
SAP GRC and security specialist
- Kuala Lumpur
- Permanent
- Full-time
- Senior in SAP authorizations and GRC.
- You need to be curious to develop your skill in security.
- You will be working on new technologies around security in SAP (S4/Hana, SAP Rise, GRC, Access control, Risk management, supervisory control, Fiori)
- You will work together with auditors and delivery teams to provide robust and secure solutions from an infrastructure and user management perspective.
- You should be able to work individually but team work is very important.
- Be part of a team of SAP specialists managing the enterprise services from the SWIFT
- Maintain and administer the SAP Security environment, including the development, implementation, and management of SAP Security Roles, to establish secure and compliant business processes, utilizing security administration tools in key SAP programs; work with internal team to maintain a secure, compliant environment; remain aware of available security tools.
- Responsible for understanding, translating and communicating governance, risk, and compliance concepts, requirements and practices to stakeholders.
- Assist in the development, implementation and maintenance of programs, processes, and procedures used to support governance, risk, and compliance efforts
- Collaborate with security staff, cross-functional teams and business owners to ensure appropriate role, authorization and access controls are in place that support security governance
- Utilize GRC tools to manage list of external authoritative sources, information technology controls, corporate policies and procedures.
- Perform cyber risk and vulnerability assessment to proactively secure the organization.
- Perform IT Security Reviews
- Collaborate with various business units to understand, resolve or mitigate constraints impacting their operations and their risks associated with GRC controls
- Prepare internal and external audit evidence
- At least 4 or-5 years of professional experience in similar role
- A university or bachelor degree in Computer Science or related disciplines/equivalent work experience
- An understanding of the following topics with hands on experience:
- Security role development and/or maintenance
- Firefighter configuration and maintenance
- GRC request administration
- Cross-System risk analysis configuration
- SAP GRC (12 or higher)
- Mitigating organizational risks (analysing, interpreting, and recommendations)
- SAP authorization concepts
- Segregation of Duties (SOD) with an understanding of business processes and applicable mitigating controls
- Information security baselining and risk frameworks/standards
- Periodic sap security reviews/audits
- Excellent communication skills, knowledge of IT controls, business processes within a financial environment.
- Working within an Agile environment is an asset