SAP Security Architect (ECC, S/4HANA & GRC Assessment)
SAP Security Architect (ECC, S/4HANA & GRC Assessment)
Location: Reading ,UK (Hybrid/Onsite as required) 3 to 4 days from office
Start Date: 14 September
Duration: Initial 3 Months (Assessment & Strategy Phase), potential to get extended for 12 months(Please commit only for 3 months for now)
Contract Type: Contractor
Role Overview
We are seeking an experienced SAP Security Architect to lead a comprehensive assessment of its SAP security landscape across both SAP ECC and SAP S/4HANA environments. The engagement will focus on reviewing the current security design, identifying the root causes behind a high volume of security-related incidents, assessing risks and controls, and developing a strategic roadmap for a future SAP GRC implementation.
This assignment is a discovery and advisory engagement that will lay the foundation for a larger implementation program planned for next year.
Key Responsibilities
• Conduct an end-to-end assessment of the current SAP security and authorization architecture across ECC and S/4HANA.
• Review roles, profiles, authorizations, segregation of duties (SoD), emergency access, and privileged access controls.
• Analyze security incidents and identify underlying design, process, governance, or operational gaps.
• Assess current SAP GRC capabilities, processes, and controls.
• Evaluate compliance with security best practices and audit requirements.
• Facilitate workshops with business, IT, audit, and compliance stakeholders.
• Define key security pain points, risks, and remediation priorities.
• Develop target-state SAP Security and GRC architecture recommendations.
• Prepare a high-level roadmap, effort estimate, and implementation approach for the planned GRC transformation program.
• Present findings and recommendations to senior stakeholders and project sponsors.
Required Experience
• 12+ years of SAP Security experience with strong architecture and advisory background.
• Proven expertise in both SAP ECC and SAP S/4HANA Security.
• Deep knowledge of SAP authorization concepts, role design, SoD controls, and user provisioning.
• Hands-on experience with SAP GRC Access Control, Risk Analysis & Remediation (RAR), Access Request Management (ARM), Emergency Access Management (EAM), and Business Role Management (BRM).
• Experience conducting SAP Security assessments, audits, and transformation programs.
• Strong stakeholder management and executive presentation skills.
• Experience defining security operating models and governance frameworks.
Preferred Experience
• Previous SAP security transformation or GRC implementation leadership experience.
• Exposure to SAP Fiori, BTP, Identity & Access Governance (IAG), and cloud security concepts.
• Experience working with external auditors and compliance teams.
Deliverables
• Current-state security assessment report.
• Security incident root-cause analysis.
• Risk and control gap assessment.
• High-level target architecture and design recommendations.
• SAP GRC implementation roadmap.
• Business case inputs and implementation readiness recommendations.