> Markdown version of [/jobs/ext/2229698-sap-security-manager](https://www.wearedevelopers.com/jobs/ext/2229698-sap-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SAP Security Manager - **Company:** Oldcastle, Inc - **Location:** Atlanta, GA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** SAP Cloud, Microsoft Word, Microsoft Excel, Microsoft Outlook, Cloud Computing, Data Integration, Identity and Access Management, Microsoft PowerPoint, SuccessFactors, SAP (Applications), SAP GRC, SAP Human Resource Management Software, SAP Project Management, SAP Security, IT General Controls (ITGC), Software Security, SAP Business Technology Platform, Sap Fiori, SAPBasis, SAP S/4HANA, Servicenow - **Published:** August 25, 2026 - **Apply:** https://www.disabledperson.com/jobs/74521260-sap-security-manager ## About the Role * 12+ years of SAP security experience, including GRC access control, ECC/S4/Fiori, and SuccessFactors, with 3+ years in a people-management or team-lead role * Extensive hands-on experience with security design, role creation and maintenance, and role-to-user assignment * In-depth understanding of security rules and controls implementation, including SoD governance * Experience with GRC access control configuration and automation * Experience securing SAP BTP, and preferably Datasphere and SAP Analytics Cloud (SAC) within a Business Data Cloud (BDC) environment * Experience managing security for SuccessFactors Employee Central (EC) and Employee Central Payroll (ECP) * Experience with ServiceNow (or similar) - SAP GRC integration for access request management preferred * Experience supporting internal and external ITGC/SOX audits * Participated in at least two SAP full-cycle implementations and/or functional upgrade projects * Demonstrated experience managing SI/AMS vendor relationships, contracts, and SLAs * Excellent communication and stakeholder-management skills, with the ability to engage executives, auditors, and cross-functional partners * Strong analytical and problem-solving skills, with demonstrated ability to lead through ambiguity and shifting priorities * Bachelor's/University degree or equivalent experience * SAP Security/GRC training and certification preferred Work Requirements * Must have expert proficiency in Microsoft Word, Excel, PowerPoint, and Outlook * Must be 18 years of age or older * Must pass pre-employment drug screen and criminal background check * Strict adherence to safety requirements and procedures as outlined in the Employee Handbook * Willingness to work independently and collaboratively, and to lead a team through evolving priorities * Must be willing to travel and work away from home when required * The position may require work outside of normal business hours Knowledge/Skill Requirements * Strong leadership skills with the ability to build, motivate, and retain a high-performing team * Excellent technical and analytical skills with the credibility to guide security design decisions * Self-motivated with the ability to operate independently and manage competing priorities * Demonstrated close attention to detail and accuracy in a compliance-sensitive environment * Proactive problem solver able to anticipate risks and drive timely resolution * Ability to lead effectively in a changing environment and manage organizational change * Strong interpersonal skills to build effective relationships across IT, business, audit, and vendor organizations ## Description We are seeking an experienced SAP Security Manager to lead application security and GRC across our full SAP landscape, including SAP S/4HANA, SAP Business Technology Platform (BTP) and Business Data Cloud (BDC) - including Datasphere and SAP Analytics Cloud - and SuccessFactors (Employee Central and Employee Central Payroll). This role owns the strategy and governance for role design, access provisioning, and controls across all in-scope platforms, leads a team of security and GRC professionals, and manages the end-to-end security request process through the ServiceNow-SAP GRC integration. The ideal candidate combines deep SAP security and GRC expertise with proven people-management experience and is comfortable representing security in audits, projects, and executive-level discussions., * Hire, lead, mentor, and develop a team of SAP Security and GRC Leads/Analysts, setting goals and career development plans * Establish coverage models and escalation paths to support security incidents and access requests across all in-scope platforms * Build a culture of accountability and continuous improvement within the security team Security & GRC Strategy and Governance * Own the strategy for application security design and GRC access control configuration across SAP projects and enhancements * Establish and govern the centralized process for role administration and role design for functional (order to cash, procure to pay, record to report) and cross-functional (reporting, IT, testing) processes * Set standards for security rules, controls, and role-to-user assignment across all production and non-production systems * Own GRC ruleset design, segregation-of-duties (SoD) governance, and post-go-live maintenance in partnership with SI/AMS partners * Own GRC Firefighter (emergency access) governance, including assignment, approval, and periodic review processes Platform-Specific Security Ownership * Own security and access governance for SAP BTP, including Datasphere and SAP Analytics Cloud (SAC), as part of Business Data Cloud (BDC) * Own security for SuccessFactors modules in use, including Employee Central (EC) and Employee Central Payroll (ECP), ensuring appropriate role design and data privacy controls for sensitive HR and payroll data * Ensure consistent security governance across SAP S/4HANA, Fiori, BTP/BDC, and SuccessFactors, and drive alignment on cross-platform identity and access strategy Access Request Management (ServiceNow - SAP GRC Integration) * Own the end-to-end security request lifecycle managed through the ServiceNow-SAP GRC integration, from intake through approval, provisioning, and review * Partner with the ServiceNow platform team to maintain and improve the integration, ensuring requests, approvals, and audit trails remain accurate and reliable * Monitor SLAs for access request turnaround and drive process improvements to reduce cycle time and manual intervention Audit, Compliance & Risk * Ensure SOX ITGC security controls are designed, operating effectively, and evidenced for internal and external audits * Train control owners on performing user access reviews and ensure timely completion * Own license compliance activities, including user counts, license type assignment, and data consolidation for license audits * Provide audit evidence and serve as the primary point of contact for internal and external auditors on SAP security matters Vendor & Stakeholder Management * Manage SI/AMS partners delivering security-related project and support activities, holding them accountable to SLAs and quality standards * Approve security changes across all functional modules, ensuring alignment with organizational standards and change management processes * Provide regular status, risk, and compliance reporting to senior leadership and program stakeholders * Partner with the Basis and Development managers to ensure security is embedded across infrastructure and development practices ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Replacing Excel with SAP APIs & Python validation](https://www.wearedevelopers.com/videos/1944-replacing-excel-with-sap-apis-python-validation) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Companies to Work For in Berlin: Top 14 Companies in 2023 ](https://www.wearedevelopers.com/magazine/188-best-companies-to-work-for-in-berlin-top-14-companies-in-2023) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Companies to Work For in Germany: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/33-best-companies-to-work-for-in-germany-top-25-companies-in-2023) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)