This position is for a Senior SAP Security Analyst - GRC on the SAP Security & Compliance Team for a large SAP implementation to provide production support and other improvement initiatives as needed. This individual is responsible for supporting the SAP Security design that supports business process design and organizational structure in the most effective and efficient manner while ensuring compliance with all security and architectural mandates. This individual will work very closely with other teams including those within SAP Shared Services, Information Security & Risk Management, and our Risk and Controls Group. Leadership and technical competence are a must.
Areas of Responsibilities include:
Act as a Subject Matter Expert for SAP Security and GRC, and support the GRC application through:
Providing subject matter expertise around GRC v10 or above
Identifying gaps and improvements in the current GRC system
Expansion of GRC capabilities to take full advantage of the suite of tools available
Creation of BRF+ workflows
Updates to the GRC Ruleset to match current segregation of duty needs
Updates to Master Data such as Roles, Role Owners, Ruleset updates, etc.
Provide subject matter expertise and oversight as needed to projects requiring GRC support
Provide training to other team members on GRC support activities so that general GRC support can be shared
Support the ongoing operations of SAP Security through:
Meeting all defined service levels and defined performance objectives
SAP Security Strategy Development and Management.
Role and User Maintenance.
Provisioning and de-provisioning of users.
Serve as a leader for implementing SAP security architecture.
Possess and able to convey a strategic vision and end state design for interrelated business and security processes (i.e. GRC Access and Security controls).
Coordinate all security designs with various Business Units
Analyze and implements SAP security requirements.
Recommends and develops security measures to protect information against unauthorized modification or loss.
Works closely with both SAP technical and functional teams to ensure the success of the overall SAP solution.
Serve as SAP Security subject matter expert and provide advisory and consulting services as needed.
Ability to collaborate with SAP Applications and SAP Basis administration teams to design and implement technical security solutions for SAP and associated bolt-on applications.
Support of SOX Compliance through:
Adherence to, and delivery of SOX controls and procedures
Support of audits both internal and external
Support of bi-annual self-assessment activities
Support the ongoing improvement of the SAP Security & Compliance area:
Providing ideas for improvement initiatives
Self-managing through improvement projects and providing clear measurable results
7+ years relevant experience
At least 2 full GRC implementations
3-4 years of progressively responsible experience in designing, implementing, and maintaining SAP Security
Deep knowledge of the GRC 10.0 application, capabilities, and limitations
At least 3 full SAP lifecycle implementations of SAP Security.
Proficient in SAP security principles, technologies and solutions, delivering functionality or services on time, on budget and to meet business needs.
Proficient in IT general controls and SOX requirements as they relate to security administration.
Technical knowledge of SAP security architecture and role-based authorization models
Proven success on multiple, enterprise-scale SAP implementation projects or services
Additional Knowledge & Skills
Strong, proven problem-solving skills and ability to identify, analyze, and resolve problems, driving solutions through to completion.
Proficient in analyzing requirements, resource estimation, and allocation.
Excellent in team leadership and team-based problem-solving skills.
Excellent interpersonal and oral, written communication skills.
Ability to translate complex technical information across all levels of the organization.
Ability to self-manage on tasks and mini-projects or improvement efforts
Strong facilitation skills and a clear ability to build strong relationships with business partners at all levels.
Demonstrated ability to translate business drivers and priorities into security design, policies and procedures.
Results driven, and able to collaborate with management and colleagues to share the responsibilities for achieving an end-to-end solution for customers.
Strong attention to detail which ensures that customer requirements are met and that a high-quality standard is achieved.
Provide technical perspectives to other architecture functions to ensure that solutions effectively leverage infrastructure capabilities and services and integrate with them.
Must have excellent initiative, organization, and customer service skills.
Education Bachelor's degree or equivalent experience
Physical Requirements General Office Demands
McKesson is an Equal Opportunity/Affirmative Action employer.
All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, sex, sexual orientation, gender identity, national origin, disability, or protected Veteran status.Qualified applicants will not be disqualified from consideration for employment based upon criminal history.
McKesson is committed to being an Equal Employment Opportunity Employer and offers opportunities to all job seekers including job seekers with disabilities. If you need a reasonable accommodation to assist with your job search or application for employment, please contact us by sending an email to McKessonTalentAcquisition@mckesson.com . Resumes or CVs submitted to this email box will not be accepted.
Current employees must apply through the internal career site.
Join us at McKesson!
Internal Number: JR0035757
About McKesson Corporation
We deliver careers with purpose and potential. Our focus on better health starts with creating an inclusive environment with strong values where you can build a fulfilling career. You can count on us to provide you with resources and opportunities to grow and be your best, while contributing to our pursuit of improving lives. Every day, McKesson’s employees deliver products to healthcare providers that make a difference in the care and life of a patient. We work to distribute medical supplies, bandages, syringes, vials of flu vaccine, and pharmaceutical drugs to help real patients like Jack, an eight-year-old boy battling cancer. We take that job seriously. Together, the work we do is shaping the future of healthcare. If you are passionate about combining a meaningful career with a balanced life, join us on this journey and apply for a job with McKesson today. Every day, McKesson’s employees deliver products to healthcare providers that make a difference in the care and life of a patient.