Now hiring

Lead Architect-SAP Security (Bangalore, Karnataka, IN) @ novonord

INOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

<p> </p><p style="margin:9.0pt 0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif;text-align:justify"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Organization: Novo Nordisk Global Business Services (GBS)</span></p> <p style="margin:9.0pt 0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif;text-align:justify"> </p> <p style="margin:0.0cm 0.0cm 10.0pt;font-size:12.0pt;font-family:Aptos, sans-serif;text-align:justify"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">At Novo Nordisk, our SAP landscape underpins critical business and regulated processes globally — spanning Finance, Supply Chain, Manufacturing, Quality, and R&amp;D. As we continue our S/4HANA transformation journey and expand our SAP Business Technology Platform (BTP) footprint, we are looking for an exceptional SAP Security Architect to lead and own our end-to-end SAP security strategy, architecture, and governance.</span></p> <p style="margin:0.0cm 0.0cm 10.0pt;font-size:12.0pt;font-family:Aptos, sans-serif;text-align:justify"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">If you are an expert in SAP security, authorisations, and SAP cyber risk management with a proven track record of designing enterprise-grade SAP security architectures across S/4HANA, BW/HANA, HANA DB, Fiori, and BTP — we want to hear from you.</span></p> <p style="margin:0.0cm 0.0cm 10.0pt;font-size:12.0pt;font-family:Aptos, sans-serif;text-align:justify"> </p> <p style="margin:8.0pt 0.0cm 4.0pt;font-size:16.0pt;font-family:'Aptos Display', sans-serif;color:#0f4761;font-weight:normal;text-align:justify"><strong><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black"><a style="color:black" name="the-position"></a>The Position</span></strong></p> <p style="margin:0.0cm 0.0cm 10.0pt;font-size:12.0pt;font-family:Aptos, sans-serif;text-align:justify"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black"><a style="color:black" name="sap-security-architecture-strategy"></a>As a SAP Security Architect, you will be a key technical leader within our SAP Security function, responsible for defining and driving the SAP security architecture, standards, and governance across a complex, global, and regulated SAP landscape. You will work closely with senior stakeholders, cybersecurity leadership, compliance teams, and SAP programme teams to ensure our SAP environment is secure, compliant, and fit for the future.</span></p> <p style="margin:0.0cm 0.0cm 10.0pt;font-size:12.0pt;font-family:Aptos, sans-serif;text-align:justify"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">This is a individual contributor and leadership role with significant scope, influence, and visibility across the organisation.</span></p> <p style="margin:0.0cm 0.0cm 10.0pt;font-size:12.0pt;font-family:Aptos, sans-serif;text-align:justify"> </p> <p style="margin:8.0pt 0.0cm 4.0pt;font-size:14.0pt;font-family:Aptos, sans-serif;color:#0f4761;font-weight:normal;text-align:justify"><strong><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">SAP security architecture &amp; strategy</span></strong></p> <ul> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Define and own the SAP security architecture (on-prem and cloud), including target-state design, standards, reference architectures, and implementation roadmaps.</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Drive security-by-design across SAP programs (new implementations, rollouts, upgrades, and S/4HANA transformations).</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Engage with technical and compliance SMEs, business stakeholders, and vendors to shape direction and delivery outcomes.</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Present SAP security posture, risks, and roadmap to senior leadership and the CISO organisation.</span></li> </ul> <p style="font-size:12.0pt;font-family:Aptos, sans-serif;text-align:justify"> </p> <p style="margin:8.0pt 0.0cm 4.0pt;font-size:14.0pt;font-family:Aptos, sans-serif;color:#0f4761;font-weight:normal;text-align:justify"><strong><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black"><a style="color:black" name="authorisation-design-implementation-core"></a>Authorisation design &amp; implementation (core)</span></strong></p> <ul> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Lead the design and implementation of SAP authorisation concepts and role-based access control (RBAC) across end-to-end business processes (e.g., Finance, Supply Chain, Manufacturing, Quality, HR, BW, ATTP, GBT).</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Establish and govern role design methodology (business roles, derived roles, org-level strategy, SU24 governance, naming conventions, firefighter strategy).</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Streamline and govern role lifecycle processes (intake, build, testing, approvals, transport, periodic review, and recertification).</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Govern change management and transport security processes to ensure integrity of the SAP security landscape.