Sap Sr. Security Lead Resume
Atlanta, GA
PROFESSIONAL SUMMARY:
- 14+ years of experience in SAP Security in 4.6x 4.7x, ECC, BW/BI/BPC/APO/EWM/SRM/SCM,HCM(Structural), SolMan, e - Recruiting, PY/TM/OM/PA/ECM/ESS/MSS/EP.6 (Portals), HANA/Fiori/Persona/GRC, BizRights/IDM/RevTrac, environments & moderate in SAP BASIS.
- Has worked on 10 + full life cycle implementation of SAP Security projects from design phase to post implementation phase in SAP Security Realm.
- Can independently provide solutions to complex SAP security architectures in terms of users & roles. Ad-hoc Troubleshooter for any SAP security issues.
- Handled 40 + internal projects as a lead with an offshore and onsite security model in both waterfall & agile methodologies.
- Remediated100K SOD violations single handedly as part of new entity acquisition.
- Implementation experience on SAP GRC 10.x & SAP S/4 HANA/Fiori/Ariba Security.
- Expertise in Designing and Implementation of HR (HRM) Structural Authorizations.
- Well defined Position/Job based security, Indirect assignment of Role and Structural
- Profiles with context based role design for HCM modules.
- Provided customized security solutions for critical / sensitive HR business scenarios
- Clear role designing approach in PY/TM/BEN/OM/PA/ECM/e-Recruiting & MDM/PTP/ATR etc.
- Experienced in Design/Creation of BI 7.0 Analysis Authorizations in various types of restriction for Sensitive Data.
- Expertise in Portal & ECC Security configuration of user & role mapping in J2EE environment.
- Extensively experienced on Mercury Quality Center 9.0 for HR/BI Security Role testing and experienced in creating Test Plan and Test Lab.
- Extensive experience on audit tools Virsa (VRAT/VFAT), GRC 5.3-10.x and Approva BizRights in context of SAP Security.
- Expert in re-design SAP Security strategy with respect to SOX compliance.
- Configured GRC 5.3 for HCM environment and defined custom functions & Rules in GRC
- Implementation experience in Central User Administration (CUA) in both single and multi-system landscapes.
- Configured SSO and LDAP (Active Directory) from both Security and Basis versions.
- Help business in different audits scenarios like SAP user license audit, Sarbanes-Oxley compliances and SOD Issues by review critical and sensitive authorizations & implement improvements to meet audit requirements.
- Performed Security upgrades to R/3 4.6B, R/3 4.6C, 4.7 EE, BW upgrade and carried out post-upgrade tasks as a member of the security team.
- Expertise in recording SCAT/SECATT/SAP-Gui scripts for mass changes for Users/Roles.
- Applied several OSS notes in order to correct profile generator, security transactions and security report bugs.
- Through understanding on SLA (Service Level Agreement) process & Service-Now tool
- Expertise on MS-Excel Spread sheet for daily reporting purpose and presenting in the status review meetings in desired manner and Experience in creating query reports using SQVI.
- Clear understanding on Role Re-design Methodology, MS-Access and Documentation.
- Proven excellence in oral/written/communication skills.
- Hands on experience in Service Desk tools like Remedy, Peregrine, Footprints, Mercury QC,HP-QC,Service-now, SAP Service desk configured in Solution Manager & RevTrac TMS tool.
PROFESSIONAL EXPERIENCE:
SAP Sr. Security Lead
Confidential, Atlanta, GA
Environment: ECC/SRM/CRM/HCM/FI/SD/MM/BI/BPC/EWM/HANA/Fiori/GRC/Portals/BizRights and HP-QC/IDM/Service-Now/Ariba/RevTrac
Responsibilities:
- Saved USD 1.5 ML in 2019 SAP user license classification of post CCEP merger.
- Implemented SAP Persona/Fiori/Ariba & SAP HANA security.
- Leading unique user ID consolidation project for about 25000 users.
- Extended GRC 10.x implementation & ongoing GRC 12 upgrade in post-merger entities.
