We provide IT Staff Augmentation Services!

Sr. Sap Security/grc Engineer Resume

5.00/5 (Submit Your Rating)

Naperville, IL

SUMMARY:

  • Over 13 years of experience in IT /SAP industry with primary focus on SAP Security strategy, Governance Risk & Compliance implementation projects specialized in design and implementation of SAP New dimensional products.
  • Experience includes 4+ years as SAP HCM Analyst and 8+ years of SAP Security/GRC
  • Led several work streams on large and complex business transformation projects supporting teh security strategy, design, building, testing and deployment of complex role Based Access Control Solutions for various clients..
  • IT Professional experience in applications analysis, design, development, testing, gap analysis, implementation, maintenance, support, training and programming of turnkey projects
  • Consulting experience working with top Consulting organizations like IBM, TCS, Infosys, Cognizant and SAP AG

TECHNICAL SKILLS

  • Experience with standard uploading tools such as: LSMW, Win shuttle, CATT, Quick test, Pro, etc.
  • Written and executed test scripts for teh testing of teh interface to third party benefit providers
  • Utilized HP Quality Center for Test Scripts, Test runs and Defect Management.
  • An TEMPeffective communicator with exceptional relationship management skills with teh ability to relate to people at any level of business.
  • Work with IT and business users to facilitate questions and oversight of issues resolution.

PROFESSIONAL EXPERIENCE

Confidential, Naperville, IL

Sr. SAP Security/GRC Engineer

Responsibilities:

  • Implementation of SAP Governance &Risk and Compliance tool includes User provisioning and Access risk management modules
  • Configured security workflows for User access review and Firefighter log review processes
  • Assess current landscape and provide recommendations of governance as it relates to security, segregation of duties, role management, and user access.
  • SAP Security implementation - single point of contact (Role design for IT and business, configuration, UAT, Hyper care support, Service Now incident tracking etc.) for Nalco Saudi/Champion Arabia
  • Worked as a liaison to teh IT Security group as well as our AMS - TCS (remote) SAP Security team.
  • Supporting SAP GRC 10.1 for Ecolab (EBS) and GRC 5.3 for Nalco system for issues pertaining to access requests and working with teh end users till they get teh required access
  • Worked with Sail Point IDM for password related issues.
  • Creating and conducted training for users, role owners, compliance owner and managers
  • Ensure that security controls are compliant with Sarbanes-Oxley.
  • Troubleshooting and performing root cause analysis for critical Incidents and documenting teh same.
  • Worked with internal and external Audit teams - PWC for sensitive transaction and query access reviews.
  • Worked on Audit projects and working as a liaison between teh security team and auditors.
  • Performed Quarterly BPC Production access review and made teh necessary updates in teh system accordingly
  • Running Virsa reports in teh PRD environment at user level and role level and analyzing teh conflicts at teh user level and drawing conclusions, how to reduce teh conflicts in teh SAP system.
  • Review roles conflicts reports and make suggestions as to role changes to avoid conflicts within teh roles.
  • Extracting and analyzing various system reports (UAR, Critical actions, SoD reports, Security parameter settings, etc.) to make sure teh systems are compliant
  • Developed roles with proper naming convention depending upon business and functional requirements for FI/CO, SD, MM, BOBJ, Portals and BW/BI modules
  • Monitoring teh critical transaction codes and ensures that they are assigned to teh concerned users only.
  • Handled complex tickets and took up teh responsibility till teh issue got resolved
  • Strategizing and implementation of SAP Security model, processes and procedures, defining various Role Matrices and designing templates.
  • Worked with AD/Workday team for teh issues related to SSO
  • Solving ticket issues in Security related tables and reports/programs.
  • Configuration and support of GRC 10.1 system
  • Removal/ Mitigation of SOD violations
  • Producing SoD Analytical Reports (both Summary and Detail) against Users, User Groups, Roles and Profiles
  • Mitigation and remediation of users and roles for SOX using User/Role Analysis
  • Determining and report if any risks will be introduced by simulating teh addition of transactions, Roles, or Profiles to a User ID.
  • Modifying GRC Rule set, MSMP workflow enhancements
  • Configured complex provisioning scenarios in GRC using BRF+ applications and reduced teh support request count
  • Analyzing risk analysis through User & Role level.
  • Implemented Risks and Functions.
  • Involved in Post-installation activities of Firefighter.
  • Documentation in various security processes, procedures, auditing; noledge transfer and an active team player.
Confidential, Chicago, IL

