Sap Resume
New Jersey, NJ
PROFILE
I am a SAP security architect who\'s driven by providing SAP project sustainment, with a strong sense of process control and technical safeguard to protect the data integrity for clients. To effectively sustain business data in SAP systems, I applied SAP GRC suites to address the Segregation of Duties Management Process, Compliance Calibrator for Risk Recognition, Rule Building, Validation, Risk Analysis SAP System and Compliance Calibrator for Remediation Alerting Functionality of Compliance Calibrator, Firefighter and Risk Terminator for Mitigation Continuous Compliance. I\'m equally at home on production support and detailed SDLC project management, and up to speed on traditional and new-millennium research tools and approaches. I\'m truly fanatical about understanding the SAP enterprise marketplace better every day, week and month -- and have helped my clients’ SAP systems grow in a controlled manner as a result.
My experience involves implementation and production support of SAP application with infrastructure security. With over ten years in performing complex and conceptual analysis, consulting, project management, I provide recommendations in the areas of application security, business process control, information technology design, implementation and assessments of policies and procedures. My specialization is in SAP Security Access Control, regulation compliance, and he possesses general understanding of the business drivers operating on the enterprise level, as well as its components in products, services, finances and strategies. List of prior SAP project experiences with Computer Science Corporation, Deloitte&Touche, and SAP America include the following institutions: DuPont, Pratt& Whitney, Kone Elevator Manufacturer, US Army Logistics Control, Internal Revenue Services, ATMEL Semiconductor, Alpine Electronics, GTECH Corporation, FileNet, Foster Farms Poultry Company, Raytheon, T-Mobile, Phelps Dodge Mining, Ingram Micro, DirecTV, Ceradyne, Chicago Metro Water District, and Smith Micro Software.
PROFESSIONAL EXPERIENCE
Confidential, August 2009 – Present
SAP QM & Security Redesign Project (Version ECC 6.0)
SAP Security Lead consultant
- Resolve QM configuration issues related to Record Inspection Result and Change Inspection Result in terms of authorization objects technical aspects
- Deliver QM user roles to meet business requirement
- Manage E&Y audit findings and bring resolution to the related SOD issues
- Draft SAP security policy and guidelines to address Security operation and administration tasks
- Manage security redesign project, lead security team to establish the project baseline, user access history, user role assignment, customized transaction and reports, and publish redesign strategy
- Provide periodical status report to management , facilitate presentation material for user workshop
- Apply Approva/BizRights 4.5 version for security role redesign effort to meet SOX concerns and sustain SOD compliance
Confidential, May 2009 – July 2009
Project New SAP Implementation (version ECC 6.0)
SAP Security Lead
- Accelerated and mapped security requirements with SME and Business owners
- Accomplished MM, PP, SD, FI security requirements for client’s user role assignment
- Coordinated integration test results, gap analysis, and provided proper remediation
- Documented user authorizations, trained staff
Confidential, January 2009 – May 2009
Project Logistics Implementation (version ECC 6.0)
SAP Security Lead
- Collected and mapped security requirements with SME and Business owners
- Constructed MM, PP, SD security knowledge to client’s user role assignment
- Led Security in blueprint, realization, test and implementation tasks
- Conducted integration test results, gap analysis, and provided proper remediation
- Identified SAP GRC 5.3 Access Control to meet the enterprise audit compliance
- Managed HCM HR-IS development work in Query authorizations
- Documented user authorizations, train staff, and paved ‘building block’ for third phase and future enterprise implementation
Confidential, September, 2008 – November, 2008
Project Security Remediation (version 4.70)
SAP Security Consultant
- Re-designed security requirements with SME and Business owners
- Applied HR, BW/SEM, SD, MM, FI/CO security knowledge to user role assignment
- Formulated ESS/MSS configurations to support project analysis in working hours accumulation and resources consolidation