- Single handedly remediated 100K SOD violations in Iberia(one of the acquired entity)
- Lead for role redesign project of task based roles for 11 EU countries with approximately 36 plants for FI/SD/MM/OTC/HCM/APO/EWM/LEO/PM/BI/HANA/Fiori etc. modules & managing Job based assignment through IDM environment in production.
- Defined Test cycles (SUT/FUT/Integration/UAT) of all re-designed roles.
- Mass role build for all EU countries and plants of an approximate count of 5000 roles.
- Preparing test environments for each test cycle with automated scripts.
- Fixing the defects in HP-QC/Service-Now & communicate to Business/Func.SMEs.
- Involved in preparation of Job role/task role mappings and generating complex excel spreadsheets & successfully handled cumbersome user deployments due to complex task based single role design.
- Solely defined & handled role re-design project to deal the complex task based single roles by converting into composite role model with custom approach of derived composite method which does not exists in SAP standard practices.
- Leading all Spring/Autumn/off release projects full life cycles
- Successfully migrated users from SRDB provisioning tool to IDM provisioning tool.
- Streamlined HCM Security configuration for an optimum performance.
- Involved in BPC 10.0 security implementation and handled support activities.
- Member of an approver’s panel for various SAP Security requests such as role modification/user role assignment/sensitive SOD violations.
- Solely handling Security tasks during the Cutover and swiftly coordinating with IDM provisioning teams in preparation of mapping task roles with job/Elevated role for user deployments. Experienced on process of RevTrac TMS tool
- Leading chaotic go-lives and hyper-care issues in timely manner in both EU on-site & USA and at the same leading/guiding the off-shore team.
- Prepared spectacular documentation and PPT on all deployment phases and conducted KT sessions with off-shore team.
SAP Sr. Security Lead
Confidential, Atlanta, GA
Environment: ECC.6.0/SRM/CRM/HCM/FI/SD/MM/BI-7.0/Portals/BizRights and HP-QC/IDM7.1
Responsibilities:
- Primary responsibility of leading SRM upgrade project from SRM5.0 to SRM7.0., to bring the SRM functionality from ITS to Enterprise Portal platform.
- Gathered all business functional requirements for security of restricting create/confirm/approve Shopping Cart, PO, Invoice, goods recipient etc., authorizations for Employee, Manager, Manager Advance, Strategic Purchaser, Commodity Manager and Goods Recipient roles.
- Re-designed/Build all SRM roles to enable the SRM 7.0 functionality.
- Developed all SRM portal roles due to short of portal resource.
- Created/Mapped UME groups with AD groups to setup an automatic portal role assignment mechanism.
- Prepared Test/ environments in both SRM GUI and Portal.
- Prepared SAP GUI scripts to manage mass activities for users/Roles for various project.
- Managed defects through HP Quality Center and transports handled through RevTrac
- Solely managed hyper-care/post go-live issues.
- Manually handled production user role deployment task due to IDM disconnected from SRM GUI during the go-live.
- Managing SRM org structure and user attributes is remains owned by Functional Team.
- Handled release project for BI Security of building roles for AR AP modules for Power User and end user with analysis authorizations.
- Partially lead another release project for role design/build for WM, MM, SD modules.
- Often worked on production support tickets that are specific to role development for HCM/R3/BI modules.
- Performed Knowledge Transfer on all leading projects and also prepared detailed documentation.
SAP HCM Security Lead
Confidential, Phoenix, AZ
Environment: ECC.6.0/OM-PA/ Payroll/ Benefits/ Time/ ESS/MSS/Comp & Perf/ FI / SD / MM/ GRC/HP-QC and BI-7.0/IDM7.1
Responsibilities:
- Designed security methodology on indirect role/Structural profile assignment at Job/Position based and Context Sensitive structural authorization environment without interrupting existing legacy SAP finance system security functionality.
- Designed Enterprise Portal (EP) Security strategy for Java Role & User administration and simplified portal role assignment task by role mapping mechanism.
