We provide IT Staff Augmentation Services!

Sr. Sap Security/grc Consultant Resume

2.00/5 (Submit Your Rating)

Houston, TexaS

SUMMARY

  • SAP Security Administration with 7 years of experience in SAP R/3 security and GRC Implementation and administration.
  • Participated in 4 full cycle implementations.
  • Implemented preventative, mitigating and compensation controls to ensure the appropriate level of protection and adherence to the goals of the overall SAP security strategy
  • Strong proficiency in the GRC (VIRSA) suite - Role Expert, Compliance Calibrator, Access Enforcer and Firefighter.
  • Worked on VIRSA systems Sarbanes-Oxley (SOX) Compliance tools (Access Control Suite)
  • Extensive expertise in the areas of ECC/R/3 Security, Portal Security, CRM Security, SRM/EBP security, BW/BI 7.0 security, APO Security, upgrade activities and compliance issues.
  • Used compliance calibrator to indentify the business risks and worked with audit and business with the remediation process to meet the Sarbanes-Oxley section (SOX) 404 compliance.
  • Worked with Audit in creating mitigation control and worked custom control review reports.
  • Through knowledge of SAP Security authorizations. Expert in performing User administration using Central User Administration (CUA), role development using Profile Generator (PFCG) and in resolving all kinds of security issues.
  • Experience working with transport management system
  • Created FireFighter IDs for each business process areas and assigned necessary roles and profiles to carry out Fire Fighter Tasks
  • Worked on Single Sign (SSO)
  • Extensive Knowledge in SAP Portal, UME and LDAP.
  • Worked on Central User Administration
  • Developed security strategy as per SOX compliance
  • Analyzed SOD conflicts and worked with developers in correction methods.
  • Worked on authorization security using custom T codes
  • Expertise in managing user groups and table security
  • Used SAP Profile Generator to create, generate and assign authorization profiles
  • Created and maintained users using SU01 and SU10
  • Designed and Assigned Derived roles, Composite roles and Single Roles using Profile Generator (PFCG) for FI, SD, MM, PP, PM,APO,SCM,BI, CRM modules
  • Expert in user administration, end user support, transporting roles and computer aided test tools (CATT)
  • Performed integration and Implementation of SSO in Enterprise Portal with R/3 4.6C, 4.7 5.0 and ECC6.0 EHP6, CRM, BI7.0
  • Maintain User administration and System administration for Portal systems (UME).
  • Worked on BW security
  • Provided day to day security support and administration for all security modules
  • Excellent problem solving, analytical, technical and trouble shooting skills, team player with good communication skills
  • Designed and tested SAP Identity Management tool which linked cross enterprise applications - ECC 6.0, HR Module, Active directory (IBM Blue pages) and Lotus notes.
  • Design and implement SSO - Single sign-on along with GRC 10.0 to align with IDM Strategy

TECHNICAL SKILLS

  • SAP ECC 7.0
  • SAP R/3 4.7/4.6C/4.6A,B/5.0/6.0
  • GRC 5.2/5.3/10.0
  • SAP Enterprise Portal 7.0/6.0
  • CRM
  • SRM
  • HCM
  • BI 7.0, BW 3.5
  • SAP IDM 7.0/7.1
  • VENDAVO
  • Portals
  • PI, XI
  • Approva BizRights
  • Sabrix
  • Cognos
  • UAWEB
  • UPSIDE
  • BPC

PROFESSIONAL EXPERIENCE

Sr. SAP Security/GRC Consultant

Confidential, Houston, Texas

Responsibilities:

  • Security design & support for ECC 4.6c, 4.7, 5.0,6.0, BI 7.0, CRM 5.0, & GRC 5.3
  • Compared the Role based and ID based approaches for implementing GRC Firefighter and recommended the best approach to the client.
  • Created Users & Groups in the portal system and Assigned the Portal based Groups to the users in DEV, QA, PROD.
  • Performed GRC Pre-implementation checks and verified the status of RTAs, IGS server, Deamon job, J2EE server, SLD Status and JCO Connection.
  • Demonstrated the capabilities of GRC Risk Terminator in preventing risks at the role creation stage.
  • Reviewed and analyzed the deficiencies in the existing security processes and recommended process improvements.
  • Streamlined the User Access Request process by clearly defining the appropriate access for each functional team.
  • Designed and tested SAP Identity Management tool which linked cross enterprise applications - ECC 6.0, HR Module, Active directory (IBM Blue pages) and Lotus notes.
  • Design and implement SSO - Single sign-on along with GRC 10.0 to align with IDM Strategy
  • Configured LDAP on the CUA and enabled the dataflow by mapping the appropriate fields.
  • Scheduled a daily background job for LDAP sync program to synchronize data between SAP and LDAP.
  • Created and maintained number of ECATT scripts for the team, thus enhancing productivity.
  • Created custom rules and incorporated them into the global rule set in Compliance Calibrator.
  • Standardized the Firefighter login activity by the creation of custom reason codes.
  • Mapped Roles to Positions in SRM Organizational structure.
  • Setup Analysis Authorizations using transaction RSECADMIN in BI 7.0
  • Created portal iViews, Worksets, Pages and Roles.
  • Defined Authorization assignment & management strategy and Procedures
  • Define User and Authorization Management Technical Strategy using CUA
  • Define User Roles and role Management Procedures (Role Owners, etc)
  • Did user analysis for all users and cleaned up users from SOD violation (24,000 users).
  • Helped and suggested client for identifying custom Tcodes and programs which have SOD impact and how to remediate conflict for custom Tcodes
  • Worked with Internal Audit in designing mitigating controls and assigned users.
  • Setup SOD weekly batch job’s that for all parts of the business.
  • Worked with Audit in providing SOD reports for SOX audit.
  • Worked with BPO’s and Senior Management on mitigation/remediation of SOD conflicts.
  • Assign Firefighter ID’s to owners and fire fighters.
  • Design, write and implement security related standard procedures for the user administration, roles and profile generation
  • Train User and Authorization Administrators (Ongoing user admin support)
  • Established Naming convention and developed Support, Dev & Production roles
  • Role Analysis & Object level security to build Production security roles
  • Created a Functional Spec for Security Automation program for Business approval
  • Identified & Built Functional controls in each business process with the help of audit team
  • Quarterly pulled audit reports for systems via Approva Bizrights.

