Senior Associate, SAP Security & GRC
Job Summary
We are the leading provider of professional services to the middle market globally our purpose is to instill confidence in a world of change empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled inclusive culture and talent experience and our ability to be compelling to our clients. Youll find an environment that inspires and empowers you to thrive both personally and professionally. Theres no one like you and thats why theres nowhere like RSM.
RSM US Integrated Services India Private Limited supports RSM U.S. engagement teams across risk consulting transaction advisory technical accounting financial consulting technology and management consulting tax and assurance by providing access to skilled professionals across an extended business day. RSM US Integrated Services India Private Limited is a member of RSM International the sixth largest global network of independent accounting tax and consulting firms. RSMs vision is to be the first-choice advisor to middle market leaders globally.
Risk Consulting helps clients address complex strategic operational compliance technology and governance challenges across dynamic business environments. The practice provides services across ERP advisory automation and analytics internal audit SOX advisory IT and technology audits cybersecurity risk management third-party risk management SOC1/SOC2 governance risk and compliance privacy and security risk managed security services digital forensics incident response and related risk advisory areas.
The Business Application Risk Solutions (BARS) practice supports consulting internal audit and external audit clients by bringing deep ERP process automation data analytics security controls and governance capabilities. The ERP risk practice focuses on governance risk security and compliance across the full lifecycle of core business applications from implementation through steady-state operations.
About the Role
We are seeking an experienced SAP Security GRC and Controls Integration professional to help lead and scale the SAP Security and GRC capability within the BARS practice. The role will involve leading client engagements overseeing delivery quality developing team capability supporting practice growth and working closely with U.S. and India leadership.
The ideal candidate should be able to think strategically about risk controls and access governance while also being hands-on and delivery-focused. This role requires experience scoping supervising and executing SAP implementation risk assessments SAP Security SAP GRC segregation of duties controls transformation process automation data analytics continuous controls monitoring and managed services engagements.
Qualification and Minimum Entry Requirements
- Bachelors or masters degree in Engineering Technology Information Systems Business Finance or a related discipline.
- Minimum 4 years of professional experience in SAP Security SAP GRC and IT controls.
- Prior experience with a public accounting firm large consulting organization or global delivery environment is preferred.
- Deep expertise in SAP Security across SAP ECC and SAP S/4HANA including authorization concepts role design authorization object analysis access troubleshooting Fiori authorizations and access remediation.
- Strong hands-on experience with SAP GRC Access Control including ARA ARM EAM BRM MSMP workflows BRF connectors synchronization jobs ruleset maintenance risk analysis and mitigation controls.
- Practical experience with SAP GRC Process Control including control design automated monitoring business rules data sources control testing and continuous controls monitoring is a plus.
- Experience leading complex SAP Security and GRC engagements across implementation transformation assessment optimization controls and managed services programs.
- Experience managing delivery teams reviewing work products mentoring resources and building technical capability within SAP Security and GRC teams.
- Exposure to other GRC identity governance access management compliance control monitoring or risk management tools will be an added advantage.
- Exposure to SAP Joule SAP BTP SAP IAG SAP Cloud Identity Services automation analytics AI-enabled controls and emerging SAP technologies would be beneficial.
- Experience with SAP HANA BW/BI Ariba IBP MDG SuccessFactors BDC SAC or other SAP public cloud and integrated applications will be preferred.
- Experience with SOX COSO COBIT ISO NIST HIPAA FDA and other IT controls methodologies and frameworks is a plus.
- Strong project management stakeholder management communication analytical thinking problem-solving and leadership skills.
- Demonstrated ability to work in high-pressure client delivery environments while managing competing priorities and maintaining quality standards.
- Excellent verbal written and interpersonal communication skills in English as the position requires frequent communication with RSM International clients.
- Relevant certifications such as SAP Security SAP GRC CISA CRISC CISSP CISM or equivalent certifications will be preferred.
Position and Key Responsibilities
- Help lead the SAP Security and GRC team within the Business Application Risk Solutions practice and support capability growth across delivery people development methodologies and market-facing initiatives.
- Lead end-to-end SAP Security and GRC engagements across implementation transformation assessment optimization controls transformation and managed services programs.
- Manage SAP Security workstreams in SAP ECC and SAP S/4HANA environments including requirements gathering solution design role build testing deployment cutover hypercare and post-go-live support.
- Lead SAP Security design and access governance activities including role design role redesign authorization troubleshooting Fiori authorizations SoD analysis sensitive access reviews emergency access management user access reviews and access remediation.
- Lead SAP GRC Access Control implementation and enhancement activities across ARA ARM EAM BRM MSMP workflows BRF ruleset design risk analysis mitigation controls connectors synchronization jobs and related GRC configuration activities.
- Support SAP GRC Process Control initiatives including control framework mapping risk and control configuration automated monitoring business rules data sources control testing and continuous controls monitoring.
- Translate business process compliance audit and internal control requirements into practical SAP Security and GRC solutions aligned with client risk and regulatory requirements.
- Advise clients on SAP Security and access governance considerations across integrated SAP landscapes including Fiori HANA BW/BI BTP Ariba IBP MDG SuccessFactors and other SAP applications as applicable.
- Manage client stakeholders engagement plans project timelines issue resolution deliverable quality and team performance across multiple concurrent engagements.
- Provide a first-choice advisor experience to clients by delivering practical recommendations maintaining strong client relationships and ensuring high-quality engagement outcomes.
- Develop reusable methodologies solution accelerators delivery templates training materials knowledge repositories and other practice assets to support consistent and scalable delivery.
- Maintain awareness of emerging SAP technologies including SAP Joule SAP BTP SAP IAG SAP Cloud Identity Services automation analytics and AI-enabled risk and controls solutions.
- Ensure engagement documentation deliverables and work products are compliant with firm quality standards and demonstrate sound professional judgment.
- Experience working with a team to provide services to numerous clients simultaneously.
- Must exhibit and have demonstrated excellent organization and project management communication interpersonal and team collaboration skills.
Professional Conduct and Firm Expectations
- Successfully integrate the strategy and core values of the firm.
- Heighten the firm brand by demonstrating thought leadership and embracing the firms marketing campaigns and related programs supported by the firm.
- Professionally presents themselves at all times at the office and the clients meetings. This includes but is not limited to appearance communication and actions.
- Exercise professional skepticism maintain confidentiality and adhere to applicable professional standards firm policies and code of ethics while delivering client engagements.
- Work collaboratively as a part of the team and communicate effectively with RSM consulting professionals supervisors and senior management in the U.S. on a daily basis.
At RSM we offer a competitive benefits and compensation package for all our offer flexibility in your schedule empowering you to balance lifes demands while also maintaining your ability to serve more about our total rewards at
RSM does not tolerate discrimination and/or harassment based on race; colour; creed; sincerely held religious beliefs practices or observances; sex (including pregnancy or disabilities related to nursing); gender (including gender identity and/or gender expression); sexual orientation; HIV Status; national origin; ancestry; familial or marital status; age; physical or mental disability; citizenship; political affiliation; medical condition (including family and medical leave); domestic violence victim status; past current or prospective service in the Indian Armed Forces; Indian Armed Forces Veterans and Indian Armed Forces Personnel status; pre-disposing genetic characteristics or any other characteristic protected under applicable provincial employment legislation.
Accommodation for applicants with disabilities is available upon request in connection with the recruitment process and/or employment/ is committed to providing equal opportunity and reasonable accommodation for people with disabilities. If you require a reasonable accommodation to complete an application interview or otherwise participate in the recruiting process please send us an email at .
Required Experience:
Senior IC
About Company
RSM US LLP is the leading U.S. provider of assurance, tax and consulting services focused on the middle market.