SAP Security/GRC Analyst

Responsibilities:

  • Designed and automated teh GRC User access review process in GRC10.1 (UAR)
  • Configured complex provisioning scenarios in GRC using BRF+ applications and reduced teh support request count.
  • Build BI analysis authorizations and security roles to restrict users on various levels
  • Designed security roles for end users to read specific views with controlled row level access
  • Designed access management solutions to automate teh provisioning process for customers
  • Designed and built security roles considering SOX recommendations
  • Designed security roles for end users to read specific views with controlled row level access
  • Monitored and analyzed segregations of duties at user level and designed mitigation strategies
  • Support teh project team members with various access related issues during various project phases
  • Technical analyst for SAP security in production & non-production environments.
  • Worked on critical authorization objects security related tables
  • Authorizations insights implementation and SOD analysis
  • Day to day technical support and resolution of Security issues.
  • Implement standards for custom authorization objects.
  • Performed user maintenance tasks, User creation, deletion, lock down, activation, password management tasks and ran various user administration reports.
  • Troubleshoot security/authorization related problems
  • Assigning additional roles to teh existing users.
  • Created Base Roles and Company Specific Roles based upon request
  • Addition, Removal of Transaction Codes, authorizations, authorization objects by modifying existing roles based upon change request.
  • Reviewed teh Organization structure, jobs, roles and teh SOD matrix for teh Security developed in SAP and handled SOD conflicts for Sarbanes Oxley Compliance.
  • Supported audit team for generating audit reports as per teh audit rules provided by teh auditors
  • Worked closely with Audit team for user-role conflict removal in R/3 and BI.
  • Supported Internal and External security audits in teh production system·
  • Created Security reports as Key Controls for SOX including critical transactions/objects and user administration.
Confidential, Kansas, KS

SAP Security Consultant

Responsibilities:

  • Involved in gathering end user requirements and implement SAP R/3 and BI security authorizations.
  • Building SAP roles and define jobs by coordinating with functional project team members.
  • Work with business owners to define teh authorizations needed for users.
  • Set-up SAP authorization profiles and roles that represent teh different end users job definitions.
  • Created CATT scripts for creating mass users, deleting mass users, assigning roles to users, locking and unlocking mass users in a CUA system.
  • Resolved daily SAP Security issues.
  • Maintain various role matrices for roles, authorization objects to keep track of teh modifications made teh roles.
  • Maintenance of User Master Record & Support End Users with Security issues.
  • Restrict open authorizations to sensitive Transaction codes.
  • TEMPEffectively analyzed trace files and tracked missed authorizations for user’s access problems and inserted missing authorizations manually.
  • Used SU24 to maintain Check Indicator Defaults and Field values, reduced teh scope of Authorization checks.
  • Extensively used SU53 and ST01 for analyzing teh authorization errors
  • Built Analysis Authorizations using teh transaction RSECADMIN and made info objects “authorization-relevant” in teh info object maintenance tool RSD1.
  • Created roles restricting access to Info cubes, ODS objects, specific queries and workbooks.
  • Assigned teh Analysis Authorizations to teh role using teh object S RS AUTH.
  • Build security and successful testing of various objects related to Dashboard.
  • Implemented Central User Administration (CUA) within R/3 and BW system landscape
Confidential, San Antonio, TX

SAP Security Consultant

Responsibilities:

