RSM · Posted 3 days ago
Senior Associate, SAP Security & GRC
The posting
key requirement, as the employer wrote it
We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential.
Our exceptional people are the key to our unrivaled, inclusive culture and talent experience and our ability to be compelling to our clients.
You’ll find an environment that inspires and empowers you to thrive both personally and professionally.
There’s no one like you and that’s why there’s nowhere like RSM.
RSM US Integrated Services India Private Limited supports RSM U.S. engagement teams across risk consulting, transaction advisory, technical accounting, financial consulting, technology and management consulting, tax, and assurance by providing access to skilled professionals across an extended business day.
RSM US Integrated Services India Private Limited is a member of RSM International, the sixth largest global network of independent accounting, tax, and consulting firms.
RSM’s vision is to be the first-choice advisor to middle market leaders globally.
Risk Consulting helps clients address complex strategic, operational, compliance, technology, and governance challenges across dynamic business environments.
The practice provides services across ERP advisory, automation and analytics, internal audit, SOX advisory, IT and technology audits, cybersecurity risk management, third-party risk management, SOC1/SOC2, governance risk and compliance, privacy and security risk, managed security services, digital forensics, incident response, and related risk advisory areas.
The Business Application Risk Solutions (BARS) practice supports consulting, internal audit, and external audit clients by bringing deep ERP, process automation, data analytics, security, controls, and governance capabilities.
The ERP risk practice focuses on governance, risk, security, and compliance across the full lifecycle of core business applications, from implementation through steady-state operations.
About the Role We are seeking an experienced SAP Security, GRC, and Controls Integration professional to help lead and scale the SAP Security and GRC capability within the BARS practice.
The role will involve leading client engagements, overseeing delivery quality, developing team capability, supporting practice growth, and working closely with U.S. and India leadership.
The ideal candidate should be able to think strategically about risk, controls, and access governance, while also being hands-on and delivery-focused.
This role requires experience scoping, supervising, and executing SAP implementation risk assessments, SAP Security, SAP GRC, segregation of duties, controls transformation, process automation, data analytics, continuous controls monitoring, and managed services engagements.
Qualification and Minimum Entry Requirements Bachelor’s or master’s degree in Engineering, Technology, Information Systems, Business, Finance, or a related discipline.
Minimum 4 years of professional experience in SAP Security, SAP GRC and IT controls.
Prior experience with a public accounting firm, large consulting organization, or global delivery environment is preferred.
Deep expertise in SAP Security across SAP ECC and SAP S/4HANA, including authorization concepts, role design, authorization object analysis, access troubleshooting, Fiori authorizations, and access remediation.
Strong hands-on experience with SAP GRC Access Control, including ARA, ARM, EAM, BRM, MSMP workflows, BRF+, connectors, synchronization jobs, ruleset maintenance, risk analysis, and mitigation controls.
Practical experience with SAP GRC Process Control, including control design, automated monitoring, business rules, data sources, control testing, and continuous controls monitoring is a plus.
Experience leading complex SAP Security and GRC engagements across implementation, transformation, assessment, optimization, controls, and managed services programs.
Experience managing delivery teams, reviewing work products, mentoring resources, and building technical capability within SAP Security and GRC teams.
Exposure to other GRC, identity governance, access management, compliance, control monitoring, or risk management tools will be an added advantage.
Exposure to SAP Joule, SAP BTP, SAP IAG, SAP Cloud Identity Services, automation, analytics, AI-enabled controls, and emerging SAP technologies would be beneficial.
Experience with SAP HANA, BW/BI, Ariba, IBP, MDG, SuccessFactors, BDC, SAC, or other SAP public cloud and integrated applications will be preferred.
Experience with SOX, COSO, COBIT, ISO, NIST, HIPAA, FDA, and other IT controls methodologies and frameworks is a plus.
Strong project management, stakeholder management, communication, analytical thinking, problem-solving, and leadership skills.
Demonstrated ability to work in high-pressure client delivery environments while managing competing priorities and maintaining quality standards.
Excellent verbal, written, and interpersonal communication skills in English, as the position requires frequent communication with RSM International clients.
Relevant certifications such as SAP Security, SAP GRC, CISA, CRISC, CISSP, CISM, or equivalent certifications will be preferred.
Position and Key Responsibilities Help lead the SAP Security and GRC team within the Business Application Risk Solutions practice and support capability growth across delivery, people development, methodologies, and market-facing initiatives.
Lead end-to-end SAP Security and GRC engagements across implementation, transformation, assessment, optimization, controls transformation, and managed services programs.
Manage SAP Security workstreams in SAP ECC and SAP S/4HANA environments, including requirements gathering, solution design, role build, testing, deployment, cutover, hypercare, and post-go-live support.
Lead SAP Security design and access governance activities, including role design, role redesign, authorization troubleshooting,
RSM
- Open roles in India
- 122
- Hiring in
- Hyderabad, Bengaluru, Gurugram, Kolkata
- Applications through
- Workday
Counted from the roles we read off RSM's own hiring page today.
No open company record matched this employer by name with certainty, so none is shown — a wrong company's facts would be worse than none.