SAP Security & GRC Analyst
spe · Mumbai, India · On-site
Posted Sep 1, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Location:
India – Remote (preference for candidates based in Mumbai, Ahmedabad or Bangalore, with occasional travel to our Mumbai office).
Employment Type:
Permanent, Full-time
Role Overview:
We are seeking an experienced SAP Security & GRC Analyst to join our team in a permanent, full-time position based in India. This role can be performed remotely from within India, with a preference for candidates based in Mumbai, Ahmedabad or Bangalore. Candidates should be willing and able to travel occasionally to our Mumbai office.
The successful candidate will have 3–5 years of hands-on experience in SAP Security, authorization management, SAP GRC Access Control, and security support across modern SAP environments.
You will be responsible for supporting and maintaining secure, compliant, and business-aligned access across the SAP landscape, including SAP S/4HANA, Fiori, SAP B4HANA, SAP SLT, SAP GRC, SAP PI and SAP Solution Manager/ChaRM environments.
The role involves close collaboration with business stakeholders, SAP functional and technical teams, application support teams, and internal/external audit teams across multiple geographies. Due to the global nature of the team, candidates will need to be flexible with their working hours to ensure sufficient overlap for regular calls and collaboration with colleagues across different time zones. Depending on business and team requirements, working hours may vary between morning and evening schedules, with evening working potentially extending up to 11:00pm IST.
The ideal candidate will have strong hands-on experience with SAP role design, user administration, authorization troubleshooting, Segregation of Duties (SoD), and SAP GRC Access Control, along with a good understanding of SAP BTP Security and SAP Change Request Management (ChaRM).
Key Responsibilities Include:
Support the end-to-end lifecycle of SAP user access, including user administration, role assignments, modifications, provisioning, de-provisioning, and access termination.
Design, build, modify, and maintain single, composite, and derived roles using PFCG, following role-design standards and least-privilege principles.
Analyze and troubleshoot SAP authorization issues using SU53, SUIM, ST01, STAUTHTRACE, and other relevant security tools.
Support SAP GRC Access Control, including Access Risk Analysis (ARA), Access Request Management (ARM), Emergency Access Management (EAM/Firefighter), and Business Role Management (BRM).
Perform Segregation of Duties (SoD) and critical/sensitive access risk analysis, and work with business and control owners on remediation and mitigation.
Maintain and support GRC rulesets, mitigating controls, Firefighter assignments, workflows, and access-control processes.
Support periodic user access reviews, role reviews, privileged-access reviews, and access certification activities.
Support SAP S/4HANA and Fiori Security, including business roles, catalogs, spaces/pages,…