SAP Security/GRC Administrator

Confidential

Responsibilities:

  • Extensively involved in creating roles in compliance with SOX regulations as determined by VIRSA/GRC.
  • Troubleshoot workflow issues in GRC Access Enforcer and approver not found errors by creating Escape routes.
  • Compared the transactions and authorization objects from old system and replaced them with the new ones for the upgrade assignment.
  • Implemented GRC’s Role Expert and performed a security redesign based on the CC facilitated Internal Controls Framework.
  • Enabled regulated Super user access control via GRC’s Firefighter.
  • Utilized trace (ST01) results to identify the expected authorization values and incorporated them into the security roles after the upgrade.
  • Performed a mapping of the portal roles with the backend system.
  • Maintained security for BW power users and gave them authorizations for their new querries.
  • Set up security roles and user accounts for three follow-on projects, including Business Warehouse (BW 7.0).
  • Prepared numerous reports and coordinated with PWC auditors to make the company SOX compliant.
  • Synchronized key data from SAP HR including default cost center, manager relationship, spend limit/signing authority, location etc in the EBP landscape.
  • Relinked user master records to profiles as part of the ECC upgrade project.
  • Followed the steps outlined in SU25 for the ECC 5.0 upgrade.
  • Performed extensive role redesign for the IT and business users in the system.
  • Worked on continuous process improvement with the team to reduce and streamline security processes.
  • Maintained users in CRM landscape and applied the best practices in CRM security administration.
  • Configured the profiles and gave appropriate authorizations for the SRM users.
  • Performed activities like role/profile assignment, user administration using the Solution manager.
  • Used Profile Generator (PFCG) for creation, modification of single roles, composite roles, global roles, derived roles in R/3.
  • Involved in portal setup and connected the different systems using RFC.
  • Interfaced with the External SOX Auditor and involved in the SOX Audit documentation and process improvement.
  • Transported the generated roles and profiles using SAP transport management system.
  • Configured AIS and assigned the Audit Roles to the Internal/External Auditors.
  • Organization level restrictions were maintained at sales organization, sales office and sales group.

SAP R/3 Security Administrator

Confidential

Responsibilities:

  • Set up security roles and user accounts for over 1200 End Users.
  • Effectively utilized the alert monitor of GRC’s Compliance Calibrator to provide an alert to any potential violation.
  • Shared my security expertise for the design of business processes in the new release in the blueprint phase of the upgrade project.
  • Prepared a revised security policy for the new release in the upgrade project.
  • Reviewed the audit trail of user access requests and approvals through GRC’s Access Enforcer.
  • Coordinated the user account creation and termination policy with Human Resources (HR) and Operations.
  • Created and maintained SAP Authorizations, User Master Records, Table authorizations, Authority checks, Activity group creation, and profiles.
  • Created custom BW Info Objects and Authorization objects on all clients.
  • Designed several utilities to support SAP R/3 security reporting needs (Reports of user usage, profiles and authorizations, comparison report in different R/3 system, Lock/Unlock user in client etc).
  • Effectively analyzed trace files and tracked missed authorizations for user’s access problems and inserted missing authorizations manually.
  • Created Custom transaction codes for the programs and worked with developers to enforce the authority check.
  • Reviewed and revised Security policies with the client and documented the same.
  • Applied OSS notes in order to correct profile generator, security transactions and security report bugs.
  • Provided knowledge transfer for SAP R/3 security environment, explaining the concepts of authorization objects, profiles, authorizations, fields and field values, user master records as well as profile generator to the client.

We'd love your feedback!