About this role
About the Role The SAP Security & Compliance Specialist is responsible for maintaining the integrity, confidentiality, and availability of BRP’s SAP Security landscape while ensuring continuous compliance with corporate governance and regulatory requirements (SOX ITGC, NIST CSF, ISO 27001). This role provides operational and governance support for SAP access management, controls monitoring (SOX), and audit readiness, in close collaboration with the IT Compliance, Internal Audit, and SAP Security teams. What You'll Do
- SAP Security & Access Control: Manage and maintain SAP user access, roles, and authorizations in alignment with the principle of Least Privilege and Segregation of Duties (SoD). Support configuration, monitoring, and operation of SAP GRC Access Control components: ARA, ARM, EAM, BRM. Review and remediate SoD conflicts and critical access risks across SAP environments (ECC, S/4HANA, BW, Fiori). Participate in SAP system audits, ensuring all key security controls are implemented and tested effectively.
- IT SOX (ITGC) Control Monitoring: Execute periodic testing and validation of IT General Controls (ITGCs) in SAP and related systems (e.g., user provisioning, role changes, privileged access, and system configuration). Provide audit evidence, walkthroughs, and documentation to support both internal and external auditors. Identify control gaps, recommend remediation plans, and track corrective actions to closure. Support continuous monitoring of control effectiveness and compliance dashboards in collaboration with GRC teams.
- Compliance & Governance: Align SAP security practices with global frameworks and standards such as NIST CSF, ISO 27001, and COBIT. Maintain up-to-date documentation for control design, process workflows, and risk assessments. Assist in defining and maintaining SAP Security Policies, Standards, and Guidelines. Contribute to the development and automation of compliance reporting through tools such as Power BI, GRC dashboards, and audit management platforms.
- Collaboration & Advisory: Partner with IT, Cybersecurity, and Business Process Owners to ensure that SAP controls are integrated within business processes. Provide advisory support to projects impacting SAP environments (e.g., S/4HANA migrations, system integrations, or cloud deployments). Act as a liaison between InfoSec GRC, Internal Audit, and external auditors.