Sr. Sap Security/grc Consultant Resume
2.00/5 (Submit Your Rating)
Houston, TexaS
SUMMARY
- SAP Security Administration with 7 years of experience in SAP R/3 security and GRC Implementation and administration.
- Participated in 4 full cycle implementations.
- Implemented preventative, mitigating and compensation controls to ensure the appropriate level of protection and adherence to the goals of the overall SAP security strategy
- Strong proficiency in the GRC (VIRSA) suite - Role Expert, Compliance Calibrator, Access Enforcer and Firefighter.
- Worked on VIRSA systems Sarbanes-Oxley (SOX) Compliance tools (Access Control Suite)
- Extensive expertise in the areas of ECC/R/3 Security, Portal Security, CRM Security, SRM/EBP security, BW/BI 7.0 security, APO Security, upgrade activities and compliance issues.
- Used compliance calibrator to indentify the business risks and worked with audit and business with the remediation process to meet the Sarbanes-Oxley section (SOX) 404 compliance.
- Worked with Audit in creating mitigation control and worked custom control review reports.
- Through knowledge of SAP Security authorizations. Expert in performing User administration using Central User Administration (CUA), role development using Profile Generator (PFCG) and in resolving all kinds of security issues.
- Experience working with transport management system
- Created FireFighter IDs for each business process areas and assigned necessary roles and profiles to carry out Fire Fighter Tasks
- Worked on Single Sign (SSO)
- Extensive Knowledge in SAP Portal, UME and LDAP.
- Worked on Central User Administration
- Developed security strategy as per SOX compliance
- Analyzed SOD conflicts and worked with developers in correction methods.
- Worked on authorization security using custom T codes
- Expertise in managing user groups and table security
- Used SAP Profile Generator to create, generate and assign authorization profiles
- Created and maintained users using SU01 and SU10
- Designed and Assigned Derived roles, Composite roles and Single Roles using Profile Generator (PFCG) for FI, SD, MM, PP, PM,APO,SCM,BI, CRM modules
- Expert in user administration, end user support, transporting roles and computer aided test tools (CATT)
- Performed integration and Implementation of SSO in Enterprise Portal with R/3 4.6C, 4.7 5.0 and ECC6.0 EHP6, CRM, BI7.0
- Maintain User administration and System administration for Portal systems (UME).
- Worked on BW security
- Provided day to day security support and administration for all security modules
- Excellent problem solving, analytical, technical and trouble shooting skills, team player with good communication skills
- Designed and tested SAP Identity Management tool which linked cross enterprise applications - ECC 6.0, HR Module, Active directory (IBM Blue pages) and Lotus notes.
- Design and implement SSO - Single sign-on along with GRC 10.0 to align with IDM Strategy
TECHNICAL SKILLS
- SAP ECC 7.0
- SAP R/3 4.7/4.6C/4.6A,B/5.0/6.0
- GRC 5.2/5.3/10.0
- SAP Enterprise Portal 7.0/6.0
- CRM
- SRM
- HCM
- BI 7.0, BW 3.5
- SAP IDM 7.0/7.1
- VENDAVO
- Portals
- PI, XI
- Approva BizRights
- Sabrix
- Cognos
- UAWEB
- UPSIDE
- BPC
PROFESSIONAL EXPERIENCE
Sr. SAP Security/GRC Consultant
Confidential, Houston, Texas
Responsibilities:
- Security design & support for ECC 4.6c, 4.7, 5.0,6.0, BI 7.0, CRM 5.0, & GRC 5.3
- Compared the Role based and ID based approaches for implementing GRC Firefighter and recommended the best approach to the client.
- Created Users & Groups in the portal system and Assigned the Portal based Groups to the users in DEV, QA, PROD.
- Performed GRC Pre-implementation checks and verified the status of RTAs, IGS server, Deamon job, J2EE server, SLD Status and JCO Connection.
- Demonstrated the capabilities of GRC Risk Terminator in preventing risks at the role creation stage.
- Reviewed and analyzed the deficiencies in the existing security processes and recommended process improvements.
- Streamlined the User Access Request process by clearly defining the appropriate access for each functional team.
- Designed and tested SAP Identity Management tool which linked cross enterprise applications - ECC 6.0, HR Module, Active directory (IBM Blue pages) and Lotus notes.
- Design and implement SSO - Single sign-on along with GRC 10.0 to align with IDM Strategy
- Configured LDAP on the CUA and enabled the dataflow by mapping the appropriate fields.
- Scheduled a daily background job for LDAP sync program to synchronize data between SAP and LDAP.
- Created and maintained number of ECATT scripts for the team, thus enhancing productivity.
- Created custom rules and incorporated them into the global rule set in Compliance Calibrator.
- Standardized the Firefighter login activity by the creation of custom reason codes.
