Lead Architect-SAP Security
Job Summary
Organization: Novo Nordisk Global Business Services (GBS)
At Novo Nordisk our SAP landscape underpins critical business and regulated processes globally spanning Finance Supply Chain Manufacturing Quality and R&D. As we continue our S/4HANA transformation journey and expand our SAP Business Technology Platform (BTP) footprint we are looking for an exceptional SAP Security Architect to lead and own our end-to-end SAP security strategy architecture and governance.
If you are an expert in SAP security authorisations and SAP cyber risk management with a proven track record of designing enterprise-grade SAP security architectures across S/4HANA BW/HANA HANA DB Fiori and BTP we want to hear from you.
This is a individual contributor and leadership role with significant scope influence and visibility across the organisation.
SAP security architecture & strategy
- Define and own the SAP security architecture (on-prem and cloud) including target-state design standards reference architectures and implementation roadmaps.
- Drive security-by-design across SAP programs (new implementations rollouts upgrades and S/4HANA transformations).
- Engage with technical and compliance SMEs business stakeholders and vendors to shape direction and delivery outcomes.
- Present SAP security posture risks and roadmap to senior leadership and the CISO organisation.
Authorisation design & implementation (core)
- Lead the design and implementation of SAP authorisation concepts and role-based access control (RBAC) across end-to-end business processes (e.g. Finance Supply Chain Manufacturing Quality HR BW ATTP GBT).
- Establish and govern role design methodology (business roles derived roles org-level strategy SU24 governance naming conventions firefighter strategy).
- Streamline and govern role lifecycle processes (intake build testing approvals transport periodic review and recertification).
- Govern change management and transport security processes to ensure integrity of the SAP security landscape.
S/4HANA Fiori & modern UX security
- Secure SAP Fiori front-end and SAP Gateway (catalogs/groups/spaces/pages concepts OData service authorisations UI/service hardening).
- Design secure authentication and SSO patterns (SAML2/OAuth2 SNC/Kerberos MFA integration where applicable).
- Design and implement SAP BTP security models (subaccount structure entitlements role collections XSUAA destinations Cloud Connector considerations).
- Integrate SAP BTP with enterprise identity providers and SAP cloud identity services (IAS/IPS) and define secure onboarding patterns.
- Define API security standards and integration security patterns for SAP Integration Suite PI/PO and other middleware components.
- Own security design for BW on HANA / BW/4HANA (analysis authorisations data access controls authorization-relevant objects).
- Design HANA database security (users/roles privileges schemas auditing encryption options secure connectivity patterns).
Governance Risk & Compliance (GRC) audits & controls
- Lead SAP security controls design and operationalization for internal/external audits (SOX/ITGC and other control frameworks) including evidence readiness and remediation plans.
- Drive Segregation of Duties (SoD) design and remediation emergency access controls and continuous control monitoring.
- Partner with cybersecurity teams to align SAP controls to enterprise security requirements (logging/monitoring vulnerability management hardening incident response playbooks for SAP).
- Lead SAP security controls design and operationalization for internal and external audits including SOX/ITGC GxP/CSV (Computerized System Validation) and other applicable control frameworks.
- Ensure security documentation readiness for GxP-validated SAP systems including User Requirement Specifications (URS) Functional Specifications (FS) and Requirements Traceability Matrices (RTM).
- Leverage SAP security tooling (e.g. SAP EarlyWatch Alert Security Bridge Onapsis or equivalent) for continuous vulnerability management and security monitoring.
- Provide technical leadership to SAP security teams (onshore/offshore) coach senior analysts and review solution designs and deliverables.
- Define and track key security metrics including SoD violation reduction audit finding remediation rates role design quality and security architecture coverage.
Qualifications
To be successful in this role you should have:
- Bachelors degree in engineering Computer Science or related field.
- 1520 years of relevant SAP Security experience including several full lifecycle implementations and global rollouts.
- Deep hands-on expertise in SAP authorizations and security administration across key SAP modules (S/4 BW ATTP GBT) and business processes.
- Strong experience with S/4HANA security and role redesign.
- Strong experience in SAP audit/security and compliance initiatives such as SoD remediation SOX and ITGC.
- Proven SAP cybersecurity experience (risk assessments secure configuration/hardening security logging/monitoring integration vulnerability remediation coordination).
- Consulting background strongly preferred; Big 4 consulting experience is highly desirable.
- Ability to work with senior stakeholders and translate business requirements into secure scalable access designs.
- Excellent communication skills in written and spoken English.
Nice to have (common for SAP Security Architect roles)
- Experience with SAP GRC Access Control and/or SAP Cloud Identity Access Governance.
- Security certifications (e.g. CISSP CISA CISM CRISC) and/or SAP security-related certifications.
- Experience in regulated environments (e.g. GxP) and validated system landscapes.
- Experience with SAP security vulnerability management tools (e.g. SecurityBridge Onapsis Relevant).
Working at Novo Nordisk
Every day we seek the solutions that defeat serious chronic diseases. To do this we approach our work with determination constant curiosity and a commitment to finding better ways forward. For over 100 years this dedication has driven us to build a company focused on lasting change for long-term health. One where diverse thinking shared purpose and mutual respect come together to create extraordinary this role youll be at the forefront of our digital transformation ensuring the security and integrity of systems that directly impact millions of patients globally. When you join us youre not just starting a job youre becoming part of a story that spans generations.
Deadline : 26 May 2026 (Applications are reviewed on an ongoing basis).
We commit to an inclusive recruitment process and equality of opportunity for all our job applicants.
At Novo Nordisk were not chasing quick fixes were creating lasting change for long-term health. For over 100 years weve been driven by a single purpose: to defeat serious chronic diseases and help millions of people live healthier lives. This dedication fuels our constant curiosity and inspires us to push the boundaries of whats possible in healthcare. We embrace diverse perspectives seek out bold ideas and build partnerships rooted in shared purpose. Together were making healthcare more accessible treating and preventing diseases and pioneering solutions that create change spanning generations. When you join us you become part of something bigger a legacy of impact that reaches far beyond today.
Required Experience:
Staff IC
About Company
You will be part of the Gulf Cluster sales team based in Qatar. You will report to the Country Sales Manager. The local team consists of approx 10 employees, and has highly-engaged and experienced members that are looking for a new teammember.