Full-Time

Cyber SAP Security and GRC Access & Process Control Manager

Deloitte

Deloitte

10,001+ employees

Global professional services and auditing

Compensation Overview

$130.8k - $241k/yr

+ Bonus

Atlanta, GA, USA

In Person

Category
Consulting (2)
,
Required Skills
SAP Products
Requirements
  • Bachelor’s degree
  • 8+ years of experience with SAP S/4 HANA Security and GRC Access & Process Control
  • Demonstrated delivery of three to five full cycle GRC Access Control implementation projects along with SAP S/4 HANA security implementations and at least two SAP GRC process control implementations
  • 8+ years of hands-on experience implementing security for SAP S/4 HANA, Fiori, Ariba, IBP, BTP, BDC security including requirement gathering, security design and deployment
  • 8+ years of experience in conducting security design workshops and designing, building, testing, and deploying business end user and IT support roles with in-depth knowledge on Fiori applications, Spaces and Pages concepts
  • 3+ years of experience in designing and implementing security for SAP reporting and analytics solutions such as SAP Business Objects, SAP BDC, SAP Cloud Analytics and BW/4HANA
  • 5+ years of experience in collaborating with various stakeholders (business process, development and organization change management workstreams, etc.) to gather business requirements for security
  • 5+ years of experience in designing, configuring and implementing SAP GRC Access Request Analysis (ARA), Access Request Management (ARM), Emergency Access Management (EAM), and Business Role Management (BRM)
  • 5+ years of experience in building and updating Segregation of Duties (SOD) ruleset, configuring ruleset in SAP GRC 12.0 systems and performing SOD risk analysis at user and role level
  • 5+ years of hands-on experience of GRC AC request workflows (e.g., Access Request Management)—request intake, approvals, risk checks, provisioning steps, and evidence trail
  • 3+ years of experience in SAP GRC Process Control design and configuration, Clear understanding of controls, risks, subprocesses, organizations, and assignments within SAP GRC Process Control.
  • 2+ years of experience with the concept of automated/continuous controls and how PC can support monitoring using Continuous Control Monitoring (CCM) - creating business rules, data sources, and scheduling jobs to monitor controls and risks
  • 3+ years of experience with data protection strategies for regulatory controls like privacy, GDPR etc. including implementation of SAP UI masking tool
  • 4+ years of experience with executing vulnerability scans, analyzing the scan results and providing recommendations
  • 3+ years of prior workstream lead experience (plan/budget/staffing, status reporting, team management, stakeholder management)
  • 3+ years of experience with managing and providing oversight for team
  • Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve
  • Limited immigration sponsorship may be available
Responsibilities
  • As a Manager, you will be part of our SAP practice and will be responsible for delivering SAP ECC and S/4 HANA security implementations and assessments. Responsibilities will include assessment, design and implementation of end user security, and/or SAP GRC 10.x/12.0 Access Control.
Desired Qualifications
  • Previous consulting or Big 4 experience preferred
  • Professional certifications such as CISSP, CISM, or CISA is desired
  • Knowledge/experience in SAP identity and access governance (IAG)
  • Excellent written and verbal communication skills
  • Knowledge/experience in cloud security and cloud migrations
  • Knowledge/experience in SAP business process controls
  • Knowledge/experience in data protection tools like NextLabs
  • Knowledge/experience in executing vulnerability management tools like Onapsis
  • Knowledge/experience in identity access management tools
  • Understand leading practices as it relates to SAP Security, and provide recommendations to clients on security role design and implementation
  • Technical understanding of SAP configurations that relate to the design, development, and testing of automated controlsAbility to set up or support self-assessments, test plans, and evidence collection workflows in PC (including tester/approver steps)
  • Knowledge/experience in IT general computer, data conversion and integration controls

What Deloitte does: Deloitte provides professional services to organizations, offering a range of services including consulting, auditing, tax, and advisory work to help clients improve performance and manage risk. How its products work: It blends practical advice with hands-on implementation through a global network of member firms and specialists. Teams assess clients’ needs, develop strategies, and help execute processes, controls, and transformations while upholding professional standards and integrity. How it differs from competitors: It operates at a large scale with a global network of diverse professionals, bringing cross‑disciplinary expertise and a wide range of services to many industries, which allows it to address complex challenges from multiple angles. What its goal is: To help clients and society become stronger by enabling sustainable progress and responsible growth through trusted services and collaboration.

