Sr. Analyst, IT - SAP Security Controls

VeranoChicago, IL
Onsite

About The Position

This position supports SAP Security, Access Management, and IT General Controls on SAP S/4HANA. The role executes SAP-specific ITGCs, ensuring monthly and quarterly controls are performed accurately, on time, and with the evidence required to withstand internal and external audit scrutiny. As a functional expert in the domain, the Sr. Analyst partners with analysts and vendor partners and supports the maturation of the controls program as it expands to other SAP products.

Requirements

  • 7+ years of hands-on SAP Security experience with strong SAP role design, provisioning, and access-management depth.
  • Demonstrated hands-on experience owning and executing SAP-specific ITGCs at the control-owner level — not just supporting audit teams. Direct experience with User Access Reviews, Termination Reviews, Firefighter Log Reviews, Change Management, and Audit Log Reviews required.
  • Track record of remediating SOX/ITGC audit findings systemically — closing recurring issues rather than patching them each cycle.
  • Experience with control evidence retention, IPE validation, reviewer sign-off standards, and defending controls in front of external auditors.
  • Demonstrated ability to lead — mentoring junior team members, setting standards, and directing internal and external contributors on security and controls work.
  • Strong communication, stakeholder management, and change management skills; ability to lead through influence across all organizational levels.

Nice To Haves

  • Experience with SAP GRC (Access Control 12.0) is a strong plus.
  • Working knowledge of Fastpath (preferred) or comparable tools such as CSI, Pathlock for automated control monitoring, access reviews, and SoD analysis.
  • Experience with controls execution for other SAP products such as SAP Ariba and SuccessFactors is a huge plus — these products will be added to the control scope over time.

Responsibilities

  • Manage SAP role design, provisioning, and de-provisioning aligned to business roles and least-privilege principles.
  • Design and maintain the SoD ruleset within our current toolset (e.g., Fastpath); own SoD analysis, mitigation, and remediation across SAP applications.
  • Own Firefighter (Emergency Access) governance — request, approval, monitoring, and log review.
  • Support integration of SAP security events with the enterprise SIEM.
  • Serve as the control owner and executor for SAP-specific ITGCs, including quarterly User Access Review, monthly Termination Review, monthly Privileged User Access Monitoring, monthly Firefighter Log Review, monthly Critical/Administrative Access Review, quarterly SAP Standard Accounts Review, quarterly Role Review, quarterly Audit Log Review, and quarterly Client Open Changes Review.
  • Ensure control execution is timely, within the correct review period, with proper reviewer approval, evidence retention, and documentation to support audit and SOX requirements.
  • Maintain and improve control templates to ensure accuracy of formulas, scoping, and reviewer instructions; standardize and version-control templates across execution cycles.
  • Track and remediate SOX/ITGC findings from internal and external audit; ensure remediation is systemic rather than reactive.
  • Partner with Internal Audit and external auditors on requests, walkthroughs, IPE (Information Produced by the Entity) validation, and evidence review.
  • Support the expansion of controls coverage to other SAP products (e.g., SAP Ariba, SuccessFactors) as they come into audit scope over time.
  • Direct and validate work performed by external AMS partners, ensuring quality and alignment with the broader SAP architecture.
  • Collaborate with business stakeholders, cross-functional teams, and vendors to ensure successful project delivery and ongoing system support.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service