We provide IT Staff Augmentation Services!

Sap Security/grc Consultant Resume

5.00/5 (Submit Your Rating)

Houston, TX

PROFESSIONAL SUMMARY:

  • SAP Certified Application Associate - SAP ACCESS CONTROL 10.0
  • SAP security/GRC specialist over 8 years of experience in SAP Security for ECC 6.0/5.0, R/3 4.7, HR/HCM/ BI 7.0/BW3.5,BOBJ 4.0 and SRM with Net weaver Portal and SAP GRC Access Control version 10.0, 5.3 and have worked on multiple full life cycle implementations, SAP Security Upgrades and SAP Security Support projects.
  • Performed end to end implementations in GRC 10 including all modules i.e. Access Risk analysis, Access request management, Emergency access management, and Business role management.
  • Experience with 3 full lifecycle implementations including Super user Privilege Management, Single Sign-On (SSO), Compliant User Provisioning, Business role management, Central User Administration (CUA) and Custom authorization checks.
  • Discussed the business process control design and assisted in implementation strategy for GRC Access Control and Process Control. Created blueprint document for three GRC AC components - ARA, EAM and ARM for covering the design decision discussed during initial workshop.
  • Prepared SoD rule-set by activating the required BC sets and downloading the table extracts for discussion with client controls and functional team.
  • Created the GRC process flowchart and detailed documentation steps for discussing the MSMP workflow with the client.
  • Extensive Experience with Profile Generator (PFCG): designed, developed, tested and implemented SAP Security Roles, Profiles and Authorizations
  • Worked with Audit team in resolving Segregation of Duty (SOD) violation for Sarbanes-Oxley (SOX) Compliance of SAP ERP Users.
  • Extensive knowledge in SAP ERP Security troubleshooting (SU53, ST01, SUIM, and ST22)
  • Experienced in Coordination with Audit team for SAP Security Audit and generated Audit Information Systems as per Audit team requirement
  • Created Firefighter IDs for each business process areas and assigned necessary roles and profiles to carry out Fire Fighter Tasks
  • Analyzed SOD conflicts and worked with developers in correction methods
  • Worked on authorization security using custom T codes, producing ad hoc reports for Role Owners/ Audit.
  • Designed and Assigned Derived roles, Composite roles and Single Roles using Profile Generator (PFCG) for FI, SD, MM, PP, PM,APO,SCM,BI, CRM modules.
  • Expert in user administration, end user support, transporting roles and computer aided test tools (CATT).
  • Performed integration and Implementation of SSO in Enterprise Portal with R/3 4.6C, 4.7 5.0 and ECC6.0 EHP6, CRM, BI7.0
  • Designing/Implementing/upgrading/managing VIRSA, SAP GRC Access Control 10.0 and 10.1 Access Risk Analysis (ARA), Emergency Access Management (EAM), Access Request Management (ARM) and Business Role Management (BRM).
  • Expertise in creating custom initiator rule, custom agent rule and custom routing rule using BRF+ for MSMP workflow configuration.
  • Proficient in building Analysis Authorizations in BI/BW systems and Experienced in Structural Authorizations and Position Based Security in HR systems.
  • Worked on Unit testing, Integration testing and User acceptance testing of security roles.
  • Extensive experience in resolving tickets and troubleshooting security authorization problems while adhering to SLA.
  • Comprehensive experience at maintaining, formulating Security Policies and Procedures, User maintenance (SU01, SU10), Role maintenance using Profile Generator (PFCG), Security Tcodes and Security redesign strategy.
  • Troubleshoot user roles, tracing the users, security authorization objects and custom reporting authorization objects to debug/troubleshoot an authorization error, resolving the issue by giving required authorizations (SUIM, SU53, ST01 and ST22) in different modules.
  • Expertise with the BI Analysis Authorization (RSECADMIN) to maintain security for reporting users and troubleshooting the reporting problems.
  • Strong experience in implementing and working with security with SAP HR module including Structural Authorizations, ESS & MSS and Position Based Security and Context Sensitive authorizations.
  • Experience with Portal Security, User Management, Development of Portal Roles, Single-Sign-On (SSO), Identity Management (IDM) and Security Weaver.
  • Extensive Knowledge in HANA and Fiori Security.

TECHNICAL SKILLS:

SAP SKILLS: GRC 10.1/10.0/5.3, ECC 6.0/5.0, SAP R/3 Enterprise 4.7/4.6C/4.6B/3.1i, BI 3.5/7.0

Modules: FI, CO, HR/HCM, MM, SD, BW/BI,SRM, CRM

Security Audit Tools: SAP GRC (SAP Access Control 5.2, 5.3), VRAT, VFAT, and GRC10

Databases: Oracle, MS Access, SQL Server, Oracle 9i/8i

Operating Systems: Windows XP/2000/98/NT, UNIX, MS-DOS.

