We provide IT Staff Augmentation Services!

Sap Security Technical Lead Resume

3.00/5 (Submit Your Rating)

Vernon Hills, IL

SUMMARY

  • 8 years of professional SAP Security Administration.
  • Experience in all aspects of SAP Security Administration - including production support on different operating systems and database platforms and various SAP R/3 versions 4.6C to ECC 6.0 and S/4 HANA.
  • Worked on all 4 Confidential (VIRSA) 5.3 tools - RAR - Risk Analysis & Remediation (Compliance Calibrator), ERM - Enterprise Role Management (Role Expert), SPM - Superuser Privilege Management (FireFighter) and CUP - Complaint User Provisioning(Access Enforcer).
  • Used Confidential (VIRSA) RAR - Risk Analysis & Remediation (Compliance Calibrator) to assure Sarbanes-Oxley/Segregation of Duties compliance for users.
  • Created a SOX compliant security matrix and operating procedure documents in consultation with process owners, internal audit and VIRSA ( Confidential ) tools. Managed SOX and IT-Audits.
  • Analyzed usage of Emergency Super users in SAP using Confidential (Virsa) SPM (Firefighter).
  • Worked in role design according to Sarbanes - Oxley (SOX) compliance - strategy management related to SAP business processes, transactions, control infrastructure and governance and audit requirements, resulting in improved processes and procedures.
  • Worked on Confidential 10/10.1 AC Components (ARA, EAM, ARM, BRM) Security Roles upgrade/Configuration.
  • Build HANA roles with analytic privileges for data restriction.
  • Confidential SOD risk analysis for HANA authorizations based on privileges.
  • Designed security roles using profile generator for SD, MM, PP, FI, CO, PM and HR modules.
  • Worked closely with HR to understand business processes and requirements.
  • Creating and Assigning Roles and Authorizations to the users, Deriving the derived roles from existing roles, Role maintenance and Role Transportation,
  • Worked on Security design using SAP HANA Studio.
  • Modified existing roles for SD, MM, PP, FI, CO, QM, PM and HR modules to meet audit requirements.
  • Worked on Information Technology (IT) audits in various industries to evaluate and identify controls to protect assets, prevent fraud and maximize operational efficiency.
  • Worked on HPQC / ALM for testing.
  • Worked on tickets, errors and bugs in the issue tracking system forwarded by the end users to the SAP security support team.
  • Possess excellent Access and Excel skills and have a good knowledge of other Microsoft applications (Word, Excel, PowerPoint, Access, Outlook), Adobe Acrobat (PDF) and GroupWise, Novell.

TECHNICAL SKILLS

ERP: SAP R/3 versions (4.6C to ECC6.0), SAP (ECC, CRM, SRM, APO -SCM, EWM, GTS, HCM, PLM BW/BI, and PI), Solman 7.2, Enterprise Portal (EP), Confidential and SAP S/4 HANA.

Networking: LAN & WAN

Platforms: UNIX (Solaris8, IBM AIX, HP-UX), Windows NT/2000/03 Server

PROFESSIONAL EXPERIENCE

Confidential - Vernon Hills, IL

SAP Security Technical Lead

Responsibilities:

  • Worked on SAP Accelerated Access Security cleanup project.
  • Created Scope security design document and reviewed with functional process team.
  • Reviewed access globally to ensure it is aligned with current security position and governance.
  • Executed simulation to ensure SOD conflicts and Sensitive Access risks are mitigated appropriately.
  • Documented security design, reviewed with functional architects.
  • Executed role changes, user assignments and role mapping as per the confirmed design.
  • Extracted data of the current role/position assignments for both US and international users.
  • Reviewed and identified all Legacy Symphony roles by creation date.
  • Worked with the business team to perform extensive data analysis including the identification legacy role assignment, t-code usage report, cross functional impact of role changes.
  • Reviewed and identified all roles with critical transactions.
  • Reviewed and identified all foundation positions with no user assignment.
  • Removed all legacy Symphony access that was inherited from previous merged accounts.
  • Identified and deleted all unused/unassigned roles from backend, Fiori and Confidential NWBC.
  • Created new foundation roles/positions as per business requirement.
  • Worked on Confidential 10.1 and Fiori business role mapping.
  • Analyzed and replaced existing Legacy roles with new roles accurately matching business needs.
  • Worked with Business process owners to understand business processes to determine security requirements.
  • Removed unused/unassigned business Roles mapping from Fiori and Confidential .
  • Uploaded new business roles in Confidential and also completed Role mapping in Fiori.
  • Updated SDD (Security Design Documents) in Solman 7.2 with security requirements.
  • Created DCR (Data change request) for Business Confidential Roles and Fiori user/role mapping.
  • Updated US and OUS Catalog with new foundation roles/positions.
  • Created and updated TR (Temp Role) and TL (Transport List) folders in Solman for Release management team.
  • Used Confidential tool for User level simulation.
  • Prioritized work assignments each day to ensure all deadlines were met in a timely manner.
  • Managed deliverables within the specified SLA defined for the project deliverables.
  • Delivered and developed client services according to SAP SOX compliance/regulations.
  • Modified existing roles to isolate sensitive transactions.