- Mapped Roles to Positions in SRM Organizational structure.
- Setup Analysis Authorizations using transaction RSECADMIN in BI 7.0
- Created portal iViews, Worksets, Pages and Roles.
- Defined Authorization assignment & management strategy and Procedures
- Define User and Authorization Management Technical Strategy using CUA
- Define User Roles and role Management Procedures (Role Owners, etc)
- Did user analysis for all users and cleaned up users from SOD violation (24,000 users).
- Helped and suggested client for identifying custom Tcodes and programs which have SOD impact and how to remediate conflict for custom Tcodes
- Worked with Internal Audit in designing mitigating controls and assigned users.
- Setup SOD weekly batch job’s that for all parts of the business.
- Worked with Audit in providing SOD reports for SOX audit.
- Worked with BPO’s and Senior Management on mitigation/remediation of SOD conflicts.
- Assign Firefighter ID’s to owners and fire fighters.
- Design, write and implement security related standard procedures for the user administration, roles and profile generation
- Train User and Authorization Administrators (Ongoing user admin support)
- Established Naming convention and developed Support, Dev & Production roles
- Role Analysis & Object level security to build Production security roles
- Created a Functional Spec for Security Automation program for Business approval
- Identified & Built Functional controls in each business process with the help of audit team
- Quarterly pulled audit reports for systems via Approva Bizrights.
SAP Security/GRC Administrator
Confidential
Responsibilities:
- Extensively involved in creating roles in compliance with SOX regulations as determined by VIRSA/GRC.
- Troubleshoot workflow issues in GRC Access Enforcer and approver not found errors by creating Escape routes.
- Compared the transactions and authorization objects from old system and replaced them with the new ones for the upgrade assignment.
- Implemented GRC’s Role Expert and performed a security redesign based on the CC facilitated Internal Controls Framework.
- Enabled regulated Super user access control via GRC’s Firefighter.
- Utilized trace (ST01) results to identify the expected authorization values and incorporated them into the security roles after the upgrade.
- Performed a mapping of the portal roles with the backend system.
- Maintained security for BW power users and gave them authorizations for their new querries.
- Set up security roles and user accounts for three follow-on projects, including Business Warehouse (BW 7.0).
- Prepared numerous reports and coordinated with PWC auditors to make the company SOX compliant.
- Synchronized key data from SAP HR including default cost center, manager relationship, spend limit/signing authority, location etc in the EBP landscape.
- Relinked user master records to profiles as part of the ECC upgrade project.
- Followed the steps outlined in SU25 for the ECC 5.0 upgrade.
- Performed extensive role redesign for the IT and business users in the system.
- Worked on continuous process improvement with the team to reduce and streamline security processes.
- Maintained users in CRM landscape and applied the best practices in CRM security administration.
- Configured the profiles and gave appropriate authorizations for the SRM users.
- Performed activities like role/profile assignment, user administration using the Solution manager.
- Used Profile Generator (PFCG) for creation, modification of single roles, composite roles, global roles, derived roles in R/3.
- Involved in portal setup and connected the different systems using RFC.
- Interfaced with the External SOX Auditor and involved in the SOX Audit documentation and process improvement.
- Transported the generated roles and profiles using SAP transport management system.
- Configured AIS and assigned the Audit Roles to the Internal/External Auditors.
- Organization level restrictions were maintained at sales organization, sales office and sales group.
SAP R/3 Security Administrator
Confidential
Responsibilities:
- Set up security roles and user accounts for over 1200 End Users.
- Effectively utilized the alert monitor of GRC’s Compliance Calibrator to provide an alert to any potential violation.
- Shared my security expertise for the design of business processes in the new release in the blueprint phase of the upgrade project.
- Prepared a revised security policy for the new release in the upgrade project.
- Reviewed the audit trail of user access requests and approvals through GRC’s Access Enforcer.
- Coordinated the user account creation and termination policy with Human Resources (HR) and Operations.
- Created and maintained SAP Authorizations, User Master Records, Table authorizations, Authority checks, Activity group creation, and profiles.
- Created custom BW Info Objects and Authorization objects on all clients.
- Designed several utilities to support SAP R/3 security reporting needs (Reports of user usage, profiles and authorizations, comparison report in different R/3 system, Lock/Unlock user in client etc).
- Effectively analyzed trace files and tracked missed authorizations for user’s access problems and inserted missing authorizations manually.
- Created Custom transaction codes for the programs and worked with developers to enforce the authority check.
- Reviewed and revised Security policies with the client and documented the same.
- Applied OSS notes in order to correct profile generator, security transactions and security report bugs.
- Provided knowledge transfer for SAP R/3 security environment, explaining the concepts of authorization objects, profiles, authorizations, fields and field values, user master records as well as profile generator to the client.
