SAP Security Specialist - Remote (25% travel)
$101,400 per year
ApplySAP Security Specialist - Remote (25% travel)
Posted today
SENIORITY
Manager
SALARY
$101,400 per year
About the role
- Design Leadership & Global Standards
- Drive the overall S/4HANA authorization and security design strategy, making final architectural decisions on role structure, SoD ruleset design, and Fiori security models
- Define, document, and own global security standards, design principles, and naming conventions for consistency across regions, business units, and future rollouts
- Oversight, Review & Approval of Contractor Work
- Provide technical oversight of contractor/SI deliverables related to role design and SoD remediation
- Review and formally approve role builds, catalog/tile assignments, and SoD ruleset changes before promotion to test/production
- Hold contractors accountable to SLAs, documentation standards, and design specifications
- Mentor contractor teams to preserve design intent and enable knowledge transferS/4HANA Migration Execution
- Lead the security workstream across Design & Build, Test Cycles, Go Live, and Hypercare phases
- Lead SoD ruleset development, and risk remediation
- Direct Fiori launchpad security design and front-end/back-end authorization alignment
- Lead cutover security activities and hypercare issue resolution
- Stakeholder & Program Engagement
- Act as primary security advisor to program and IT leadership on design risk and compliance exposure
- Represent security workstream in project meetings
- Partner with global functional and technical leads (OTC, FTM, FUL, GTS, SCP, PP, EWM, MFG) to ensure security design supports redesigned business processes
- 10+ years of SAP security administration experience, including full-cycle leadership of at least one SAP implementation
- Bachelor's degree in computer science, Information Systems, or related field.
- Experience setting global security design standards across a multi-region SAP landscape
- Proven experience reviewing, quality-checking, and approving deliverables produced by external contractors or SI partners
- Expert-level knowledge of SAP authorization concepts: PFCG, SU24, SU25, SUIM, SU53, role derivation, composite/master role structures
- Experience supporting SAP system upgrades from a security perspective, including pre/post-upgrade authorization testing and remediation
- Demonstrated ability to build and govern SoD rulesets and drive large-scale risk remediation
- Strong hands-on experience with Security Access Control process
- Solid understanding of SOX/ITGC compliance requirements
- Experience running USMM (SAP System Measurement) for license audits, including reconciling user classifications and measurement results to support license compliance reporting
- Experience managing or directing the work of both employees and external vendors/contractors on a technical deliverable
- Strong executive communication skills; able to present design decisions and risk trade-offs to senior stakeholders
- Ability to set direction and own outcomes - comfortable as the final technical authority on design decisions
- Strong quality-control mindset; holds self and contractors to a high bar
- Strategic and standards-oriented, balancing global consistency with local/regional needs
- Effective at influencing without direct authority, particularly with external partners
- Excellent written and verbal communication for both technical and executive audiences
- Approximately up to 25% of travel may be required
- SAP Security or GRC certification
- Experience with SAP Cloud Identity Access Governance (IAG) or SAP BTP security
- Experience building a global governance model for SAP security
- Familiarity with vendor management, SOW/deliverable review processes, and contractor performance management
- Experience with managing SAP Full Use Equivalent licensing metrics, ensuring user classifications and authorization assignments align with license compliance requirements and support cost optimization
- Experience with Control
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
