Skip to content

Sr. SAP GRC Security Consultant

Weekday AI · Pune · Remote

Posted 8/26/2026 · last confirmed live 8/27/2026

Apply on Weekday AI’s site
This role is for one of Weekday’s clients Min Experience: 7+ years Location: Pune, Maharashtra / Remote (India) JobType: full-time POSITION SNAPSHOT Job Title Sr. SAP GRC Security Consultant – S/4HANA & BTP Cloud Applications Employment Type Permanent / Full-Time Location Pune, Maharashtra / Remote (India) Experience 7–10 Years in SAP GRC & Security Shift Time US Shift (5:30 PM to 2:30 AM IST) Notice Period Immediate to 30 Days Preferred We are looking for an experienced SAP GRC & Security Consultant with strong hands-on exposure to SAP S/4HANA Security and SAP BTP Cloud Applications, including Identity Access Governance (IAG), SAP Analytics Cloud (SAC), and Datasphere. The ideal candidate combines a strong understanding of business process functionality with the ability to design, manage, and audit access controls across hybrid SAP landscapes, ensuring SoD compliance and audit readiness while working closely with business and IT stakeholders. Requirements KEY RESPONSIBILITIES Design, configure, and manage user roles, authorizations, and profiles across SAP S/4HANA and Fiori environments. Configure and administer SAP BTP Identity Access Governance (IAG) for access risk analysis, SoD management, and automated access certifications across cloud landscapes. Manage role-based security and data-level access controls within SAP Analytics Cloud (SAC) and SAP Datasphere. Partner with business process owners to translate business functionality and process requirements into effective access control designs. Design, monitor, and maintain SoD rulesets, and lead risk analysis and remediation across hybrid (cloud + on-premise) SAP landscapes. Conduct periodic user access reviews, audit trail analysis, and compliance checks aligned with SOX, GDPR, and internal audit requirements. Prepare and maintain audit evidence, security documentation, and control reports for internal and external auditors. Collaborate with cross-functional teams — Basis, Functional, and IAM — to ensure secure, compliant, end-to-end access design across the SAP ecosystem. MUST-HAVE SKILLS 7–10 years of hands-on SAP Security / GRC experience across S/4HANA and cloud landscapes. SAP GRC Access Cont10ol (ARA, EAM, ARM, BRM) experience alongside SAP BTP IAG Strong hands-on expertise in SAP BTP Cloud Applications — Identity Access Governance (IAG), SAP Analytics Cloud (SAC), and Datasphere security and auditing. Solid understanding of SAP S/4HANA and Fiori security — role design, authorization concepts, and access provisioning. Strong grasp of business processes and functionality, with the ability to translate business requirements into control and access designs. Experience managing SoD rulesets, access risk analysis, and remediation across GRC Access Control modules. Proven experience supporting audit cycles (SOX, GDPR, or equivalent), including access reviews, control testing, and audit evidence preparation. Ability to independently manage complex access control landscapes and communicate risk clearly to business and IT stakeholders. GOOD TO HAVE SAP HANA database security exposure — user management, privileges, and audit log configuration. SAP Cloud Identity Services (IAS/IPS), SSO configuration via SAML 2.0 / OIDC, and integration with Azure AD or Okta. Exposure to Cloud ALM security and SAP BTP trust configuration. SAP GRC or SAP Security certification is a plus. Must-have skills SAP, GRC, BTP Good-to-have skills S4 Hana, HANA DB, FIORI

How your resume reads against this

What this posting states — years, degree, arrangement, pay, the skills it names — beside what your resume says. No match percentage: there is not an honest one to give.

This reads the resume you have in the editor, and this browser has none yet.

Open the editor and upload yours

Free, no account. It stays in this browser and is never stored on our side.

This role is published by Weekday AI on workable. SwiftFit is not the employer and does not accept applications.