Now hiring

SAP S/4 HANA Security Expert (Chennai, IN, 600 032) @ ASSA ABLOY AB

Chennai, IN, 600 032OnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

<p><img src="https://dmscdn.successfactors.com/27c0a91770d9ecac9ed08a9f63f401a6121aa728d77960676d754d492bcae147/static_content/8761288a654040abb2af/jobad1.png" alt="" width="748" height="128"> </p> <p> </p><h2><span style="font-size:10.0pt">PRIMARY JOB PURPOSE </span></h2> <p> </p> <p><span style="font-size:10.0pt">Responsible for delivering design and system configuration for SAP S/4HANA Security, ensuring the implementation of robust access control and authorization frameworks across business units. The candidate is accountable for translating business and compliance requirements into secure role designs, managing user access, Segregation of Duties (SoD) controls, and supporting data migration, testing, audit readiness, and post-go-live activities, while aligning with SAP security best practices and project timelines.</span></p> <p> </p> <p><span style="font-size:10.0pt"><strong>Key Position Accountabilities</strong><strong> for SAP Security – S/4HANA</strong></span></p> <p> </p> <ul> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Being part of the Global IT team and responsible for SAP S/4HANA Security design, ensuring roles and authorization concepts are designed, built, tested, and deployed in alignment with SAP best practices and compliance standards.</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Facilitate and support workstream managers, Solution Architects, and business leads from requirement gathering through solution design, with a strong focus on access control, Segregation of Duties (SoD), and integration across Finance, PM, BRIM and other functional modules.</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Analyse business and audit requirements related to user access, role design, privileged access (FFID), and compliance mandates, ensuring secure and appropriate system access.</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Design and configure SAP security components such as single roles, master roles, derived roles, organizational level restrictions, and user provisioning processes, while coordinating with technical teams for enhancements and automation.</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Responsible for creating and maintaining role design documentation, security specifications, and supporting GRC-related objects including access risk analysis, mitigation controls, and firefighter IDs (FFID) This will be future role assignments.</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Perform user administration activities including user creation, role assignment, troubleshooting authorization issues, and ensuring compliance with security policies.</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Execute and support security lifecycle activities including role build, testing (unit/SIT/UAT), audit validation, migration, cutover, go-live, and hyper care support.</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Support incident management and change requests related to SAP security, ensuring timely resolution and minimal business disruption.</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Strong experience in SAP Fiori Security, including Fiori Launchpad configuration, Catalogs, Groups, and Spaces &amp; Pages.</span><br><span style="font-size:10.0pt">• Hands-on experience in managing OData Services activation (SICF &amp; /IWFND/MAINT_SERVICE) and troubleshooting authorization issues.</span><br><span style="font-size:10.0pt">• Knowledge of front-end vs back-end role design for Fiori apps and integration with PFCG roles.</span><br><span style="font-size:10.0pt">• Experience with Fiori app types (Transactional, Analytical, Fact Sheets) and required authorization objects.</span><br><span style="font-size:10.0pt">• Understanding of SAP Gateway architecture and Fiori role mapping.</span></li> </ul> <p><span style="font-size:10.0pt"><strong>SELECTION CRITERIA </strong></span></p> <p><span style="font-size:10.0pt"><strong>Essential: </strong></span></p> <ul> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Bachelor’s / Master’s degree in Computer Science, Information Technology, Business, or equivalent discipline with <strong>minimum 6 to 7 years of experience</strong> in SAP Security &amp; GRC across multiple industries.</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Minimum 2 full lifecycle implementations / rollouts and support experience in SAP S/4HANA or SAP ECC projects with a focus on Security and Authorizations.</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Extensive hands-on experience in SAP Security design and configuration, including roles and authorizations (Single, Master, and Derived roles), organizational level restrictions, and user administration.</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Strong experience in SAP GRC Access Control (ARA, ARM, EAM), including SoD risk analysis, mitigation controls, Firefighter ID (FFID) management, and access request workflows.