SAP Security Analyst - Consultant

Cynet SystemsSunnyvale, CA

About The Position

We are seeking an experienced SAP Security Analyst - Consultant with a strong background in SAP S/4HANA security and Fiori/UI5 app authorizations. The ideal candidate will have over 5 years of hands-on experience, including deep knowledge of PFCG role maintenance, authorization objects, SU24, and derived/composite role structures. This role requires practical experience securing Fiori Launchpad in both embedded and standalone scenarios, managing OData service authorizations, and aligning front-end and back-end roles. You will utilize strong troubleshooting skills with tools like SU53 and STAUTHTRACE, and have experience with SoD/risk analysis. Familiarity with different Fiori app types and experience supporting S/4HANA implementation projects from a security perspective are essential. This is a hands-on role requiring independent work with minimal oversight, focusing on configuration rather than just documentation.

Requirements

  • 5+ years of hands-on SAP Security experience.
  • Solid, demonstrable experience in SAP S/4HANA security and Fiori/UI5 app authorizations.
  • Deep working knowledge of PFCG role maintenance, authorization objects, SU24 proposal maintenance, and derived/composite role structures.
  • Practical experience securing Fiori Launchpad (catalogs, groups, spaces, pages, tiles) in both embedded (S/4HANA) and standalone (SAP BTP) scenarios.
  • Experience with OData service authorization and Gateway (front-end) to back-end role alignment.
  • Strong troubleshooting skills using SU53, STAUTHTRACE/ST01, SUIM, and authorization trace tools.
  • Experience with SoD/risk analysis.
  • Familiarity with SAP Fiori app types (transactional, analytical, factsheet) and their authorization requirements.
  • Experience supporting S/4HANA implementation, upgrade, or migration projects from a security perspective.
  • Ability to work independently with minimal oversight and deliver hands-on configuration, not just documentation or strategy.

Responsibilities

  • Design, build, and maintain SAP S/4HANA authorization roles and profiles using PFCG, including single, composite, and derived roles.
  • Configure and secure Fiori Launchpad, including catalogs, groups, tiles, and spaces/pages for embedded and standalone Fiori deployments.
  • Maintain front-end (Fiori Gateway/BTP) and back-end (S/4HANA) role synchronization, ensuring correct mapping between OData services, ICF nodes, and backend authorization objects.
  • Perform user administration tasks: user creation, role assignment, mass user maintenance, and periodic access reviews.
  • Troubleshoot authorization errors using SU53, ST01/STAUTHTRACE, and SU24 to resolve missing authorizations quickly.
  • Support segregation of duties (SoD) analysis and remediation (risk analysis, mitigation, firefighter/emergency access management).
  • Build and maintain security for Fiori apps including transactional, analytical, and factsheet app types, and coordinate with functional teams to align role design with business process requirements.
  • Execute role redesign and cleanup projects, including authorization object trace analysis and role optimization (SU25 methodology).
  • Support S/4HANA upgrade and migration projects with authorization impact analysis, testing, and remediation.
  • Maintain documentation for role matrices, access provisioning procedures, and audit/compliance evidence.
  • Respond to and resolve day-to-day SAP security tickets within SLA.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service