  • Worked closely with project team and SAP developers to resolve bugs and improve performance
  • Actively participate in client discussion and meetings, manage engagements, prepare project documentation, balance teh occurrence of unanticipated issues, and lead workshops on security topics as needed.
  • Designed security roles for HR, Finance FSCM, AP, AR, Logistics Master data, Sales and Marketing teams considering SOX regulations
  • Designed and built BI analysis authorizations for multiple complex sales and finance queries in multiple projects
  • Worked on SU10 to perform mass operations.
  • Analyze and troubleshoot security issues using SU53, ST01 and SUIM
  • Worked closely with Audit team for SAP Security Audit and generated Audit Information Systems (AIS) logs
  • Performed user administration activities such as creating, deleting, renaming, locking and unlocking users, and resetting passwords, maintaining logon data and assigning roles to teh users.
  • Created User Groups by using transaction code SUGR.
  • Fix teh bugs related to roles and authorizations in order to build security in R/3
  • Managing Standard and Custom Authorization Object.
  • Transport Roles using teh change request method and also teh Download/Upload method for transporting teh roles to systems not in teh transport landscape.
  • Worked on Authorization Objects P ORGIN, P ABAP, P PERNR, P ORGXX etc.
  • Assigned structural profiles to users using teh program RHPROFL0
  • Maintained authorization profiles using OOSP.
  • Created transport packages to move roles from development portals to other systems in teh landscape
  • Performed user administration activities such as creating user ids, copying user ids, assigning roles, assigning groups etc.
  • Created groups and assigned roles to groups.
Confidential, Chicago, IL

SAP Security Consultant

Responsibilities:

  • Creation and maintenance of user master records in a CUA environment using CATT Scripts
  • Assigning teh roles to users in different systems as per approved procedures
  • Regular follow ups with teh functional leads on any changes by showing excellent communication and maintaining a good client relationship.
  • Documented teh security role design and security restrictions on SAP.
  • User Management using Central User Administration
  • SOD Conflict analysis & reporting
  • Role creation/modification
  • Analysis of system security and generation of reports for documenting teh same
  • Review security procedures and recommend improvements
  • Identified teh project status and reported to Project Manager.
Confidential, Kansas, KS

SAP Security Consultant

Responsibilities:

  • Provided SOD and Role matrices templates to teh Business owners.
  • Interacted with teh Role owners and teh team lead for maintaining teh correct restrictions on teh Transaction codes and teh activities within teh Transaction codes.
  • Transporting teh change requests from teh Development environment to Testing/QA/PRD environments.
  • Created custom transaction Codes for restricting access to custom tables, views and programs.
  • Created Authorization groups and assigned Tables and Programs to teh groups.
  • Performed reconciliation of user master record and roles using PFUD.
  • Built Analysis Authorizations using teh transaction RSECADMIN.
  • Assigned teh Analysis Authorizations to teh role using teh object S RS AUTH.
  • Troubleshoot authorizations related problems using RSECADMIN
  • Setup security at teh Info objects level (field-level security).
Confidential, New York, NY

SAP HR Consultant/SAP HR Security

Responsibilities:

  • Created teh test strategy and test plans for regression testing during support package application.
  • Implementation and Post Production Support for PA, OM, Time/CATS, ESS/MSS, Payroll and Benefits Modules.
  • Provided critical functional support involving system configuration, technical assistance to end users of teh Personnel Administration, Organization Management, Benefits and Payroll modules of SAP HR.
  • Created Functional specification as per client requirement. Info type Creation and Info type enhancement, Personnel Administration configuration, Creation of data template as per requirement and data upload with LSMW/BDC, Unit Testing.
  • Worked on Authorization Objects P ORGIN, P ABAP, P PERNR, P ORGXX etc.
  • Assigned structural profiles to users using teh program RHPROFL0
  • Maintained authorization profiles using OOSP.
Confidential, Moline, IL

SAP HCM Consultant

Responsibilities:

  • Conducted scoping and business workshops for Blueprint design.
  • Completed major phases of teh project using teh ASAP methodology in teh implementation of PA, OM, Payroll
  • Creating teh test plan and test cases using mercury testing tool.
  • Run test scenarios for custom programs, features, user exits, dynamic actions, and processes.
  • Provided production support to business users during go-live and post production.
  • Developed Test Plans, Test Cases, prepared Test Data for interpreting teh positive/negative testing.
  • Performing Functionality, Unit, and Integration testing.
  • Created Actions, Configured info types and performed conversions of info types.
  • Conducted an overview training of SAP Organizational Management and Personnel Administration and configuration of Organization Structure & Staffing.
  • Set up new SAP benefit plans and modified existing benefit plans to suit teh client’s business process.
  • Setup Portal content including ESS/MSS components. Portal configuration for views (hiding fields, filtering, label changes, etc.)
Confidential

SAP HR/HCM Corporate Trainer

Responsibilities:

  • Responsible for delivery of training to end users, business process owners and super users in teh areas of Payroll

    Developed teh training schedule and consulted with Subject Matter Experts.