- Defined a prototype on HCM Context Sensitive structural authorizations environment as a proof of concept during the blueprint stage.
- Projected detailed security tasks plan that includes duration of each task from design phase to go-live phase and defined naming convention for Roles/Struct. Profiles, Table Auth Groups, Program Auth Groups and Batch jobs etc.
- Conducted workshops with Business Analysts & System Analysts and identified all security roles for PY/BEN/Time/OM/PA/Workflow/ESS/MSS/Comp&Perf modules and Firefighter roles for Payroll and Non Payroll.
- Identified Sensitive infotype tables of Payroll and Time and moved to custom table auth groups and also secured Payroll cluster tables.
- Created custom program auth groups by each module and suggested to ABAP team to utilize them for AUTHORITY-CHECK statement in custom programs.
- Identified all structural profiles with various level of struct. access and co-ordinate with an ABAPer to build custom security Function Modules to use in structural profiles.
- Build all identified HCM role and Struct. Profiles based on the role matrix spreadsheet
- Implemented structural authorizations environment in entire SAP system landscape.
- Prepared Dev/Testing//Production environments using automated SECATT script based on the Job role mapping spread sheet without interrupting existing finance system role assignments.
- Fixed the identified defects which are processed through HP Quality Center 10 and followed the transport approval process.
- Scheduled Structural Authorization Indexing reports to improve the authorization check performance for users who sit on top level org units.
- Suggested custom security automations like MSS role assignment/user profile parameters and security authorization assignment report and co-ordinate with an ABAPer to achieve them.
- Scanned all existing non HCM roles for HCM authorizations and identified roles are submitted to non HCM security team to tweak them to exclude HCM authorizations.
- Configured an existing GRC 5.3 system to support SOX for HCM implementation and created custom Functions, Risks and Rules.
- Prepared detailed documentation on each and every configuration step with clear screen-shots and given knowledge transfer to Security Support Team for an on-going support.
SAP Security Lead
Confidential, Chicago, IL
Environment: ECC.6.0,PTP(PP,MM&SD)/ATR(FI)/OTC/MTS/MDM(MM)HTR(HR)DTB (APO),BI7.0, Solution Manager 4.0, EP 6.0, SRM 5.0, SCM 5.0, SAP Net Weaver 2004s(C-Folders), GRC 5.2.
Responsibilities:
- Handling team members by assigning day to day activities and helping them in critical and show stopper issues.
- Attending status meetings and updating/suggesting for security related issues.
- Primary Security Role design is implemented by Deloitte & Touché.
- Security design is being in re-design process due to the role count is too huge.
- Single handedly given new re-design approach to decrease role count around 80%.
- Designed/built all re-designed roles using various design methodologies and SECATT Scripts.
- Completely involved in SRM/SCM/ECC/MDM/MM/SD/PP/FI/C-Folders/BI role design related issues.
- Worked with GRC team in configuration of GRC Compliance Calibrator/Firefighter systems to review the SOD violation by single/Composite Role/user assigned roles and to track Firefighter activities.
- Configured CUA with more than 30 child systems in Solution Manager 4.0.
- Designed central security administration by connecting J2EE environment with Solution Manager 4.0 with LDAP to administer Portal role assignment from CUA.
- Solely handled HRM Security design of OM and PA module and implemented Analysis Authorization for reports in BI using RSECADMIN.
- Suggested Development team to restrict HR Sensitive Data in SD and MM screens in configuration level like tables T77* field settings and in SPRO screen design and keenly restricted RFC authorization for all systems which are point to HR Data Systems
- Secured HR Tables/Programs/files using S PROGRAM, S DEVELOP, S TABU DIS and S DATASET objects by custom table auth groups/Program Auth groups.
- Designed spectacular HR Data Protection Strategy Document about how the HR data is protected.
- Configured User Log-on Parameters and password parameters in system profiles.
- Scheduled security batch jobs for User comparison and composite role comparison in all child systems using PFUD (RHAUTUPD NEW) with required variants and schedule batch job in CUA central system for Role text comparison form all Child systems.