Application Software: Microsoft PowerPoint, Microsoft Access, Microsoft Excel, Microsoft Visio.

Other: LSMW, CATT.

Testing Tools: Quality Center.

AL QUALIFICATION: Bachelor s Degree

PROFESSIONAL EXPERIENCE:

Confidential, Houston, TX

SAP Security/GRC Consultant

Responsibilities:

  • Performed an End to End implementation of GRC Access control and involved in upgrade from GRC 5.3 to 10.0.
  • Post installation activities like creating connectors, connector groups, work flow customizing, business process and sub process creation, creating root organization hierarchy and activated Business Configuration sets.
  • Configured Access risk analysis, mapping of connectors to integration scenarios, setting configuration parameters like default report type for risk analysis, default rule set for risk analysis and etc.
  • Defined the frequency of synchronization jobs based on customer requirement and resolved issues.
  • Created functions, modified existing functions to include custom transactions, and generated rules.
  • Created/ modified risks to include the custom functions.
  • Development of mitigating controls, created workflow for mitigation assignment approval.
  • Configured Emergency access management and created Firefighter monitors and approvers.
  • Configured Access request management and implemented Access request workflow, mitigation assignment approval, role maintenance approval workflows.
  • Created a BRF+ workflow for Initiator to route the requests depending on the client requirement.
  • Configured Business role management, defined role naming conventions, role criticality and sensitivity levels.
  • Used Role mass import option to import roles from back end servers by using role attribute template.
  • Followed standard role methodology and used Role approval workflow for seeking approvals before generating the roles.
  • Resolving both End users and power user’s authorization problems.
  • Worked in all risk control processes including IT general controls, testing plans, testing execution in an integration testing environment and control remediation.
  • Designed Firefighter roles, business roles, Background roles and error handling roles (support services) for business area FI/CO, HR, PS, PM, MM, BI/BW and SRM. Maintaining, Creating, Modifying existing roles (Single, Composite and Derived) for project team.
  • Worked with Internal Control team for Role level Remediation and User level Remediation.
  • Extensive experience in designing and implementing mitigating controls.
  • Support Basis team for user master export and import, lock mass user during systems maintenance.
  • Expertise in SAP Security and Authorizations which includes User Management, User Administration, Monitoring, User Tracing (ST01).
  • Implemented access control on security related tables (AGR, USR and Custom Tables) and sensitive authorization objects (S TABU DIS, S PROGRAM, etc.).
  • Used transaction RSECADMIN for creating custom authorization objects and S RS AUTH for assigning authorization objects for BI query end user roles.
  • Set up security by Info Area, Info-Cube, Info-Object, QUERY and WORKBOOKS
  • Exclusively worked on BI Objects by restricting the access for Reporting and Power Users.
  • Created analysis authorizations to provide security on Hierarchies and Info Objects, made the info objects authorization relevant.
  • Implemented BI Security with management of Analysis Authorizations at Characteristics, Key Figure and Hierarchy Node Level using Transaction RSECADMIN.
  • Worked on BEx analyzer using transaction RRMX and restricting the users to see the queries using S RS COMP and S RS COMP1.
  • Created different single and composite roles for SRM Shopping cart application as required by the business.
  • Worked with portal team and mapped the SRM backend roles with the Portal roles for the users to login in to SRM application through Portal.
  • Created Power user role Requistioner role, Supply chain user role Buyer role, DOA Approver role Approver role and other roles as per the business requirements.
  • Set up structural authorizations for HR module which involved activating, creating and assigning structural authorization.
  • Extensively worked with the P PERNR, P ORGIN, P ORGXX, P ORGINCON and P ORGXXCON objects in designing the HCM Roles.
  • Implemented HR security and provided production support on HR security and structural authorizations (MSS)
  • Created Test IDs and attach appropriate Business Role, support Testing team and also performed Unit Testing, Integration testing on created roles using Test Director Tool.
  • Extensively involved in Re-designing the SAP Security for ECC system. Designed the Job based security for the users.
  • Designed, Developed, Testing and Implementation of Enterprise Portal User IDs, Roles.
  • Worked on user administration in SAP portal security, creating users, roles and user groups in to give users access to iView objects Designed, Developed and Tested ESS/MSS roles in conjunction with Enterprise Portal.
  • Creating iViews, Worksets and Roles in SAP Portal 7.0 for SRM Users
  • Mapped the SRM backed roles with the Portal roles for the users to login in to SRM application through Portal.

