SAP Security & GRC Engineer

Bright Vision Technologies
Lexington, MA, United States
7 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$100,000.0 - $150,000.0
Working hours
Regular working hours

Tech stack

Audit Trail Cloud Computing Identity and Access Management SuccessFactors Runbook SAP (Applications) SAP NetWeaver Business Warehouse SAP GRC SAP Security User Provisioning Software Data Logging SAP Business Technology Platform
+5 more
Sap Fiori SAPBasis Information Technology SAP S/4HANA GXP

Job description

We are seeking an experienced SAP Security & GRC Engineer to design, implement, and operate security and access-control frameworks for complex SAP landscapes, including S/4HANA, ECC, BW/4HANA, Fiori, BTP, and SuccessFactors. In this role you will be responsible for SAP role design, user provisioning, segregation-of-duties analysis, audit support, and the technical operation of SAP GRC suites. The ideal candidate will combine deep expertise in SAP authorization concepts with strong hands-on experience operating SAP GRC Access Control and Process Control, and will partner closely with audit, compliance, and business teams to deliver a secure, auditable SAP environment. Key Responsibilities

  • Design and maintain SAP authorization concepts and role structures aligned with business processes and least-privilege principles.
  • Build and maintain master, derived, composite, and business roles for S/4HANA, ECC, and Fiori applications.
  • Configure and operate SAP GRC Access Control (ARA, ARM, BRM, EAM), including ruleset management, mitigating controls, and emergency access management.
  • Perform segregation-of-duties analysis and remediation in collaboration with business process owners and internal audit.
  • Configure user provisioning workflows in SAP GRC ARM, including request types, approval paths, and integration with IDM/IAM platforms.
  • Operate SAP GRC Process Control for continuous controls monitoring and policy management.
  • Implement security for Fiori applications, including catalogs, groups, and front-end authorizations.
  • Configure and operate security for SAP BTP and cloud applications using XSUAA, IAS, and IPS.
  • Support SAP audits (SOX, GxP, PCI) and respond to audit findings with documented remediation plans.
  • Implement transport security, table logging, and audit logging in line with internal security policies.
  • Monitor and remediate SAP Security Notes in coordination with Basis and DBA teams.
  • Maintain comprehensive, current technical documentation - including architecture diagrams, design decisions, configuration references, runbooks, and operational procedures - so that the system remains supportable, auditable, and easy to onboard new engineers onto over time.
  • Mentor junior team members and support knowledge transfer across the security team.

Requirements

  • Bachelor’s degree in Computer Science, Engineering, or a related technical discipline.
  • Five or more years of SAP Security / GRC experience in enterprise landscapes.
  • Strong hands-on experience with SAP authorization concepts and role design.
  • Deep experience operating SAP GRC Access Control (ARA, ARM, BRM, EAM).
  • Experience supporting SAP audits and remediation activities.
  • Hands-on experience securing Fiori, BTP, and cloud SAP applications.
  • Familiarity with SAP IDM or third-party IGA tooling.
  • Working knowledge of SAP Process Control.
  • Strong understanding of regulatory frameworks such as SOX, GxP, and PCI.
  • Excellent communication and documentation skills.

About the company

Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:50 min

Introduction and the value of runbooks

Hila Fish · World Congress 2023

3:13 min

Core components of the internal Optimize ecosystem

Dominik Schneider Dominik Schneider · World Congress 2025

1:44 min

Background and career journey in regulated software systems

Martin Hynie · Coffee With Developers

1:32 min

Structuring automated incident workflows between runbooks and raw models

Aram Hakobyan Aram Hakobyan +1 · World Congress 2026 Europe

1:01 min

Reviewing supplementary platform features and secured enterprise environments

Videos

See all

Related articles

See all