Company Size

10,001+

Company Stage

Late Stage VC

Total Funding

$17.1M

Headquarters

Madrid, Spain

Founded

1845

Simplify Jobs

Simplify's Take

What believers are saying

  • U.S. revenues hit $35.7 billion in FY ended May 31, 2025.
  • Global network enables comprehensive delivery to multinational clients.
  • Strategic alliances advise clients across industries on initiatives.

What critics are saying

  • Fragmented firms isolate liability, damaging brand from misconduct.
  • EY, KPMG undercut AI audit prices, capturing 15-20% Global 500 contracts.
  • Talent exits to Palantir, Accenture halve consulting growth under Anna Marks.

What makes Deloitte unique

  • Deloitte's 470,000 global workforce spans 150 countries for multinational service.
  • Blends business acumen, technology, and alliances for industry future-building.
  • $70.5 billion FY2025 revenue reflects 4.8% growth in local currency.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Deloitte who can refer or advise you

Benefits

Professional Development Budget

Hybrid Work Options

Company News

Business Insider
Jan 29th, 2026
AI forces companies to rethink hiring practices as job applications surge and entry-level pipelines shrink

Business Insider convened 15 HR and C-suite leaders in Davos to discuss how AI is reshaping hiring and talent pipelines. The roundtable, presented by Indeed, revealed growing concerns about entry-level positions and skills assessment. Deloitte's Elizabeth Faber emphasised maintaining a "human-led, technology-powered" approach whilst carefully navigating reduced junior hiring. TCW's Melissa Stolfi noted her firm has downsized its analyst class but maintains a pyramid structure to preserve apprenticeship culture and future leadership pipelines. Indeed's chief economist Svenja Gudell warned that whilst tech employers now demand five-plus years' experience, this creates future talent shortages if junior hiring continues declining. Salesforce's Nathalie Scardino said her company receives two million applications annually and has shifted focus from years of experience to learning aptitude. Manpower Group's Becky Frankiewicz noted AI can process candidates faster whilst reducing bias, potentially unlocking opportunities beyond traditional qualifications.

Yahoo Finance
Jan 20th, 2026
Deloitte to hire 50,000 employees in India, eyes Mangaluru expansion

Deloitte plans to hire 50,000 employees in India and is evaluating Mangaluru, Karnataka, as a potential new location, according to South Asia CEO Romal Shetty. The company currently employs 140,000 people in India, representing one in four Deloitte employees globally. Shetty said India hosts 50% of all global capability centres worldwide, with significant growth potential in Tier II and Tier III cities. He proposed creating digital economic zones integrating GCCs, GPU-based data centres, startups and academic institutions to accelerate expansion. The CEO called for streamlining GCC setup processes from six months to two weeks, whilst acknowledging infrastructure constraints around energy and water for data centres. Shetty noted Mangaluru offers advantages including talent availability and real estate, adding the company's presence there is a matter of timing.

PR Newswire
Oct 31st, 2025
Deloitte Invests in Kihomac for Drones

Deloitte has invested in Kihomac to enhance U.S. drone manufacturing, aiming to strengthen national security and supply chains. This investment will allow Kihomac, a veteran-owned company, to expand production in Utah and mass-produce drones for U.S. government agencies and businesses. Deloitte's support will create manufacturing jobs and secure the supply chain for American customers.

La Tercera
Jul 14th, 2025
Deloitte Acquires Virtus Partners in Chile

Deloitte has acquired 100% of Virtus Partners, founded by Gonzalo and Marcelo Larraguibel, to enhance its strategic consulting business in Chile. This acquisition aims to offer comprehensive solutions from strategy design to execution. Deloitte's CEO, Christian Durán, emphasized the significance of this move in strengthening their market position. The merger combines Deloitte's global capabilities with Virtus Partners' local expertise, offering a unique strategic consulting platform in Chile.

Yahoo Finance
Jul 4th, 2025
Deloitte Canada Acquires Fintech Firm Allevar

Deloitte Canada has acquired Toronto-based fintech firm Allevar, enhancing its capabilities in regulatory compliance and technology solutions. Allevar specializes in fraud management, AML, payment systems, and KYC regulations, crucial for Canadian banks and the financial services industry. Allevar's leadership, including CEO Dan Wood, will join Deloitte's Regulatory Risk practice. This acquisition aligns with Deloitte's strategy for growth in the digital and AI age.