Confidential, Frisco, TX

SAP GRC/Security Consultant

Responsibilities:

  • Involved in Blueprint and Redesign existing security roles to maintain SOX Compliance.
  • Worked with business to redesign the roles without any SOD risks in roles and defined roles based on different business functions in compliance with SOX.
  • Implemented Risk Analysis and Remediation (RAR 5.2), Super user Privilege Management (Firefighter 5.2)
  • Created FF-IDs for functional people and regularly monitored FF log reports.
  • Used CC (Compliance Calibrator) and RE (Role Expert) to do the role analysis to find out the Conflicts in the roles. Redesign GRC Rule-set, Identified new risks, functions and removed false positives in GRC rule set.
  • Worked with business to build custom GRC rule sets for SAP Insurance Landscape (not provided by SAP standard rule sets).
  • Based on our company’s SOD Risk Matrix, all the roles have been done SOD checks at both role level and user level using GRC RAR and also implemented mitigation controls.
  • Designed, documented and implemented the GRC Stay Clean procedures such as Rule set change, User and Role Creation and Change process and other SAP Security Processes.
  • Schedule background jobs in GRC RAR for time to time data synchronizations, Rule generations
  • Actively involved in designing RAR Rule Architect, mitigating controls
  • Maintaining CUP workflow and assigning Firefighter ids in SAP
  • Created Mitigation Controls and assigned it to users according to the company procedures. Worked on risk analysis for the transaction codes in GRC 5.3 using RAR and looking for any SOD conflicts
  • Performed mitigation at the user level by applying mitigation control id. Analysis of the roles in Compliance Calibrator by simulation for remediation
  • Updated the rules by creating new risk id for conflicting functions and transported through the landscape of GRC RAR
  • Provide daily SAP R/3, CRM, BW, SCM, EBP and HR security production support such as ID requests, access requirements and troubleshooting problems. Defined and maintained authorizations and roles
  • Performed daily support activities and troubleshooting using SUIM, SU53,ST01, PFCG SU01,SU10,SU24,SU20, SU21, SM59, SM12, SM13, SM30, SM36, SM37, SU56, AL08, SM01, SE16N, STMS, SE09,SM18,SM19,SM20
  • Extensively worked with critical Authorization Objects like S DEVELOP, S PROGRAM, S TABU DIS, S TABU CLI, S TABU NAM, S USER GRP, S USER PRO, S USER AUT, S USER VAL, S USER AGR

Confidential

SAP Security Consultant

Responsibilities:

  • Implemented SAP HR Structural Authorization for the HR team for Organizational management
  • Implementation included role modification to adjust context authorization
  • Created structural profiles T77PR and assigned to users in T77UA table.
  • Extensively worked on the important HR security t codes like OOSP, OOSB, PPO1, PA20, and PA30.
  • Configured BOBJ 4.0 single sign on with Win AD to allow access control through AD groups.
  • Configured authentication for BOBJ 4.0 system and configured controlled access to queries using CMC (Central Management Console) to limit users for accessing Folders through AD groups and creating queries.
  • Set up structural authorizations for HR module which involved activating, creating and assigning structural authorization.
  • Extensively worked with the P PERNR, P ORGIN, P ORGINCON and P ORGXXCON objects in designing the HCM Roles.
  • Implemented HR security and provided production support on HR security and structural authorizations (MSS)
  • Created Test IDs and attach appropriate Business Role, support Testing team and also performed Unit Testing, Integration testing on created roles using Test Director Tool.
  • Extensively involved in Re-designing the SAP Security for ECC system. Designed the Job based security for the users.
  • Worked on BOBJ Explorer using transaction RSDDTPS and restricting the users to see the queries using info objects.
  • User and Role administration through Central Management Console.