</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Hands-on experience in end-to-end user and role lifecycle management, including role design, build, testing (Unit/SIT/UAT), and production support.</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">In-depth understanding of SAP security best practices, compliance frameworks, audit requirements, and segregation of duties (SoD) concepts.</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Experience in S/4HANA environment, Fiori security (catalogs, groups, spaces/pages), and frontend/backend role design.</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Working knowledge of integration with SAP modules such as (FI, MM, BRIM, PM,S2C,R2R, P2P, Basis, etc.for cross-functional security design.</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Experience in handling audits, user access reviews, and compliance reporting.</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Strong analytical, problem-solving, and troubleshooting skills in resolving authorization issues (SU53, ST01, SUIM, etc.).</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Excellent communication skills in English, with the ability to interact with business stakeholders, auditors, and technical teams.</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Self-driven, proactive, and able to manage multiple priorities within tight project timelines.</span></li> </ul> <p><span style="font-size:10.0pt"><strong> </strong></span></p> <p><span style="font-size:10.0pt"><strong> </strong></span></p> <p><span style="font-size:10.0pt"><strong> </strong></span></p> <p><span style="font-size:10.0pt"><strong> </strong></span></p> <p><span style="font-size:10.0pt"><strong>Desirable:</strong></span></p> <p><span style="font-size:10.0pt"><strong> </strong></span></p> <ul> <li style="font-size:10.0pt"><span style="font-size:10.0pt">SAP S/4HANA Security Certification (preferably S/4HANA 1909 / 2020 / 2021 and above).</span><br><span style="font-size:10.0pt">• Strong knowledge of SAP Security in S/4HANA environment including Fiori Security, OData services, and Catalog/Group management.</span><br><span style="font-size:10.0pt">• Experience with SAP GRC (Access Control 10.1 / 12.0) – ARA, ARM, EAM (Firefighter), and BRM modules.</span><br><span style="font-size:10.0pt">• Expertise in role design and authorization concepts using PFCG, including single/derived/master roles.</span><br><span style="font-size:10.0pt">• Hands-on experience in SU24, SU25, SUIM, AGR tables, and authorization troubleshooting (ST01, SU53).</span><br><span style="font-size:10.0pt">• Knowledge of HANA Database security concepts and S/4HANA authorization model simplification.</span><br><span style="font-size:10.0pt">Strong experience in SAP Fiori Security, including Fiori Launchpad configuration, Catalogs, Groups, and Spaces &amp; Pages.</span><br><span style="font-size:10.0pt">• Hands-on experience in managing OData Services activation (SICF &amp; /IWFND/MAINT_SERVICE) and troubleshooting authorization issues.</span><br><span style="font-size:10.0pt">• Knowledge of front-end vs back-end role design for Fiori apps and integration with PFCG roles.</span><br><span style="font-size:10.0pt">• Experience with Fiori app types (Transactional, Analytical, Fact Sheets) and required authorization objects.</span><br><span style="font-size:10.0pt">• Understanding of SAP Gateway architecture and Fiori role mapping.</span></li> </ul> <p> </p> <p><span style="font-size:10.0pt"><strong>WORK ENVIRONMENT FACTORS </strong> </span></p> <ul> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Office based/Remote with occasional international travel.</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Health and Safety accountability statements.</span></li> <li style="font-size:10.0pt"><span style="font-size:10.0pt">Working times are European time zone, however open to be available in APAC/US time zone as well for the need basis.</span></li> </ul> <p> </p><p> </p> <p><strong>We are the ASSA ABLOY Group</strong><br>Our people have made us the global leader in access solutions. In return, we open doors for them wherever they go. With nearly 63,000 colleagues in more than 70 different countries, we help billions of people experience a more open world. Our innovations make all sorts of spaces – physical and virtual – safer, more secure, and easier to access. </p> <p>As an employer, we value results – not titles, or backgrounds. We empower our people to build their career around their aspirations and our ambitions – supporting them with regular feedback, training, and development opportunities. Our colleagues think broadly about where they can make the most impact, and we encourage them to grow their role locally, regionally, or even internationally.</p> <p>As we welcome new people on board, it’s important to us to have diverse, inclusive teams, and we value different perspectives and experiences.</p>

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores