Sap Security Consultant Resume
2.00/5 (Submit Your Rating)
SUMMARY
- 9 years of experience in the Information Technology industry as an SAP Security Consultant
- 9 Years of Production support and Client Specific Application implementation Experience and SAP Application Security support work.
- Experience in maintenance of Security Administration, Segregation of Duties (SOD) within SAP implementation
- Worked as security admin in all functional areas (MM, FI, SD, WM, MFG, PP, PM, PS) and other areas like SRM, SUS, MDM, Reporting, E - Sourcing, XI, BI and EP.
- Experience in implementing security for various SAP modules such as FI, CO, MM, SD, etc. in various versions of R/3 including 4.6C, Enterprise R/3 4.7 and NW2004s products such as ECC 6.0, BI 7.0, EP 7.0 SRM5.0, GRC etc.
- Interacted with business/process team for data and information gathering. Strategizing and implementation of SAP Security model, processes and procedures by following SAP best practices for SAP security
- Experience in analyzing and processing of SOD and SOX issues, Audit projects and in reviewing critical and sensitive authorizations, implement improvements to meet audit requirements
- Experience in using GRC 5.3 & 10.0 Suite
- Experience in working with Automatic Profile Generator, creating and modifying Single, Composite and Derived roles. Transporting roles using Change Requests, Download/Upload
- Extensively performed User Master Reconciliation and Mass Generation of profiles, SUIM reports for reporting, audit and troubleshooting purpose
- Strong Experience with helpdesk, resolving ticket issues and troubleshooting support problems, Documentation and knowledge transfer and an active team player
- Preventative, mitigating and compensation controls to ensure the appropriate level of protection and adherence to the goals of the overall SAP security strategy
- Respond to requests and prepare SAP security reports based on management and department needs
- Troubleshooting System, User and authorization problems, Batch/Background Jobs Management, CATT Scripts
- Documented processes, improved user change management procedures, monitored segregation of duties, and supported any SOX standards.
- Solved SAP Security issues by following established protocols and continuously improved safeguards.
- Prepared user security assignment files daily, for processing by the Security Administration team and monitored quality levels.
- Worked in various ongoing projects at the client location.
- Excellent team player with good analytical communication skills and self-initiation.
- Working knowledge of CRM 4.0, and HR security
- Functional Knowledge in the areas like FI, MM, SD, PM & PS
TECHNICAL SKILLS
ERP: SAP R/3 Version 4.6 C,4.7, ECC 5.0, 6.0
DataWarehouse: BI 7.0
Operating Systems: Windows & UNIX
Security Utilities: VIRSA & GRC 5.3 & 10.0
PROFESSIONAL EXPERIENCE
Confidential
SAP Security ConsultantResponsibilities:
- SAP Security IHC (In-House Consultant) for a landscape
- On-site coordinator for the Confidential offshore security team
- Key decision maker for security & authorizations for a cluster (landscape)
- Evaluating and analyzing all the security maintenance tickets prior to the execution
- Day to day interaction with the business to gather the requirements for the role maintenance
- Interacting with the users to solve their issues
- Process improvements in security and authorizations area
- Work with Audit team to resolve SOX/SOD related issues and will provide the proofs to the (Internal & External) auditors.
- Worked as a security admin for the Implementation project PEP-Procurement Excellence Project XI, BI, MDM, SRM, SUS, Reporting, EP & E-Sourcing.
- Creating users and roles in MDM repositories (Service, Material and Vendor)
- Worked on Sunset project - migrate Mexican cluster to the North America Cluster.
- Worked on Viking IT Mtg project - Client sold out a plant and migrating the related data to the new company.
- Worked on role re-organization process for the GRC implementation project (RAR, CUP, and SPM).
- Worked on GRC 5.3 Implementation project
- Regular GRC activities - RAR - Rule Set Maintenance, Generating rules, transports, monitoring backgrounds, analyze and fix the issues.
- User maintenance in MDM - Repositories (Vendor, Material and Service) and assign he corresponding role sin portal along with the user mapping.
- E-sourcing team will create the users and will assign the corresponding roles in portal for allowing the user to access the system from portal
- User maintenance for the reporting tool and will assign the corresponding roles in portal which allows the user to access the reporting tool from the portal system.
- Create and maintain the roles in MDM system.
- Based on business requirement will provide the required data to the users from MDM and Reporting tool
Confidential
IHC (In-House Consultant)
Responsibilities:
- Security IHC (In-House Consultant) for a landscape and On-site coordinator
- Key decision maker for security & authorizations for a cluster (landscape)
- Evaluating and analyzing all the security maintenance tickets prior to the execution
- Day to day interaction with the business to gather the requirements for the role maintenance
- Interacting with the users to solve their issues
- Process improvements in security and authorizations area
- Work with Audit team to resolve SOX/SOD related issues and will provide the proofs to the (Internal & External) auditors.
