We provide IT Staff Augmentation Services!

Sap Grc 10.0 Consultant Resume

5.00/5 (Submit Your Rating)

TX

SUMMARY

  • Experienced SAP Security/GRC expert wif 7+ years of IT and 6 years of SAP GRC/security experience. Excels at leveraging GRC and security expertise to assure clients build a sustainable and robust, risk - free SAP landscape.
  • Strong GRC knowledgebase across all versions and modules, including GRC 10.0, GRC 5.3, Virsa 4.0, SAP HCM, SAP BW, SAP GTS, and SAP Portal. Proven track record as a communicator and influential leader who is able to articulate and transform clients’ requirements into sustainable solutions.

TECHNICAL SKILLS

  • Governance, Risk, and Compliance
  • Access Control, Security, Process Controls
  • Enterprise Architecture
  • Implementation Lifecycle Support
  • SAP Security
  • Project & Time Management
  • Written & Verbal Communication
  • Team Leadership

PROFESSIONAL EXPERIENCE

Confidential, TX

SAP GRC 10.0 Consultant

Responsibilities:

  • Lead a project team responsible for implementing Sap Business Objects Access Control 10.0
  • Performed Post Installation activities
  • Configured teh system for EAM, ARA and ARM
  • Responsible for setting up client’s connectors by creating SM59, RFC destination, maintaining connectors and connection types and assigning all four integration scenarios
  • Directly responsible for creating and delivering high quality project deliverables including blueprints and training manuals
  • Responsible for BC Set validation Created function and risk
  • Created Organization hierarchy, access control owners, mitigating controls and applied mitigating controls to users and roles
  • Generated rules in RAR for easy creation, maintenance and management of risks
  • Participated in Identifying Segregation of Duty conflicts and proposed recommendations that lead to implementation of mitigating controls and elimination of risks.
  • Implemented and configured Emergency Access formerly Firefighter
  • Configured all seven steps of MSMP workflow
  • Defined Job profiles for various Functional Areas
  • Scoped GRC10 - Access control covering Emergency Access Management (Fire Fighter or SPM), Access Risk Analysis (RAR) and Access Request Management (CUP)
  • Configured Risk Analysis, Emergency access and Access request as delivered by SAP
  • Migrated teh rule-set from Virsa compliance calibrator to AC10
  • Re-designed some access request and security development processes around GRC10
  • Implementing Access Request Management using MSMP workflows including integration wif LDAP as teh IDM source
  • Developed custom rule-set around custom Z Transactions, Z tables and associated authorizations.
  • Remediated (Retrofitted) roles containing risk violations
  • Trouble-shooting and support to ARA, EAM sub-modules while in production run.

Confidential, Chicago, IL

SAP Security Consultant

Responsibilities:

  • User Administration User and their Roles (Profile maintenance through PFCG)
  • Added and Modified teh Role to teh End User as per Management Guideline
  • Defined Job profiles for various Functional Areas
  • Created Authorizations and Profiles based on teh Job Profiles
  • Created and Maintained User Master records
  • Utilization of SU53, System traces and Debug utilities
  • Used several transactions (SU10, SU53, SU24, SUIM, ST01 etc)
  • Responsible for day-to-day user administration tasks
  • Resolved many missing authorization issues by analyzing teh SU53 screen shots
  • TEMPEffectively analyzed trace files and tracked missed authorizations for user’s access problems and inserted missing authorizations manually
  • Performed Automatic Profile Generation PFCG to create roles/profiles for various modules such as MM, FI/CO, and SD
  • Respond to requests and prepare SAP security reports based on management and department needs
  • Coordinating wif teh functional and business team
  • Business role specific authorizations for power users
  • Providing read access to info providers
  • Providing reporting authorizations based upon data values

Confidential, Newport News, VA

SAP Security Consultant

Responsibilities:

  • Used several transactions (SU10, SU53, SU24, SUIM, SE93 etc) and administered 300 users
  • Worked wif teh Business Process Owners to restrict sensitive transactions and security authorizations, and ensured segregation of duties across business areas Created segregation of duties and single critical transaction policies for IT security
  • Resolved many missing authorization issues by analyzing teh SU53 screen shots
  • Work wif profile generator (PFCG) in creating roles, profiles, composite roles & derived
  • Used Virsa tool extensively for handling SOD conflicts for each user
  • Created users, roles and assigned required privileges for teh database access
  • Mapped Business roles wif Security technical roles
  • Ran security reports for critical transactions and objects and for users who never logged on
  • Work wif VIRSA systems VRAT tool (Compliance Calibrator)
  • Used Profile Generator for creation, modifying roles, composite roles, global roles, derived roles

Confidential, Rochester, MN

SAP Security Consultant

Responsibilities:

  • Responsible to implement Role-based security administration, including design, testing and documentation
  • Complete overall support includes design and implementation for all Security needs for all user ID admin and Role builds for SOX compliance
  • Work wif profile generator (PFCG) in creating roles, profiles, composite roles & derived roles
  • Assisted in development and policies
  • Work wif VIRSA systems VRAT tool (Compliance Calibrator) in identifying conflicts single roles and composite roles
  • Redefined authorization scope using SU24 etc
  • Created new and edited teh existing Activity Groups as per teh requirements coming through Help Desk which involves teh inclusion of transactions in teh menu tree or editing teh activities as per SU53 results
  • Trouble shooting performance issues & adjustment of SAP profiles
  • Work wif Business specialists to halp them understand what SAP authorization objects are causing teh conflicts and what all options exist for mitigating teh conflicts
  • Worked wif teh Business Process Owners to restrict sensitive transactions and security authorizations, and ensured segregation of duties across business areas Created segregation of duties and single critical transaction policies for IT security
  • Implemented IT controls and a new security process for User Access management and Segregation of Duties to ensure
  • Analyzed all customer programs and transaction codes for authority checks
  • Ran security reports for critical transactions and objects and for users who never logged on
  • Worked wif functional team leads to define teh new transactions
  • Worked on SAP Check Indicator Defaults and Field values, reduced teh scope of Authorization checks using transaction SU24 and maintained check indicators for Transaction codes
  • Trouble shoot R/3 security problem by using different scenario such as system trace, parameter change, buffer reset, SU53, and SU56 in order to find security problem
  • Continuously improved security configuration to reflect best practices and to prepare for system audits
  • Distributed user master records, including migration of existing users
  • Documented teh procedure for all SAP tasks process and controls
  • Review critical and sensitive authorizations, implement improvements to meet audit requirements
  • Support teh Remediation effort for various modules in SAP Security area
  • Respond to requests and prepare SAP security reports based on management and department needs
  • Responsible for day-to-day user administration tasks
  • Resolved many missing authorization issues by analyzing teh SU53 screen shots
  • TEMPEffectively analyzed trace files and tracked missed authorizations for user’s access problems and inserted missing authorizations manually
  • Performed Automatic Profile Generation PFCG to create roles/profiles for various modules such as MM, FI/CO, and SD

We'd love your feedback!