Confidential, New Jersey, NJ

SAP Security Applications Management Senior Lead Analyst

Responsibilities:

  • Analyze, design and develop SAP Roles in ECC, CRM, SRM, SCM, EWM, GTS, HCM, BI, XI/PI, Solution Manager and Confidential .
  • Involved in Security design/support for FTM, EDM, CTC, UTR, STS, STP, DTS, ITR, ATR, EH & S & MTC/OTS process areas.
  • Worked with different business teams from North America, Europe and Asia to design global and local roles based on job responsibilities and implemented common security policies for all SAP landscapes.
  • Delivered and Developed Client services according to SOX Compliance Regulations.
  • Resolved most of the MR1/Wave2 Go-Live, hypercare & support IM tickets/defects promptly and efficiently.
  • Promptly responded and provided solutions to all technical queries/questions of the client.
  • Review and approves Software Requirements Specifications (SRS) and Solution Design Specification (SDS) in Solman (Solution Manager).
  • Created Charm (Change Request Management) and Transport requests via SAP Solution Manager.
  • Transported Security roles in SOLMAN using Charm (Change Request Management)
  • Created Solman Role ID’s.
  • Involved in SAP License management using USMM, LICENSE ATTRIBUTES and SLAW transactions.
  • Provided technical expertise to SAP Confidential implementation and re-engineer the security roles as required
  • Worked on all the four Confidential components CUP (Compliant User Provisioning), RAR (Risk Analysis & Remediation), SPM (Fire Fighter) and ERM (Enterprise Role Manager).
  • Worked with Business Process Managers in changing SAP roles and ensuring appropriate work flow in Confidential Compliant User Provisioning (CUP).
  • Used Confidential (RAR) tool for handling SOD conflicts. Assisted in resolving audit issues.
  • Reviewed critical and sensitive authorizations, implementing improvements to meet audit requirements, and advising solutions for security policies and best practices.
  • Redesign Security roles based on Segregation of Duties conflicts.
  • Develop, maintain and enforce security policies and procedures.
  • Principal contact for SAP Security internal and External SOX audits. Prepare responses and provide technical evidence to challenge audit findings.
  • Created new Cost Centers in Confidential (Business Objects - BOBJ).
  • Monitored the tickets queue in HP Service Center and delegated workload to Off-shore resources to resolve tickets efficiently.
  • Involved in Mentoring and Knowledge transfer to Off-shore Security team.
  • Extensively worked with Security Related tables such as AGR DEFINE, AGR 1251 and AGR 1252 using transaction SE16.
  • Serve as primary focal point for SAP Security for production support and defects request.
  • Worked extensively during the hyper-care period and have resolved CR/IM tickets based on priority status.
  • Analyzed and replaced existing roles with new roles accurately matching business needs.
  • Provided production support to end users, functional and technical users.
  • Point of Contact for External and Internal Auditors to provide all SAP Security related information, communicate current company policy and procedure documentation, and provide data from SAP Systems for audit analysis.
  • Created and managed Security roles for BI and worked in creating Reporting Authorization objects for BI.
  • Worked on Confidential 10/10.1 AC Components (ARA, EAM, ARM, BRM) Security Roles upgrade/Configuration.
  • Building the Roles using the transaction codes and implementing these Roles for the client organizational levels creating derived Roles and authorization profiles for the various plants located at different geographical locations in Development system.
  • Analyzed the impacts to security roles and authorization, created and modified roles for S/4 HANA to accommodate the changes to obsolete and new transactions and to authorizations.
  • Worked on SAP HANA studio / Fiori apps security. Created users and modified existing users, created Roles and modified existing roles. Assigned Roles for new and existing users.

Confidential, Chicago, IL

SAP Application Security Consultant

Responsibilities:

  • Participated in user reported problem solving, including writing report specifications, configuration changes, testing and system documentation.
  • Designed, developed, and maintained structural authorizations and standard roles for position-based HR security strategy.
  • Analyzed and replaced existing roles with new roles accurately matching business needs.
  • Utilized Confidential Compliance Calibrator in identifying Segregation of Duty (SOD) conflicts as defined by Internal and External controls.
  • Enabled regulated Super user access control via Confidential ’s Firefighter.
  • Extensively involved in creating roles in compliance with SOX regulations as determined by VIRSA/ Confidential .
  • Identified Security issues, recommended and implemented solutions to problems.
  • Modified roles to isolate sensitive transactions.
  • Utilized Virsa Firefighter to design critical roles for immediate access.
  • Maintained HR Master Data (PA30)
  • Created and changed position in Change Organization and Staffing (PPOME).
  • Setup user accounts in SAP xMII.
  • Created user accounts and assigned roles in Enterprise Portal.
  • Designed/built/tested new security roles and modified existing roles
  • Worked on Master& Derive roles, User Administration and User Authorizations.
  • Managing user master records, creating & deleting users, managing passwords, managing user groups.
  • Developed and maintained roles and performed user administration for ECC 6.0.
  • Resolved critical authorization issues using SU53 and ST01 (trace).
  • Access Control- Authorization Groups (SM30, TBRG table)
  • Restricted table access through authorization groups.
  • Worked on security tickets and satisfied the client by reducing the ticket volume to a manageable number in the Getronics Service Support System (S3) ticketing system.
  • Used SE10 for single and mass role transports and SCC1 for role import.
  • Performed extensive user administration using SU01 and SU10.
  • Effectively used VIRSA’s Compliance Calibrator to resolve and prevent SOX/SOD issues.
  • Extensively used the profile generator to design and modify roles in ECC.
  • Responsible for creating user IDs based on a standard naming convention, setting up of new users, modifying user accounts, resetting passwords, locking and unlocking user IDs.
  • Experience with Role based security design (role creation, transports and organization levels).
  • Trace and troubleshoot user authorization errors.
  • Develop derived roles for FI by converting certain fields to organizational level fields.
  • Maintained company approved audit standards for SAP Application security, resolved BW, SD, FICO security related issues.
  • Authorization objects and Analysis authorization.
  • Role Maintenance, User Administration, Authorization objects and Analysis authorization.
  • Managed mass transport with PFCG and SE10. Troubleshooted (SU53 and ST01)
  • Providing technical support to functional areas, configurations and developers.
  • Resolved daily support tickets for 12 plants.
  • Regularly interact with management, infrastructure and application support and outsource partners to increase the security awareness & posture at a corporate level.
  • Worked with Business process owners to understand business processes to determine security requirements.
  • Redesigned roles for SOX compliance.
  • Troubleshooting by tracing authorizations with transaction SU53, enabling system trace using ST01, enabling and disabling system wide checks for standard SAP transaction codes, RFC authorizations.
  • Single roles, profiles and authorization objects using profile generator are created for requirements related to company code.

Confidential, Kansas, KS

SAP Security Consultant

Responsibilities:

  • Developed and maintained roles and performed user administration for ECC 6.0.
  • Worked on authorization security using custom T codes.
  • Effectively used VIRSA’s Compliance Calibrator to resolve and prevent SOX/SOD issues.
  • Worked on SAP Check Indicator Defaults and Field values, reduced the scope of Authorization checks using transaction SU24 and maintained check indicators for transaction codes.
  • Traced (ST01) for authorization errors and failures and used SU53 reports.
  • Used Transport Management System to perform transports between clients within R/3 system.
  • Transporting Roles and derived Roles to Quality Assurance System (QAS) and initiating the testing process of the roles by assigning the intended Roles to test users and monitoring and troubleshooting the authorization failures during testing.
  • Resolve issues arising from testing using system traces and dumps.
  • Worked on Authorization objects, object fields, authorizations and authorization profiles.
  • Worked on Virsa Compliance Calibrator in dealing with SOD conflicts.

Confidential, Columbus, OH

SAP Security Consultant

Responsibilities:

  • Analyzed the ERP information security environment and developing security measures to safeguard information assets against accidental or unauthorized modification, destruction, or disclosure.
  • Responsible for the review of design, implementation, and on-going support of security profiles, roles and processes within a large, multi-product ERP implementation.
  • Worked on Authorization support of internal users on ECC and CRM.
  • Designed and developed Security solutions for CRM. Modified and assigned roles using (PFCG) for CRM.
  • Created technical security documentation for SAP ( Confidential ) Superuser Privilege Management (SPM, also known as Virsa or Firefighter) User procedure guide and developed documentation for ongoing audit purposes.
  • Helped internal Audit Department to achieve Sarbanes-Oxley Compliance to overcome SOD issued in SAP ERP System. Updated technical documents for audit purposes.
  • Restricted open authorizations to sensitive Transaction codes.
  • Involved in Sarbanes Oxley - SAP Security Audit.
  • Experienced in designing, testing, auditing, security roles and profiles, user account management (UAM), supporting and troubleshooting.
  • Updated Segregation of duties (SOD) matrix template.
  • Worked with business teams to analyze SOD issues on R/3 Enterprise environment by removing the conflicting TCODES / Authorizations.
  • Extensively worked on SAP R/3 Authorization model (SU01, ST01, PFCG, SU24 and SUIM).
  • Advisor to process owners for the development and implementation of security processes.
  • Monitors the ERP environment for Sarbanes-Oxley Act section 404 compliance (SOX), including but not limited to Segregation of Duties, Privileged Access and Critical Transactions Review and approve IT changes that may impact SOX compliance.
  • Worked closely with internal and external audit teams in providing information, assessing findings and remediating validated issues.
  • Coordinated and worked with the Security Administrators to ensure management of user accounts is accurate and effective.
  • Tested and implemented security recommendations given by SAP audit team.

We'd love your feedback!