- Designed with Basis team to initiate security logs in Solution Manager
- Initiated Security re-design and execution tasks for the newly acquired division
- Devised and Established integration test results, gap analysis, and provided remediation
- Reviewed GRC package with intention for next HR phases to do user provisioning and termination process
- Documented user authorizations, trained staff, and prepared for next Audit review
Confidential, May 2008 – July 2008
Project FI Implementation (version ECC 6.0)
SAP Security Lead
- Mapped security requirements with SME and Business owners
- Applied FI/CO security knowledge to client’s user role assignment
- Launched Security design and execution tasks
- Tested and reviewed integration test results, gap analysis, and provided remediation
- Wrote Security Management policy and Guidelines
- Expanded out HCM implementation, HR Payroll and ADP interface
- Introduced SAP GRC suites package to PMO
- Documented user authorizations, trained staff, and prepared for second phase implementation
Confidential, May 2008 – May 2008
Project BI Upgrade (BI version 7.0)
SAP Security Consultant
- Reviewed BI security processes with Business owners
- Presented BI security knowledge to client’s user role assignment
- Migrated BW 3.5 authorizations to BI 7.0 analysis authorization
- Accomplished and reviewed integration test results
- Served as a functional lead to address APPROVA issues
- Reviewed Virsa 4.0 package to meet the enterprise access control and audit compliance, met with APPOVA upgrade team to discuss upgrade schedule
- Negotiated BI new analysis authorizations impact to developers
Confidential, Oct 2007 – May 2008
Project PRISM SAP system (version 4.7)
SAP Security Consultant
- Collaborated security processes with Business owners requirement and Change management workflow
- Implemented CUA security knowledge to redesign client’s user role assignment
- Managed Integration test defects and updated authorization objects and roles
- Generated Training system and coordinated with trainer and training documentation
- Assisted in implementation of the APPROVA and Solution Manager to meet the enterprise access control and audit compliance
- Aligned security guidelines with developers and Business SME for project deliverables
Confidential, July 2007 – Oct 2007
Senior Security Consultant (version 4.7, ECC 5.0, ECC 6.0)
- Assessed security upgrade from 4.7 to ECC 6.0 with infrastructure architect
- Applied Role based security practice to redesign client’s user role assignment
- Practiced BI 7.0 analysis security and updated authorization objects and roles
- Called upon SEM BPS security with clients about best practices and standards
- Served as a principle and contributes to enhance SAP GRC best practices
- Led design and oversee development of complex, cross-functional, multi-platform processes and application systems
- Advised clients and developed complex technical architecture and design
- Advised client on complex systems management plans and issues
- Designed and documented administration policies and procedures to meet SOX compliance
Confidential, April, 2007 – June, 2007
Global Financial Initiative SAP Project (ECC 6.0)
SAP Security Administration
- Participated in infrastructure architect for SAP security
- Gathered authorization objects and roles for FI/CO and OTC
- Experienced with eFax OCR software to integrate with SAP A/P user access
- Presented blueprint design in establishing the security procedures for SAP systems
- Led the process of data classification and sensitive data interface matrix
- Selected SAP GRC suites to meet the enterprise access control and audit compliance
- Designed and documented security administration policies and procedures for the production environment to meet SOX compliance
Confidential, October, 2006 – March, 2007
RedPoint Moly SAP Project (ECC 6.0)
SAP Security Architect
- Participated in requirements gathering, assessment, design, configuration and testing activities for SAP security
- Configured authorization objects and roles for MM, PP, APO, FI/CO, and OTC
- Managed the CUA establishment of SAP landscape
- Implemented SAP security using best practices and standards for SAP security
- Provided support in establishing and maintaining the security and security procedures for SAP systems
