> Markdown version of [/jobs/ext/222421-sap-security-engineer-grc-technical](https://www.wearedevelopers.com/jobs/ext/222421-sap-security-engineer-grc-technical). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SAP Security Engineer (GRC - Technical) - **Company:** Bright Vision Technologies - **Location:** Fremont, CA, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** SAP Cloud, Audit Trail, Cloud Computing, Identity and Access Management, SuccessFactors, Runbook, SAP (Applications), SAP NetWeaver Business Warehouse, SAP GRC, SAP HANA, SAP Security, User Provisioning Software, Data Logging, RISE with SAP, SAP Business Technology Platform, Sap Fiori, SAPBasis, Information Technology, SAP S/4HANA, GXP - **Published:** May 20, 2026 - **Apply:** https://www.careerjet.com/jobad/us7efaa09ff025fecc15b47de218358cca ## About the Role * Bachelor's degree in Computer Science, Engineering, or a related technical discipline. * Five or more years of SAP Security / GRC experience in enterprise landscapes. * Strong hands-on experience with SAP authorization concepts and role design. * Deep experience operating SAP GRC Access Control (ARA, ARM, BRM, EAM). * Experience supporting SAP audits and remediation activities. * Hands-on experience securing Fiori, BTP, and cloud SAP applications. * Familiarity with SAP IDM or third-party IGA tooling. * Working knowledge of SAP Process Control. * Strong understanding of regulatory frameworks such as SOX, GxP, and PCI. * Excellent communication and documentation skills. Preferred Qualifications * SAP-certified Security or GRC credentials. * Experience with SAP Cloud Identity services (IAS, IPS) and SCIM-based integrations. * Familiarity with HANA security and analytic privileges. * Experience with continuous controls monitoring frameworks. * Exposure to SAP RISE / Grow security operating models. ## Description As we continue to grow, we're looking for a skilled SAP Security Engineer (GRC - Technical) to join our dynamic team and contribute to our mission of transforming business processes through technology., This role is part of Bright Vision Technologies' in-house Statement of Work (SOW) engagement. The client, end customer, and employer for this position is Bright Vision Technologies - there is no third-party client, vendor, or implementation partner involved. We do not engage in C2C, 1099, or third-party arrangements for this role. BUT STRICTLY NO C2C/1099/3RD PARTY COMPANIES. ALL OUR ROLES ARE W2 AND NO 3RD PARTY BROKERING PLEASE. Candidates must be willing to work directly as a full-time W2 employee of Bright Vision Technologies and contribute to our in-house SOW deliverables. No new H1B sponsorship is available for this role. However, candidates who are currently on a valid H1B visa and require a transfer are welcome to apply. We will support H1B transfers for qualified candidates. For every role, a technical coding assessment is mandatory. Please apply only if you are confident in your technical abilities and hands-on experience., We are seeking an experienced SAP Security and GRC (Governance, Risk, and Compliance) Engineer to design, implement, and operate security and access-control frameworks for complex SAP landscapes, including S/4HANA, ECC, BW/4HANA, Fiori, BTP, and SuccessFactors. In this role you will be responsible for SAP role design, user provisioning, segregation-of-duties analysis, audit support, and the technical operation of SAP GRC suites. The ideal candidate will combine deep expertise in SAP authorization concepts with strong hands-on experience operating SAP GRC Access Control and Process Control, and will partner closely with audit, compliance, and business teams to deliver a secure, auditable SAP environment. Key Responsibilities * Design and maintain SAP authorization concepts and role structures aligned with business processes and least-privilege principles. * Build and maintain master, derived, composite, and business roles for S/4HANA, ECC, and Fiori applications. * Configure and operate SAP GRC Access Control (ARA, ARM, BRM, EAM), including ruleset management, mitigating controls, and emergency access management. * Perform segregation-of-duties analysis and remediation in collaboration with business process owners and internal audit. * Configure user provisioning workflows in SAP GRC ARM, including request types, approval paths, and integration with IDM/IAM platforms. * Operate SAP GRC Process Control for continuous controls monitoring and policy management. * Implement security for Fiori applications, including catalogs, groups, and front-end authorizations. * Configure and operate security for SAP BTP and cloud applications using XSUAA, IAS, and IPS. * Support SAP audits (SOX, GxP, PCI) and respond to audit findings with documented remediation plans. * Implement transport security, table logging, and audit logging in line with internal security policies. * Monitor and remediate SAP Security Notes in coordination with Basis and DBA teams. * Maintain comprehensive, current technical documentation - including architecture diagrams, design decisions, configuration references, runbooks, and operational procedures - so that the system remains supportable, auditable, and easy to onboard new engineers onto over time. * Mentor junior team members and support knowledge transfer across the security team. ## Related Videos - [Blueprints for Success: Steering a Global Data & AI Architecture](https://www.wearedevelopers.com/videos/1577-blueprints-for-success-steering-a-global-data-ai-architecture) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Remote Driving on Plant Grounds with State-of-the-Art Cloud Technologies](https://www.wearedevelopers.com/videos/251-remote-driving-on-plant-grounds-with-state-of-the-art-cloud-technologies) - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Best Companies to Work For in Berlin: Top 14 Companies in 2023 ](https://www.wearedevelopers.com/magazine/188-best-companies-to-work-for-in-berlin-top-14-companies-in-2023)