</span></li> </ul> <p style="margin:1.8pt 0.0cm 1.8pt 36.0pt;font-size:12.0pt;font-family:Aptos, sans-serif;text-align:justify"> </p> <p style="margin:8.0pt 0.0cm 4.0pt;font-size:14.0pt;font-family:Aptos, sans-serif;color:#0f4761;font-weight:normal;text-align:justify"><strong><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black"><a style="color:black" name="s4hana-fiori-modern-ux-security"></a>S/4HANA, Fiori &amp; modern UX security</span></strong></p> <ul> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Secure SAP Fiori front-end and SAP Gateway (catalogs/groups/spaces/pages concepts, OData service authorisations, UI/service hardening).</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Design secure authentication and SSO patterns (SAML2/OAuth2, SNC/Kerberos, MFA integration where applicable).</span></li> </ul> <p> </p> <p style="margin:8.0pt 0.0cm 4.0pt;font-size:14.0pt;font-family:Aptos, sans-serif;color:#0f4761;font-weight:normal;text-align:justify"><strong><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black"><a style="color:black" name="sap-btp-security-cloud"></a>SAP BTP security (cloud)</span></strong></p> <ul> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Design and implement SAP BTP security models (subaccount structure, entitlements, role collections, XSUAA, destinations, Cloud Connector considerations).</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Integrate SAP BTP with enterprise identity providers and SAP cloud identity services (IAS/IPS) and define secure onboarding patterns.</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Define API security standards and integration security patterns for SAP Integration Suite, PI/PO, and other middleware components.</span></li> </ul> <p> </p> <p style="margin:8.0pt 0.0cm 4.0pt;font-size:14.0pt;font-family:Aptos, sans-serif;color:#0f4761;font-weight:normal;text-align:justify"><strong><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black"><a style="color:black" name="bwhana-hana-db-security"></a>BW/HANA &amp; HANA DB security</span></strong></p> <ul> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Own security design for BW on HANA / BW/4HANA (analysis authorisations, data access controls, authorization-relevant objects).</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Design HANA database security (users/roles, privileges, schemas, auditing, encryption options, secure connectivity patterns).</span></li> </ul> <p> </p> <p style="margin:8.0pt 0.0cm 4.0pt;font-size:14.0pt;font-family:Aptos, sans-serif;color:#0f4761;font-weight:normal;text-align:justify"><strong><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black"><a style="color:black" name="Xa0532320cc3598f9c32f4e6beab55c2f202891c"></a>Governance, Risk &amp; Compliance (GRC), audits &amp; controls</span></strong></p> <ul> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Lead SAP security controls design and operationalization for internal/external audits (SOX/ITGC and other control frameworks), including evidence readiness and remediation plans.</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Drive Segregation of Duties (SoD) design and remediation, emergency access controls, and continuous control monitoring.</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Partner with cybersecurity teams to align SAP controls to enterprise security requirements (logging/monitoring, vulnerability management, hardening, incident response playbooks for SAP).</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Lead SAP security controls design and operationalization for internal and external audits including SOX/ITGC, GxP/CSV (Computerized System Validation), and other applicable control frameworks.</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Ensure security documentation readiness for GxP-validated SAP systems including User Requirement Specifications (URS), Functional Specifications (FS), and Requirements Traceability Matrices (RTM).</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Leverage SAP security tooling (e.g., SAP EarlyWatch Alert, Security Bridge, Onapsis, or equivalent) for continuous vulnerability management and security monitoring.</span></li> </ul> <p> </p> <p style="margin:8.0pt 0.0cm 4.0pt;font-size:14.0pt;font-family:Aptos, sans-serif;color:#0f4761;font-weight:normal;text-align:justify"><strong><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black"><a style="color:black" name="delivery-leadership"></a>Delivery leadership</span></strong></p> <ul> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Provide technical leadership to SAP security teams (onshore/offshore), coach senior analysts, and review solution designs and deliverables.</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Define and track key security metrics including SoD violation reduction, audit finding remediation rates, role design quality, and security architecture coverage.</span></li> </ul> <p style="margin:0.0cm 0.0cm 10.0pt;font-size:12.0pt;font-family:Aptos, sans-serif;text-align:justify" align="center"> </p> <p style="margin:8.0pt 0.0cm 4.0pt;font-size:16.0pt;font-family:'Aptos Display', sans-serif;color:#0f4761;font-weight:normal;text-align:justify"><strong><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Qualifications</span></strong></p> <p style="margin:9.0pt 0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif;text-align:justify"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">To be successful in this role, you should have:</span></p> <ul> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Bachelor’s degree in engineering, Computer Science, or related field.