We provide IT Staff Augmentation Services!

Global Lead Security Architect (sap) Resume

4.00/5 (Submit Your Rating)

PROFESSIONAL PROFILE:

  • I have 18 years' experience as a SAP Security Ad ministrator/Engineer/Architect and GRC. As a Sr. Security Architect, I worked on the implementation of SAP Security involving more than 30 separate from Design/ Build to Go Live initiatives with multiple companies.
  • Engaged in 24 separate from Design/Build Go Live initiatives for an international logistics corporation. Contributed to multiple project implementation strategies, outlined operational security dependencies, pro vided staff training, and created procedural manuals outlining protocols for Segregation of Duties and run environment exe cution structure.
  • Support implementation teams through access controls to enable transaction activity and enforce security protocols for all new applications and upgrade of existing applications.
  • Developed test scripts for Unit/Functional and Integration testing of role definitions in QA. Prepared Stage and Production environments for Go - live readi ness.
  • Responsible for ensuring that all en vironments are SOX and Audit compliant. Worked closely with the internal SOX and Audit teams to review process documenta tion for the continuing compliance of all environments.
  • Worked with the Business and Func tional teams to assure that end users could efficiently perform job duties while still adhering to SOX and Audit Compliance mandates. Reviewed the implementation and configuration of multiple GRC tools and utilized it for the identification of role con flict/compromise in all environments.
  • Gathered tcode requirements from blue print designs for role creation within and across departments. Worked with SU24/SU53 and ST01/ST03 analysis to determine authorization errors.
  • Participated with the Process Experts/Solution Architect of various teams to design end user functional roles. Constructed roles and lead design and execution testing on functional roles from design to hyper-care.
  • Lead a Global group that was respon sible for New Business Unit Implementation. Collaborated with teams such as Communications, Change Management, PMO, Deployment, Training, Portal, Basis and Functional teams. Oversaw the user provisioning ac tivities and performed post -provisioning audits.

CHRONOLOGY OF EXPERIENCE:

Confidential

Global Lead Security Architect (SAP)

Environment: SAP

Responsibilities:

  • Supporting modules HANNA DB/BW4HANA/ MIRP-MDM/MDG,PLM, SAM, SVC, SCM, VC FIN, FIORI, BI, UACC 2.0
  • Business Blueprint and Role Design from sandbox to Production - multiple (44) successful go-live initiatives
  • Role design, creation. PFCG, SU53, ST03, SU24, SU22, SA38, SE93, PFUD, SUPC
  • User Access Control - SU01, SU10, SM04, SAP IDM, GRC
  • Tools: SAP GRC/SAP IDM/SERVICE NOW/CONIGMA/SOLMAN/HPQC/TEAM DYNAMICS/AGILE/WATERFALLS/ etc
  • Technically guiding a Global Security Team of 15

Confidential

SAP Security Engineer

Environment: SAP

Tools: ECC 6.0, SOM, XI, BI-BW, CP GRC

Responsibilities:

  • Collaborated with the system architects from CSC to define the business blueprint for transac­tion design, role definition.
  • Created roles to meet those specifications for all environments.
  • Created and executed the complete Security Plan including Unit and Integration testing of roles in all environments.
  • Worked with the Finance and Internal Audit teams to mitigate SOD’s (Segregation of Duty) violations.
  • Supporting modules MM, PP, SD and FICO
  • Business Blueprint and role Mapping from sandbox
  • Role design, creation. PFCG, SU53, USR02, ST01, SU24, SA38
  • User Access Control - CUA, SU01 and SU10
  • Worked on setting up SOD tool (Control Panel GRC) and implementing compliance to all role and user definitions

Confidential

SAP Security Consultant

Environment: SAP

Tools: ECC 6.0, EP, SM, TM, XI, SAP GRC

Responsibilities:

  • I collaborated with the system architects to define the business blueprint for security transac­tion flow, role definition, design, and Tcode definition.
  • Created roles to meet those specifications for all environments.
  • Created and executed the complete Security Plan including Unit and Integration testing of roles in all environments.
  • Worked with the Finance and Internal Audit teams to mitigate SOD’s (Segregation of Duty) violations.
  • Configured and administered Access Enforcer, Firefighter, Compliance Calibrator and Role Expert.
  • Worked with the portal and net­work teams to define and implement Single Sign on through the Portal using the internal LDAP (Active Directory).
  • Business Blueprint and role Mapping
  • Role design, creation. PFCG, SU53, USR02, ST01, SU24, SA38
  • User Access Control - SU01 and SU10
  • Configuration and Administration of Access Enforcer, Firefighter, Compliance Calibrator

Confidential

Consultant SAP Security and Controls

Environment: SAP (FSP Project)

Tools: ECC 6.0, EP, SM, SRM, CRM, BI, Approva, IDM (CA), Vertex, XiPay, Unicenter (CA)

Responsibilities:

  • Performed SOD analysis using Virsa Compliance Calibrator and Approva Bizrights on all role profiles.
  • Consulted with the business units to resolve conflicts to preserve job function.
  • Worked closely with the business as well as the implementation partners to facilitate the design and implement both stopgap and long­term processes that introduce new compliance monitoring technologies to the project.
  • Performed regular system audits to detect deviations from established protocol practices and reported findings to management.
  • Regularly reviewed transaction logs to document security violation for Internal Audit review and investigation.
  • Devel­oped, maintained and communicated general computing controls, SAP Security Policy and procedures.
  • Role design, creation. PFCG, RSECADMIN, RSA1, SU53, USR02, ST01, SU24, SA38
  • User Access Control - SU01 and SU10
  • Central User Administration - CUA, SCUG, SCUA, SCUL
  • Sarbanes­Oxley and FDA requirements for the Domestic and Global (notably Singapore) enterprises
  • SAP Security Policy and procedures ­Develop, maintain and communicate general computing controls
  • Mentor peers in the SAP Security organization regarding process, troubleshooting, priority setting and project management

Senior Access Control Analyst

Confidential

Tools: SAP R/3, Virsa Compliance Calibrator, Ames, DJIT, Business Objects, Clarify, ITG, Novell, NTActive Directory, VPN, Microsoft Outlook

Responsibilities:

  • Performed Security and User Administration tasks on all of the above tools and applications.
  • Lead implementations that were responsible for deployment and administration of end users for various SAP modules.
  • Created the security structures, role definition, and role profiles to facilitate implementation and support of a Go Live in the Singapore op­erations of the SAP R3 environment.
  • User Access Control - SU01 and SU10
  • User Administration on CUA
  • Part of the project team for the Singapore Deployment

Confidential

Data Center Analyst

Environment: Tandem, AS400, COBOL, RPG

Tools: COBOL, Powerhouse, RPG

Responsibilities:

  • Requirements gathering
  • Development of Code
  • End user testing and code promotion to production

Confidential

Application developer

Environment: HP 3000 - AS400

Tools: COBOL, Powerhouse, RPG

Responsibilities:

  • Engaged the complete software development life cycle as a team member to create custom accounting application functionality.
  • Met with business analysts and technical leads to discuss application requirements and identify developmental approaches.
  • Designed user screens and created logic structures to integrated with existing programs as well as the creation of new programs.
  • Modified and tested in­-house software to ensure Y2K compliance.
  • Utilized COBOL on HP 3000 platform, Powerhouse, and Librarian.
  • Requirements gathering
  • Development of Code

We'd love your feedback!