- Experienced in Service Desk tool Numara Footprints for all Incidence tracking.
- Designed built sophisticated Security Strategy from the scratch to meet SOX Audit expectation and suggest automation processes to eliminate human errors.
- Highly used SQVI to generate reports using various SAP Tables.
- Extensively created SECATT scripts for mass changes like User creation/modification, adding Single Roles to Composite Roles, removing role assignments from users, generating derived master roles etc.
- Prepared crystal clear documentation on process and KT to AC full time Security team.
SAP HR/BI Security Consultant
Confidential, Overland Park, Kansas
Environment: ECC.6.0, BI 7.0, EP.6.0, HCM/OM/PA/PM/ECM, e-Recruiting, Oracle 10.2.0, HP-UX/NT and Testing tool Mercury Quality Center 9.0.
Responsibilities:
- Working with Confidential is a challenging task, where the design of implementation is involved for HR Structural and BI analysis authorization with mixture of Position based, context based and custom relationship based security from business blue print through production support.
- Configured the HR Structural Authorizations by enabling switches using OOAC and OOPS Designed and created the Structural profiles using OOSP.
- Created custom functional module for structural profiles using custom relationship.
- Worked on HR modules for position-based security.
- Experienced on design context and non-context structural authorization.
- Involved in a dynamic approach of role and Security design for HR sub modules like OM, PA, PM, ECM and e-Recruiting.
- Customization is done for BI security to restrict HR sensitive data in BI system with combination imported R/3 HR Structure and user exit program.
- Created analysis authorization profiles based on Info-Object values, Info-Providers, and hierarchy level with structural authorizations.
- Created ESS and MSS roles and User administration for 12000 + users.
- Completely involved on different kind of test phases for SAP HR and BI Roles using Mercury Quality Center 9.0 and resolved the defects raised by testers.
- Extensively worked on creation of Test Plan and Test Lab and Defect Management.
- Experienced on mapping ECC and BI roles to Portal roles.
- Created portal roles for e-Recruiting, ECM, BI based on Confidential business requirement.
- Implemented CUA (Central User administration) in all SAP environments.
- Configured Single Sign On (SSO) and LDAP (Active Directory) functionality from both Security and Basis versions by enabling system profile parameters and configured LDAP connectors using RFC in ABAP system and configured UME in Enterprise Portal (EP).
- Setting of new authorization objects and values based on requirement for Custom T codes and Custom tables.
- Troubleshoot security/authorization related problems after go-live using trace tools.
- Worked on develop and document SAP Security policies and procedures, standards and guidelines.
- Created Role Design procedure document, Role build approach document and Security strategy documents
SAP Security Lead Consultant
Confidential, Seattle, WA
Environment: R/3,BW,APO,HR,CRM,FICO,SD,MM,Portals,Virsa, BizRights, Oracle 9.2.0, HP-UX/NT.
Responsibilities:
- Mainly engaged for CRM and HR module to Re-design the Technical Roles for BASIS/Security/ABAP teams and also involved in collection of base data to design structural authorization for HR Module as a part of first phase of this project.
- Designed a dynamic methodology to re-design the roles without interrupting the legacy environment till GO-LIVE of this project. Design includes configuration of SAP Security system to help both business/technical customer requirements.
- Extracted User and Role tables from SAP and designed a separate AS-IS database in MS-Access to get quick understanding on existing roles.
- As per the methodology scheduled regular meetings with SAP Technical Users/Administrators about the current issues with AS-IS roles and getting the future requirements for TO-BE roles.
- Due to the recourses issue in Production support team, also handled Production Support tasks as User creation/termination/modification, pulled the Daily/Weekly/Monthly reports for SOX audit purpose and reviewed Virsa violation using VRAT/VFAT tools on part time basis about 3 months without interrupting main tasks.
- In parallel there is also Approva BizRights 3.5 is under implementation. It’s an additional task to Maintain BizRights user administration is also included in part of Project
- Designed spectacular spoon feeding documentation on BizRights 3.5 for BizRight users/Administrators/Auditors.