- Led the process, training, and change management teams to implement appropriate role-based security for the production environment including role definition and job/position mapping
- Enforced SOD concept in deploying security roles and established procedures for role simulation after implementation
- Designed and documented security administration policies and procedures for the production environment to meet SOX compliance
Confidential,Project SOX Compliance (Version 4.7) January, 2006 – September, 2006
SAP Security Redesign Team Lead
- Responsible for Role Redesign effort of SAP security roles for FI/CO, BW, SEM, EBP, HR, and SD
- Designed and directed governance activities to ensure compliance with the application and enterprise architecture
- Designed and deployed GRC Access Control methodology for documenting Compliance /variance of projects to meet SAP best practices and SOX requirements
- Designed and led the implementation of processes for mapping new application requirements to infrastructure guidance
- Led technical and engineering teams to develop and maintain architecture and standards for Application Development, Delivery, and Deployment
- Developed and led the implementation of application standards, Virsa (4.0 version) Fire Fighter to review with auditors on subjects of design of IT controls, Segregation of Duties, and Sarbanes Oxley compliance
- Evaluated complex technical issues and recommended actions or programs for their resolution
Confidential,Project PRISM SAP system (Version 4.7) April, 2005 – October, 2005
SAP Security Architect Lead
- Responsible for creation of security roles for SCM, FI/CO, BW, SEM, Depot, MM, WM, IM, PS, HR, PM, GPD, SD
- Provided auditors on subjects of IT access controls, Segregation of Duties, and Sarbanes Oxley compliance
- Performed unit and integration test cycles with functional teams to refine the configuration of roles
- Prepared Production Go Live procedures, coordinated hyper care and SCR sustain effort with Help Desk support
- Validated IMG configuration setup with Business Process Team
- Attended Change Control Meetings with functional teams, analyzed and designed the requirements of the post-implementation procedures
Confidential,LLP
Project FileNET SAP system (Version 4.6C) September, 2004 – March 2005
Senior SAP Security Consultant
- Responsible for auditing IT Operation with COBiT ten areas of General Computer Controls guidelines
- Reviewed design of IT controls, Segregation of Duties, and Sarbanes Oxley compliance
- Performed Walkthrough of Key IT Areas: Change Control, Information Security, Operation, Physical Security, and System Software
- Tested Business Cycle Controls Designated by Financial Audit, worked with internal audit team for follow-up remediation
- Reviewed significant events in the past years, prepared roll-forward procedures at year-end
Confidential,LLP
Project Alpine SAP system (Version 4.7) July, 2004 – September 2004
Senior SAP Security Consultant
- Responsible for drafting up the SAP Security and Operation Procedures and Policies
- Combined the Indiana Operation with Torrance plants site with uniform Policies
- Worked with Alpine staff to update the overall IS Operation and IS Policy
Confidential,LLP
Project ATMEL SAP system (Version 4.6C) May, 2004 – July 2004
Senior SAP Security Consultant
- Responsible for compliance work to meet Sarbanes Oxley Act, and provided recommendations to management to sustain SAP Security going forward
- Extracted SAP data and reviewed the possible gaps in both access control and segregation of duties
- Worked with internal and external auditors to align the remediation effort
TECHNICAL EXPERIENCE
Operating Environments: UNIX, MVS, DOS/Windows, Windows 95/98/NT/2000, HP-MPE/ix
Languages: SQL, Visual Basic, PowerBuilder, Dbase4, COBOL/COBOL II, C++, Cognus PowerHouse, SmallTalk
Databases: Oracle, Informix, Sybase, DB2, IMS, ACCESS, IMAGE, KSAM
Development Tools: SAP profile generator, Vision Data, Visual Basic, WinRunner, PowerBuilder, OO Analysis and Design
Modeling Tools: Rapid prototype Data Modeling
Data Base Tools: QTP, QMF, Quiz, Query, SuperTool, DBArtesian
Development Methodologies: ASAP, Catalyst and CSCMap
Applications: MS Office Products; Lotus Notes
EDUCATION
M.S. in Forest Management
B.S. in Natural Resources
BI 7.0 Analysis Authorization
Virsa version 5.0 Training
SAP Enterprise Overview 4.7
SAP BASIS Delta 3.x to 4.6 Training, Chicago
CSC SAP Academy, Newark, Delaware
