SAP Security Engineer (GRC - Technical)

Bright Vision Technologies

Remote

Full-time

Posted 11 days ago


Job description

Job Summary:
Bright Vision Technologies is a forward-thinking software development company dedicated to building innovative solutions that help businesses automate and optimize their operations. They are seeking an experienced SAP Security Engineer (GRC – Technical) to design, implement, and operate security and access-control frameworks for complex SAP landscapes.
Responsibilities:
• Design and maintain SAP authorization concepts and role structures aligned with business processes and least-privilege principles
• Build and maintain master, derived, composite, and business roles for S/4HANA, ECC, and Fiori applications
• Configure and operate SAP GRC Access Control (ARA, ARM, BRM, EAM), including ruleset management, mitigating controls, and emergency access management
• Perform segregation-of-duties analysis and remediation in collaboration with business process owners and internal audit
• Configure user provisioning workflows in SAP GRC ARM, including request types, approval paths, and integration with IDM/IAM platforms
• Operate SAP GRC Process Control for continuous controls monitoring and policy management
• Implement security for Fiori applications, including catalogs, groups, and front-end authorizations
• Configure and operate security for SAP BTP and cloud applications using XSUAA, IAS, and IPS
• Support SAP audits (SOX, GxP, PCI) and respond to audit findings with documented remediation plans
• Implement transport security, table logging, and audit logging in line with internal security policies
• Monitor and remediate SAP Security Notes in coordination with Basis and DBA teams
• Maintain comprehensive, current technical documentation — including architecture diagrams, design decisions, configuration references, runbooks, and operational procedures — so that the system remains supportable, auditable, and easy to onboard new engineers onto over time
• Mentor junior team members and support knowledge transfer across the security team
Qualifications:
Required:
• Bachelor’s degree in Computer Science, Engineering, or a related technical discipline
• Five or more years of SAP Security / GRC experience in enterprise landscapes
• Strong hands-on experience with SAP authorization concepts and role design
• Deep experience operating SAP GRC Access Control (ARA, ARM, BRM, EAM)
• Experience supporting SAP audits and remediation activities
• Hands-on experience securing Fiori, BTP, and cloud SAP applications
• Familiarity with SAP IDM or third-party IGA tooling
• Working knowledge of SAP Process Control
• Strong understanding of regulatory frameworks such as SOX, GxP, and PCI
• Excellent communication and documentation skills
Preferred:
• SAP-certified Security or GRC credentials
• Experience with SAP Cloud Identity services (IAS, IPS) and SCIM-based integrations
• Familiarity with HANA security and analytic privileges
• Experience with continuous controls monitoring frameworks
• Exposure to SAP RISE / Grow security operating models
Company:
Bright Vision Technologies is an information technology company that offers software development, AI, and cybersecurity services. Founded in 2020, the company is headquartered in Bridgewater, USA, with a team of 51-200 employees. The company is currently Growth Stage.


Frequently asked questions

Q: What skills or qualities help someone succeed as a SAP GRC Security?

A: To succeed as a SAP GRC Security professional, key technical skills include expertise in SAP GRC modules, such as Access Control, Risk Management, and Compliance Management, as well as proficiency in SAP security tools and technologies like SAP NetWeaver and SAP Identity Management. Additionally, strong analytical, problem-solving, and communication skills are essential for effective risk assessment, policy development, and stakeholder engagement. These technical and soft skills enable SAP GRC Security professionals to design and implement robust security controls, mitigate risks, and ensure compliance, ultimately driving business growth and success.

Q: What is the career path for a SAP GRC Security?

A: A typical career path for a SAP GRC Security professional involves starting as a GRC Security Analyst, where they implement and configure security controls, followed by a mid-level role as a GRC Security Consultant, where they design and implement security solutions for clients or within their organization. As they gain experience, they can progress to senior roles such as a GRC Security Architect or a GRC Security Manager, where they oversee the development and implementation of comprehensive security strategies. Throughout their career, SAP GRC Security professionals can develop skills in areas like risk management, compliance, and IT security, which can lead to opportunities in related fields like IT audit, compliance, or cybersecurity.



Bright Vision Technologies job posting for a SAP Security Engineer (GRC - Technical) in Remote, US with a salary of $72 to $82 Hourly with a map of Remote location.