SAP S/4HANA Security Consultant
Posted 3 days ago
neshent technologiesDallas County (TX)
Computer Systems AnalystsComputer Systems Design Services
SENIORITY
Lead
About the role
Roles and Responsibilities
Design, develop, and maintain SAP security roles and authorization concepts across S/4HANA environments.
Configure and manage single, composite, and derived roles, authorization objects, and organizational-level restrictions using PFCG.
Manage user provisioning, role assignments, modifications, and deprovisioning in accordance with security policies.
Lead security design workshops and translate business requirements into scalable authorization solutions.
Implement and support SAP Fiori security, including catalogs, spaces, pages, launchpad authorizations, OData services, and SAP Gateway.
Support security requirements for CDS views, embedded analytics, and other S/4HANA capabilities.
Perform SoD assessments, identify access risks, and coordinate remediation and mitigation activities.
Configure and support SAP GRC Access Control, including ARA, ARM, EAM, and BRM.
Conduct periodic access reviews, role rationalization, and compliance assessments.
Troubleshoot authorization issues using SU53, SUIM, PFCG, ST01, STAUTHTRACE, and Security Audit Logs.
Support internal and external audits by preparing role matrices, access reports, SoD analysis, and compliance evidence.
Collaborate with Basis, ABAP, functional, integration, and infrastructure teams to resolve complex security and authorization issues.
Support SAP implementations, upgrades, migrations, rollouts, and S/4HANA transformation initiatives.
Establish security standards, role naming conventions, authorization guidelines, and access control procedures.
Evaluate new SAP technologies and ensure security requirements are incorporated into enterprise architecture and business processes.
Required Skills
10+ years of experience in SAP Security and Authorizations.
Strong hands-on experience with SAP S/4HANA Security and authorization frameworks.
Expertise in SAP ECC and S/4HANA user and role administration.
Strong experience with PFCG, authorization objects, organizational levels, and role design.
Hands-on experience with SAP Fiori, Launchpad, OData, SAP Gateway, and CDS authorization concepts.
Strong experience with SAP GRC Access Control, including:
Access Risk Analysis (ARA)
Access Request Management (ARM)
Emergency Access Management (EAM)
Business Role Management (BRM)
Strong understanding of Segregation of Duties (SoD), access governance, risk management, audit, and compliance controls.
Experience troubleshooting authorization issues using SU53, SUIM, ST01, STAUTHTRACE, and Security Audit Logs.
Experience supporting SAP implementation, rollout, upgrade, migration, or transformation programs.
Strong communication, analytical, problem-solving, and stakeholder management skills.
Preferred Skills
SAP BTP Security
SAP IAS, IPS, and Cloud Identity Services
SAP MDG Security
SAP Ariba Security
SAP SuccessFactors Security
SAP BW/4HANA Security
SAP Analytics Cloud (SAC) Security
SAP Solution Manager and ChaRM
Enterprise IAM solutions
Qualifications
Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field.
SAP Security and/or SAP GRC certifications are preferred.
Experience supporting global SAP programs is highly desirable.
Experience working in regulated environments with strong audit and compliance requirements is a plus.
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