  • Analyzed business processes and training needs in teh areas of Payroll, Benefits, Time Management and LSO

    Created teh Training materials for HR- Payroll, Benefits, Time Management and LSO using Infopak

    Created and updated course materials

Confidential

SAP HCM Consultant

Responsibilities:

  • Provided post-implementation support in teh modules of PA, OM, Travel, Time Management, CATS and Payroll.
  • Explored new solutions for teh client and TEMPeffective execution of teh same
  • Generated reports using Ad-hoc query and SAP-Query.
  • Defined Functional Specifications for new developments
  • Drafted teh test cases and testing teh new developments across development and quality environments in R/3 system.
  • Continuously upgrade teh system with teh latest “Support Pack” releases from SAP
  • Assisted teh client in modifying teh existing organizational structure to meet business requirements
  • Workflow: Employee trip handling and Time approval with workflow approval process. Notifications to teh employee and manager
  • Monitored SLA’s for teh team, handling complex tickets and taking up teh responsibility till teh issue got resolved.
  • Monitored SLA’s for teh team handled complex tickets and took up teh responsibility till teh issue got resolved.
Confidential

SAP HR Consultant

Responsibilities:

Tata Motors – Shift Planning Implementation

  • Responsible for solution documentation (Business Blue Print), requirement mapping and customizing teh configurations with face-to-face client interaction, discussing HR functionalities and implementing in 4.7 version and integrating applications.
  • Planning and Configuring Shift planning with various Shift Groups using company’s factory Calendar.
  • Testing teh scenarios in Quality system such as changing teh shifts in target plan, locking /unlocking employees, freezing teh target plan, making changes in teh actual plan, deployment of employees from one organizational unit to other
  • Responsible for preparation of user manual and user training.

TCS, India (Client- SAP AG), Germany – Global Production Support of SAP HR

  • Managed a small team of consultants for post implementation support and enhancements activities.
  • Responsible for 2nd and 3rd level production support in teh modules of PA, OM, Time Management, Travel Management, Payroll and ALE/IDOC
  • Configured teh system as per teh Service Requests. Documented teh various business processes.
  • Monitored SLA’s for teh team, handled complex tickets and took up teh responsibility till teh issue got resolved

SAP Labs – E- Recruitment Testing

  • Preparing test scenarios and system test cases.
  • Managing a team of testers.
  • Helping teh developers and testers in better understanding of teh business process.
  • Documenting, execution of system tests.

Telcon – SOX Compliance

  • Analyzing and enhancing Clients entire HR processes.
  • Setting process boundaries and defining and documenting ‘Hire to Retire’ processes cycle.
  • Documenting teh business scenarios in teh form of flow charts and narratives.
  • Interacting with client at different stages of project, and convinced them with TEMPeffective presentations.
  • Documenting each SOX control for compliance reporting and auditing
  • Creating control documents on teh basis or templates required by SOX

Tata Motors – Upgrade and Support Project of SAP HR

  • Analyzing and Actively involved in production support and up gradation activities from 4.6c to 4.7
  • Responsible for teh production support of Personnel Administration, Organizational Management, Recruitment, Training and Event Management, PD, Payroll, Travel Management and Time Management modules.
  • Preparing user- manual, conducted end-user training sessions.
Confidential

HR Executive

Responsibilities:

  • Designed HR policies and forms at teh corporate level and implemented successfully.
  • Designed Hiring procedure to hire best candidate in coordination with Group Heads with a proper procedure suiting their requirements.
  • Designed Resume Management system to upgrade databank and for easy look out of desired profile.

We'd love your feedback!