Access Controls Lead
Your Company:
NET Recruit is proud to be partnering with a large and established organisation in their search for an Access Controls Lead to join their Finance Controls & Governance function.
This is a specialist role operating across Finance, Technology, Risk and Assurance, with responsibility for strengthening the organisation’s access governance framework across core finance systems and supporting technologies. The successful candidate will play a key role in ensuring appropriate access is maintained, risks are proactively identified and managed, and key controls are consistently operated and evidenced to a high standard
Your Roles & Responsibilities :
While in this position your duties will include, but are not limited to:
- Owning and overseeing a defined suite of IT General Controls relating to user access management, SAP GRC Access Control and privileged access governance.
- Operating and maintaining SAP GRC Access Control processes, including access request workflows, risk analysis and user provisioning controls.
- Monitoring SAP GRC workflows and provisioning activities to ensure access requests are appropriately approved, completed and evidenced.
- Owning and overseeing periodic reviews of privileged, emergency and sensitive access using SAP GRC reporting and risk analysis tools.
- Ensuring access controls are appropriately designed, documented, executed and evidenced to audit standard.
- Maintaining governance standards across role owners, risk owners and control operators.
- Supporting the remediation and resolution of access control deficiencies, audit findings and control exceptions.
- Owning and governing the Segregation of Duties and Sensitive Access framework across SAP S/4HANA and connected systems.
- Working with Business and IT workstream leads to review SAP GRC risk analysis at user, role and profile level, identifying High and Critical access risks.
- Analysing SoD conflicts and working with stakeholders to define remediation actions, role redesign or appropriate mitigating controls.
- Monitoring sensitive and privileged access risks and ensuring the required approvals, documentation and periodic reviews are completed.
- Reviewing and challenging access requests containing High or Critical risks and ensuring governance decisions are appropriately documented.
- Governing, maintaining and enhancing the SAP GRC Access Control ruleset, including SoD risks, sensitive access risks, functions, permissions and rule assignments.
- Maintaining and periodically reviewing mitigating controls within SAP GRC to ensure they remain appropriate, effective and supported by clear business justification.
- Performing ruleset analysis and supporting updates resulting from new transactions, Fiori applications, business process changes and system enhancements.
- Supporting the testing and validation of SAP GRC controls, workflows and ruleset changes during projects and system releases.
- Producing and analysing SAP GRC reports and dashboards to support control monitoring, audit requirements and management reporting.
- Supporting the periodic extraction and review of access governance evidence for internal and external audit activities.
- Owning the User Access Review process and ensuring reviews are completed accurately and within agreed timescales.
- Performing periodic control self-assessments and supporting the remediation of identified control gaps and audit findings.
- Maintaining comprehensive control documentation and appropriate audit evidence.
- Acting as a key contact for internal and external audit activities relating to access governance controls.
- Working closely with Finance, IT, Risk and Assurance teams to support effective control environments and risk management.
- Providing guidance to stakeholders on access governance requirements, risk decisions and appropriate control measures.
What You Will Need to Apply:
- Strong understanding of Finance processes, IT General Controls and access governance principles.
- Extensive knowledge of Segregation of Duties, Sensitive Access and privileged access management.
- Proven experience working with SAP GRC Access Control and SAP security concepts.
- Practical experience performing SAP GRC risk analysis and supporting access governance activities.
- Strong understanding of SAP roles, authorisations, access provisioning and User Access Reviews.
- Experience supporting audit, compliance or internal controls activities.
- The ability to analyse access risks and coordinate appropriate remediation activities across Business and IT teams.
- Strong understanding of access control frameworks and the principles underpinning effective governance.
- Excellent stakeholder management and communication skills, with the ability to work confidently across Finance, Technology, Risk and Assurance functions.
- Strong analytical and problem-solving skills, with the ability to assess complex access risks and develop practical solutions.
- A highly organised and detail-focused approach, particularly when managing control evidence, reviews and audit requirements.
- The ability to operate effectively in a complex environment and build strong relationships with both technical and non-technical stakeholders.
What You Will Get in Return:
This is a temporary opportunity to take ownership of a critical area of the organisation’s Finance Controls and Governance framework, working at the intersection of Finance, Technology, Risk and Assurance.
The role is based in Farringdon, London, with a hybrid working arrangement. The successful candidate will be expected to attend the office as required, anticipated to be approximately 1–2 days per week, depending on business requirements.
The role offers a day rate of approximately £550–£600 per day. Candidates seeking a rate above this range may be considered depending on experience, although the position is working within an agreed budget.
You will have significant responsibility for shaping and maintaining the organisation’s approach to access governance, SoD, Sensitive Access and privileged access management, while working closely with stakeholders across multiple functions.
If you are interested in this opportunity and would like to find out more information, please reach out to:
Justin Heron - Talent Acquisition Director
M:
E: