit Your Rating)

Dallas, TX

SUMMARY:

  • Strong Experience in understanding Segregation of Duties and Audit Compliance Standards, with multiple SAP security lifecycles (Analysis & Conception, Implementation, Quality Assurance &Tests and Cutover). Excellent knowledge in profile - based security, structural authorizations, Central User Administration, Segregation of Duties (SOD), SAP Governance Risk and Compliance.
  • Extensive and hands on experience in Integration of SAP Security in SAP R/3, SD/MM/PP modules with FI/CO and in overall business processes such as, Order-to-Cash, Purchase-to-Pay and Make-to-Order. With a full implementation in SAP GRC 10.X

TECHNICAL SKILLS:

SAP Security: FI, CO, SD, MM, PP, HR, PAY, GRC AC 5.3/10.0, ERP Maestro

Technical skills: SQL, R, Python, SAP R/3 4.0, 5.0 ECC, GRC AC10.X, Microsoft Office Suite (Outlook, Word, Excel, MS Access & PowerPoint, Microsoft Project)

Functional skills: Project Management, Application Control, SOD Detection & Prevention

Framework & Best Practices: SOX, PII, PCI, COBIT, COSO& HIPPA

PROFESSIONAL EXPERIENCE:

Confidential, Dallas, TX

SAP GRC/Security Consultant

Responsibilities:

  • Managed and led a full life cycle implementation of SAP security from start to finish ranging from requirement gathering, validation of requirements, configuration, migration and testing, cutover related activities and go-live.
  • Designed and created security profiles based on functional and technical requirements of all security roles and authorizations for all SAP modules (ECC 6.0, BW, FI, SRM, SD, CRM, Portals, HR and HANA).
  • Configured, modified and managed Single roles, Composite roles, and Derived roles using automatic profile generator (PFCG) to meet business requirements, ensuring that users get only the authorizations needed to perform their tasks.
  • Created over 1000 job roles utilizing PFCG in FI, SD, WM, MM, PP and HR modules and utilizing STMS, SCC1 and SE10 to transport them from Development to QA for integration testing and then to Production.
  • Designed master, and derived roles for FI/CO by converting certain authorization fields to organizational level fields using program PFCG ORGFIELD CREATE.
  • Troubleshoots Authorization Error Analysis (SU53, SU56) and System Trace (ST01) to conduct in-depth research and mitigation covering authorization denials/unauthorized permissions.
  • Utilized Central User Administration (CUA) to maintain user creation, deletion, modify, lock, unlock and reset password, assigning roles and profiles, and validity changes for roles.
  • Performed Mass deletion of roles in QA and Dev systems as a part of clean-up work.
  • Used SUIM and security related tables such as AGR TCODES, AGR USERS, AGR 1251, AGR 1250, AGR DEFINE to generate Reports
  • Supported SAP ECC, BI, EP, HCM, SRM, GRC Access Control ARA, EAM BRM and ARM (from GRC v5.3 to 10.1).
  • Analyzed users and roles through GRC Access risk analysis ARA component by running SOD reports in Transaction and Authorization level as well as provisioning and de-provisioning roles for user access using Access Request management ARM in GRC AC 10.x.
  • Utilized VIRSA Compliance Calibrator to check for and remove critical SODs on users and roles, and remediated the SOD violations.
  • Implemented SOD conflicts administration strategies and managed remediation tasks to comply with SAP/SOD/SOX requirements.
  • Upgraded SAP access control from GRC 5.3 to 10.1. Roles includes but not limited to the Design, creation and delivery GRC 10 solutions to ensure SAP Security and Compliance and continuous monitoring of access where applicable.
  • Liaised with functional team leads and role owners to help them understand what SAP authorization objects are causing the SOD conflicts and options for conducting remediation and implementing mitigating controls.
  • Developed more than 40 SOD mitigation controls which covers various areas like order to cash, procure to pay, general ledger, Inventory management, master data changes for customer, vendor, materials, sales orders, billing documents, post journal entries, vendor payments, vendor invoices, customer invoices, customer payments and HR. Generated the SOD reports based on user and role and uploaded into application.
  • Configured Emergency Access Management (EAM) for assignment of the Firefighter ID's to support users in order to resolve provisionally broad issue and subsequently captured firefighter audit logs/activities and trigger alert to Firefighter Controller for review of the Firefighter ID usage.
  • Maintained Profile generator authorization table with the use of SU24
  • Worked extensively with Sarbanes-Oxley Compliance (SOX) Strategy and performed Remediation of Segregation of Duties (SOD) within SAP implementation, Profile Generator (PFCG), for developing Roles and Profiles.
  • Utilized SAP Security audit logging tools such as SM20, SM19, SM18), setting Security audit log parameters, logging changes to user master records, profiles, and authorizations
  • Managed, security defects and handled and resolved all technical issues on priority tickets related to Security and GRC.
  • Defined and assigned Role Approvers, Monitors, Risk ID owners, and Business Units.
  • Risk ID creation and assignment to appropriate approvers & monitors for the risk. All the risk are later stored in the companies rule set.
  • Analysis & Remediation of SOD violations against the various risk in SAP GRC 10.0.
  • Role based Simulation of SOD at Transaction Code Level, Authorization Object Level, Critical Role Level & Mitigation Level.
  • Provided project Key deliverables such BRD, FDD, TDD and Training documents. Facilitated weekly status meeting with the project sponsors and created the status report with project details and activities accomplished.

We'd love your feedback!