Extensive experience (3+ years) in SAP Platform Security, SAP Basis, HANA DB, internal controls, compliance, or a related field, focusing on SAP systems
Extensive and broad-based experience and expertise with all stacks of SAP Infrastructure and Application stack with demonstrated understanding of SAP Security and Compliance within a large and diverse enterprise environment or business community
Strong understanding of SAP processes, modules, and configurations, including ECC, S/4HANA, BTP, SAP Platform, Basis, Integration, OS, and related technologies
Ideally, knowledge of the P&G information security framework and SAP Enterprise Security Control
Knowledge of IT SAP security tools such as code scanners, GRC tools, or tools for SAP SoD monitoring
Relevant certifications such as ITIL, SA
Responsibilities
Support the SAP Security Operations & Audit & Compliance Team on an operational level, delivering consistent, high-quality, and complete support for all security aspects beneath the SAP Basis Application – including Infrastructure, Operating Systems, Databases, and any horizontal software components shared across multiple applications
Handle day-to-day design, build, implementation, testing, deployment/release management, and monitoring of security solutions and platforms
Engage in information security projects that evaluate existing security infrastructure and propose changes as defined by security leadership and architects
Communicate vulnerability results in a manner understood by technical and non-technical business units based on risk tolerance and threat to the business
Identify, analyze, and respond to malicious behaviors from a variety of sources and create action plans to mitigate future incidents
Research new tactics, techniques, and procedures (TTPs) in public and closed forums, assessing risk and implementing/validating controls as necessary through the CI/CD pipeline
Oversee, assess, and manage security approach driven by business, compliance, and regulatory requirements; security solutions aligning with P&G’s Info Security policies; security structure with minimum administrative overhead; restrict access authorizations to user’s job requirements; provide expertise, best practices, and guidance on SAP security standards; and provide appropriate security monitoring to reduce audit & compliance deviations