</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">15–20 years of relevant SAP Security experience, including several full lifecycle implementations and global rollouts.</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Deep hands-on expertise in SAP authorizations and security administration across key SAP modules (S/4, BW, ATTP, GBT) and business processes.</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Strong experience with S/4HANA security and role redesign.</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Strong experience in SAP audit/security and compliance initiatives such as SoD remediation, SOX, and ITGC.</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Proven SAP cybersecurity experience (risk assessments, secure configuration/hardening, security logging/monitoring integration, vulnerability remediation coordination).</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Consulting background strongly preferred; Big 4 consulting experience is highly desirable.</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Ability to work with senior stakeholders and translate business requirements into secure, scalable access designs.</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Excellent communication skills in written and spoken English.</span></li> </ul> <p style="margin:8.0pt 0.0cm 4.0pt;font-size:14.0pt;font-family:Aptos, sans-serif;color:#0f4761;font-weight:normal;text-align:justify"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Nice to have (common for SAP Security Architect roles)</span></p> <ul> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Experience with SAP GRC Access Control and/or SAP Cloud Identity Access Governance.</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Security certifications (e.g., CISSP, CISA, CISM, CRISC) and/or SAP security-related certifications.</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Experience in regulated environments (e.g., GxP) and validated system landscapes.</span></li> <li style="color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Experience with SAP security vulnerability management tools (e.g., SecurityBridge, Onapsis, Relevant).</span></li> </ul> <p style="margin:9.0pt 0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif;text-align:justify"> </p> <p style="margin:9.0pt 0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif;text-align:justify"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black"><strong>Working at Novo Nordisk</strong></span></p> <p style="margin:9.0pt 0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif;text-align:justify"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black">Every day we seek the solutions that defeat serious chronic diseases. To do this, we approach our work with determination, constant curiosity and a commitment to finding better ways forward. For over 100 years, this dedication has driven us to build a company focused on lasting change for long-term health. One where diverse thinking, shared purpose and mutual respect come together to create extraordinary results. In this role, you’ll be at the forefront of our digital transformation, ensuring the security and integrity of systems that directly impact millions of patients globally. When you join us, you’re not just starting a job – you’re becoming part of a story that spans generations.</span></p> <p style="margin:9.0pt 0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif;text-align:justify"> </p> <p style="margin:9.0pt 0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif;text-align:justify"><span style="font-family:verdana, geneva, sans-serif;font-size:10.0pt;color:black"><strong>Deadline</strong> : 26 May 2026 (Applications are reviewed on an ongoing basis).</span></p><p><span style="color:#000000"><span style="font-size:12.0px"><span style="font-family:Verdana, Geneva, sans-serif">We commit to an inclusive recruitment process and equality of opportunity for all our job applicants.</span></span></span></p> <p> </p> <p><span style="color:#000000"><span style="font-size:12.0px"><span style="font-family:Verdana, Geneva, sans-serif">At Novo Nordisk, we&apos;re not chasing quick fixes – we&apos;re creating lasting change for long-term health. For over 100 years, we&apos;ve been driven by a single purpose: to defeat serious chronic diseases and help millions of people live healthier lives. This dedication fuels our constant curiosity and inspires us to push the boundaries of what&apos;s possible in healthcare. We embrace diverse perspectives, seek out bold ideas, and build partnerships rooted in shared purpose. Together, we&apos;re making healthcare more accessible, treating and preventing diseases, and pioneering solutions that create change spanning generations. When you join us, you become part of something bigger – a legacy of impact that reaches far beyond today.</span></span></span></p>

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores