Search by job, company or skills

P

Consulting - Manager SAP Security

6-8 Years
new job description bg glownew job description bg glownew job description bg svg
  • Posted 10 days ago
  • Be among the first 10 applicants
Early Applicant

Job Description

About the role

PwC Consulting Indonesia is seeking an experienced SAP Security Manager to lead delivery of SAP user access control, role management, and security & compliance engagements. You will run client projects and internal initiatives that design, implement, and operate secure SAP access controls, role-based access control (RBAC) models, SAP GRC, identity provisioning, and SoD remediation. This is a hands-on, client-facing manager role combining technical expertise, governance knowledge, people leadership, and consulting delivery skills.

What you will do

  • Lead SAP security engagements end-to-end: scoping, design, implementation, testing, go-live and transition to operations.
  • Design and implement role models, PFCG roles, authorization concepts and RBAC frameworks aligned with business processes and segregation of duties (SoD) requirements.
  • Configure, administer and optimize SAP GRC Access Control (AC), Access Risk Analysis (ARA), Business Role Management (BRM) and related modules; lead GRC implementations, upgrades and integrations.
  • Manage user provisioning and lifecycle processes: design target state processes, integrate SAP with identity management systems (SAP IDM, SailPoint, Microsoft Identity Manager), and implement automated provisioning/de-provisioning.
  • Conduct SoD risk analyses, define compensating controls, prioritize and drive remediation plans with business and IT owners.
  • Lead periodic access reviews (user access recertification), attestations and remediation tracking to ensure regulatory and internal policy compliance.
  • Establish and enforce SAP access policies, role change controls, segregation of duties policies, and change management for security artifacts.
  • Provide operational support and incident response for SAP security issues, including investigations into inappropriate access and potential fraud.
  • Work closely with IT security, application teams, BASIS, HR, audit, and business process owners to embed controls and governance into change and release processes.
  • Develop deliverables: security assessments, control matrices, role catalogues, GRC configuration documentation, test scripts, training materials, and status reports.
  • Manage, mentor and grow a team of SAP security consultants and engineers; manage resource allocation, workplans, staffing and people development.
  • Support business development activities: proposal development, solutioning, client presentations and pre-sales technical input.
  • Ensure compliance with local regulations, PwC methodologies and quality standards.

What you'll bring (required)

  • Bachelor's degree in Information Systems, Computer Science, Accounting, Business, or related field.
  • 6+ years of hands-on SAP security experience (authorizations, role design, PFCG) with at least 3 years in a lead/managerial role; 8+ years preferred.
  • Demonstrated experience with SAP GRC Access Control (10.x/12.x) including ARA/BRM/AC workflows and GRC governance processes.
  • Experience with SAP platforms including SAP ECC and S/4HANA security concepts and architecture.
  • Strong understanding of segregation of duties, compliance frameworks and audit requirements (SOX, ISO 27001, local regulations).
  • Practical experience integrating SAP with Identity & Access Management solutions (SAP IDM, SailPoint, CyberArk, AD/Azure AD, Okta).
  • Proven ability to lead client engagements, manage stakeholders, and deliver projects on time and budget.
  • Strong analytical, problem-solving and documentation skills.
  • Excellent communication skills in English and Bahasa Indonesia (written and verbal).
  • Willingness to travel to client sites across Indonesia/region as required.

Preferred qualifications

  • Professional certifications: SAP Certified Technology Associate SAP S/4HANA Security, SAP GRC certification, CISM, CISSP or equivalent.
  • Experience in a consulting environment and track record of successful client engagements.
  • Familiarity with system landscapes, BASIS operations, transport management and cross-system authorization concepts.
  • Knowledge of scripting/automation tools for role creation and analysis (e.g., ABAP basics, SQL, Python) is a plus.
  • Experience working with ERP security for other SAP modules (FI/CO, MM, SD, HCM) and Fiori authorization.

What we offer

  • Opportunity to work on high-impact projects for leading Indonesian and multinational clients.
  • Collaborative, supportive culture with strong focus on professional development, technical training and PwC global networks.
  • Competitive compensation and benefits package, work-life balance initiatives and career progression in a growing SAP security practice.
  • Exposure to diverse technical environments and opportunities to shape security and compliance solutions across industries.

PwC is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 135208039