- Cleanly documented each and every process throughout the project of SAP Security/Technical and Audit reports.
Sr. SAP Security Consultant
Confidential, Holtsville, NY
Environment: FI/CO, HR, MM, SD, PP, BW, APO, CRM, SM, GTS and EP, HP-UX/NT, Oracle 9.2.0.
Responsibilities:
- Communicating regularly with offshore team and updating them about the onsite issues and also communicating with business users for Authorization issues.
- Re-designed Symbol security strategy with extensive tighten Security plans according to Sarbanes Oxley Compliance (SOX).
- Installed/Configured Virsa Risk Assessment Tool (VRAT 3.0) in R/3, HR, BW, and APO
- Installed/Configured Virsa Firefighter Tool (VFAT 2.0) in R/3, HR, BW and APO
- Handled Security upgrade for BW 3.1 SEM to 3.5 SEM versions.
- Maintaining more than 35000 user accounts in 7 landscapes of R/3, BW, APO, HR, CRM, GTS and Portals.
- Created/Modified/re-designed role matrix for FI/HR/SD/BW/MM/BASIS roles.
- Actively participated in role cleanup process for R/3, HR, BW, APO, GTS and CRM.
- Task owner for security SOX compliance controls and solely responsible to provide the evidence to auditors for every end of the month and beginning of the following month.
- Provided required data for External/Internal auditors for audit purpose.
- Attending status review meetings periodically for Daily/Weekly/Monthly with Symbol IT Managers/Directors and with Patni offshore team and Project Managers.
- Generated daily/weekly/monthly report in audit prospective.
- Thoroughly designed the BIS/IT approval process to eliminate SOD violations.
- Responsible to work on old aged tickets which are incomplete by offshore team.
- Successfully completed client Sponsored HRM 940 Authorization course in Chicago.
- Worked on a mini project called Named ID to A ID conversion and cleanup double accounts, Converted 8000 Named accounts among them more than 4000 users got both Named IDs and A IDs with different roles, so compared all double accounts with their roles and assigned required role efficiently to A ID as per SOX SOD.
Sr. SAP Consultant (Security)
Confidential, woodland hills, CA
Environment: FI/CO, MM, QM, PP, BW, and CRM, SUN Enterprise 10000, SUN Solaris 8.0/ NT, Oracle.
Responsibilities:
- Responsible for management of user and authorization along with creation of new role using PFCG for both R/3 and BW users.
- Performed System Refreshing using R3COPY method. Setup the ALE and Central User Administration (CUA) in multi-system environment
- Converted manual profiles and implemented role based security. Evaluated and used SAP standard roles as templates for custom roles.
- Worked on assignment of Authorization Objects to Transactions using SU24.
- Create and modify Single roles, Composite roles and Derived roles.
- User master maintenance - creating users, deleting users and renaming users.
- Monitoring the powerful Authorizations, Performing routine checks for Security related issues and troubleshooting.
- Transported profiles between clients within R/3 system and between R/3 systems
- Used R/3 Profile Generator (PFCG) to create, generate and assign authorization profiles to roles.
- Worked with user information system to update and modify profiles and assign users to the updated activity groups (Roles). Redefined authorization scope using SU24 etc.
- Created new roles and edited the existing roles as per the requirements coming through Help Desk that entailed inclusion of transactions in the menu tree or editing the activities as per SU53 results.
- BW security - Involved with creation and maintenance of roles and custom authorization objects.
- Implemented Info object level BW security and created BW security Authorizations using RSSM transaction.
- Worked on installation of hot patches and upgrade of SPAM.
- Implemented BIW, CRM Security with security team
- Responsible for daily security checks, monitoring unsuccessful log-ons, monitoring inactive users and locking inactive users in production system.
- Performed Auditing using SM19, SM20, and SUIM etc. by running and analyzing traces.
- Worked closely with Audit team for SAP Security Audit and generated Audit Information Systems logs.