Confidential, Austin, TX

SAP Security Consultant

Responsibilities:

  • Designed technical roles for sand box, development and quality systems.
  • Involved in gathering the requirements for designing production roles from blue print documents
  • Worked with STMS in transporting roles between sand box, development and quality systems.
  • Configured Central user administration for non production systems
  • SAP Marketplace activities like creating OSS ID, Developer access key, Registering Object, OSS messages for opening and closing SAP systems
  • Created Single roles, Composite roles, Master roles and Derived roles.
  • Worked on role modification as per the business need
  • Involved in system trace ST01 to troubleshoot user’s authorization issues
  • Used SAP marketplace for SAP notes in order to troubleshoot the problems arising out of daily system administration activities.
  • Maintained RFC connections between different SAP systems using SM59.
  • Involved in preparing end user documents
  • Extensively worked with all security related authorization objects and authorization objects related to ABAP, SD MM, HR and FI/CO
  • Closely worked with the internal auditors while doing the system audit and implemented the recommendations advised.
  • Performed quarterly security self assessment audit and coordinated with auditors for resolution of audit issues.
  • Defined and documented security standards, operational and administrative processes.
  • Performed GRC post installation activities like Activating AC application, SICF services, BC sets and configuration parameters.
  • Created connectors, maintained connector type, assigned connector to connector group.
  • Added connector to AUTH, PROV, ROLEMG and SUPMG scenarios.
  • Performed Authorization and Repository synchronization.
  • Generated rule set, downloaded rule set, customized the rule set as per business need and uploaded for risk analysis.
  • Imported PFCG roles from business systems to GRC system using role import
  • Created access control owners like Role owner, Risk owner, Function approver, Firefighter owner, Firefighter controller and Security lead.
  • Extensively worked with Function approval, Risk approval, Mitigation control assignment and maintenance workflows.
  • Mitigated the risks by assigning mitigation controls to risks.
  • Assigned owners and controllers to Firefighter ID.
  • Created custom initiator rule using BRF+ and used in MSMP Access request workflow to auto-provision Firefighter IDs to Firefighter users.
  • Activated Firefighter log report review work flow for Firefighter controllers to request log report.
  • Performed Automatic work flow customizing, Tasks specific customizing, Activated event linkage and Defined number ranges for access requests.
  • Configured number ranges, maintained provisioning settings and customized End user personalization (EUP) form.

Confidential . Holland, MI

SAP Security Consultant

Responsibilities:

  • Performed user administration activities such as create, delete, lock & unlock, deactivate, reset passwords, and maintain logon data and assigning roles to the users as per the business requirement.
  • Created new roles and changed existing roles as per request after proper approval from business.
  • Configured and maintained central user administration for easy user administration.
  • Assigned roles for existing users based on request and approval.
  • Single and mass roles transportation from one system to another system.
  • Analyzed user’s authorization issues using SU53 & ST01 and solved by assigning appropriate authorizations
  • Authorization groups creation and maintain authorization groups in the roles.
  • Extensively worked on production tickets and requests, second and third level support, fixing end user Roles/Profiles based on change requests created for breaks/fixes.
  • Performed daily support activities and troubleshooting using SUIM, SU53, ST01, PFCG, SU01, SU10, SU24, SU20, SU21 SCUA, SCUG, SM59, SM12, SM13, SM30, SM36, SM37, SU56, AL08, SM01, SE16N, STMS, SE09.
  • Extensively worked with critical Authorization Objects like S DEVELOP, S PROGRAM, S TABU DIS, S TABU CLI, S TABU NAM, S USER GRP, S USER PRO, S USER AUT, S USER VAL, S USER AGR.
  • Created authorization group for table’s security using SE54.
  • Extensively used tables like USOBT C, USOBT X, AGR USERS, AGR TCODES, AGR DEFINE, AGR 1251, AGR 1252, USR* and USH*.
  • Extensively worked with all security related Authorization objects and Authorization objects related to SD, MM, PP, HR, FI/CO, ABAP.
  • Worked with eCATT and LSMW scripts for mass user maintenance.
  • Monitored application server’s status, work processes and their status from time to time.
  • Monitored update status whether it is active or deactivated and check failed updates.
  • Analyzed system logs and ABAP dump and followed its recommendation.
  • Released long time locked objectives by user approval and monitoring r/3 locks.
  • Defined and monitored back ground jobs, view logs for cancelled jobs and analyzing them.
  • Creating BW roles and restricting them in Queries, Infocube, Infoarea levels.
  • Worked with different objects related to BW/SEM administrator workbench (S RS ADMWB, S RS IOBJ, and S RS ISOUR).
  • Secured Info Area, Info Cube, Info Object, ODS, PSA, Query and Work Books by maintaining hierarchy authorizations.
  • Secured Reporting users by configuring roles and authorization objects.
  • Activated the new info objects 0TCA* and 0TCT* and made them authorization relevant.
  • Added 0TCAIFAREA as external hierarchy characteristics to 0INFOPROV.
  • Identified all the org level info objects and confirmed they are Authorization relevant.
  • Used VIRSA tool to detect conflicts on Segregation of Duties as part of the SOX compliance

We'd love your feedback!