- Working as a security admin for the Implementation project
- Created users and roles in MDM repositories (Service, Material and Vendor)
- Working on role re-organization process for the GRC implementation project (RAR, CUP, and SPM).
- CUA Maintenance.
Confidential
Project Lead
Responsibilities:
- Defining menus and default parameters to users
- Performed transports and mass transports of roles
- APO Security
- Handling Enhancement Tickets & Projects
- Following the Security Procedures
- CUA - Central User Administration
- Day to day technical support and resolution of security issues, Analysing Problems and Resolving the Issues (Tickets). Involves Troubleshooting.
- Documenting all Security deliverables.
- Working for the current business process functional specifications and identified the relevant areas for customizations for the customer.
- Handled SOD conflicts for all production system using SUMAT tool.
- Analysis and documentation of the User Roles for R/3, BW systems.
- Analysing and modifying Roles based on request.
- Managing all SAP Security related Change Requests for entire SAP production server throughout the widely spread landscape.
- Build each role as per the documents through the standard Profile Generator tool and other associated SAP transactions
- Documented all the changes related to roles in LNCC.
- Testing transactions assigned to the role and reporting the complexity of those transactions.
- BW Security - 3.1 & 3.5 Version, Implementation of BIW roles as per the end user requirement.
- Designed and periodically reviewed SAP critical transactions, tables and reports in compliance with SOX guidelines.
- Interacted with business managers to identify roles and their level of authorization in accordance with their job functions.
- Assignment of role requirements based on job functions and audit control processes.
- Implement and establish standards for custom authorization objects.
- Hands-on security upgrades using SU25 and Profile Generator (PFCG).
- Cleaned up and optimized security Roles.
- Review critical and sensitive authorizations, implement improvements to meet audit requirements.
- Create and modify Single roles, Composite roles and Derived roles by using Profile Generator PFCG.
- Work with Business specialists to help them understand what SAP authorization objects are causing the conflicts and what all options exist for mitigating the conflicts
- Worked with functional team leads to define the new transactions and checking the suitable role to be fit without SoD Conflicts.
- Secured roles by Company Code, Plant, Cost Center, Profit Center, and Purchasing Organization. Work with Audit team to resolve SOX/SOD related issues.
- Continuously improved security configuration to reflect best practices and to prepare for system audits.
- Taking Periodic logs for the given Emergence id’s like (ZORANGE, ZRED & SAPOSS).
- Performed trouble shooting on R/3 security problems by using system traces
- Confidential has 6 system landscape each in R/3, BW (3.1 and 3.5 versions), APO & solution manager. With total number of users across all the systems running to 50,000 and 4 to 5 new projects running any time of the year-authorization requests to the tune of 500 per month are handled
- Performed Enterprise portal Security and administration.
- Helped in Implementing Structural Authorizations,
- Maintained authorization profiles using OOSP and users using OOSB.
- Worked on Authorization all HR Objects PLOG, P ORGIN, P ABAP etc.
- Worked Extensively on HR tables T77*
Confidential
SAP Security Consultant
Responsibilities:
- User Maintenance and generating profiles based on user requirement
- Security Audit System
- SOD (SEGGREGATION OF DUTIES).
- Defining menus and default parameters to users
- Transporting released objects
- Defining and Scheduling background jobs
- Quite Time Activity
- Handling Enhancement Tickets
- Used Virsa Compliance Calibrator (Simulation mode and Detail mode), Firefighter to identify SOD’s and resolve any issues.
- Used Virsa Role Expert to ensure consistency of Role definitions, testing and maintenance across the entire implementation
- Automated the access provisioning approval process by combining roles and permissions with workflow using Virsa Access Enforcer
- User maintenance (User creation/deletion/lockdown/activation /Password management)
- Provided knowledge transfer for SAP R/3 security environment
- Knowledge in VENDAVO
- Vertex Updates
Confidential
Team Member (Jr. Basis Administrator)
Responsibilities:
- Involved in creating and maintaining role/profile, changes to existing roles by adding new authorization objects and values, and deletion of roles using Profile Generator PFCG
- User Maintenance and generating profiles based on user requirement
- Security Audit System
- Defining menus and default parameters to users
- Configuring and maintaining logon groups for logon load balancing
- Performed transports and mass transports of roles
- Creating customizing clients and performing client copies
- Security Administration
- Defining and Scheduling background jobs
- Performance Monitoring
