Sign up free to see how well your resume matches this role.
Location:
India – Remote (preference for candidates based in Mumbai, Ahmedabad or Bangalore, with occasional travel to our Mumbai office).
Employment Type:
Permanent, Full-time
Role Overview:
We are seeking an experienced SAP Security & GRC Analyst to join our team in a permanent, full-time position based in India. This role can be performed remotely from within India, with a preference for candidates based in Mumbai, Ahmedabad or Bangalore. Candidates should be willing and able to travel occasionally to our Mumbai office.
The successful candidate will have 3–5 years of hands-on experience in SAP Security, authorization management, SAP GRC Access Control, and security support across modern SAP environments.
You will be responsible for supporting and maintaining secure, compliant, and business-aligned access across the SAP landscape, including SAP S/4HANA, Fiori, SAP B4HANA, SAP SLT, SAP GRC, SAP PI and SAP Solution Manager/ChaRM environments.
The role involves close collaboration with business stakeholders, SAP functional and technical teams, application support teams, and internal/external audit teams across multiple geographies. Due to the global nature of the team, candidates will need to be flexible with their working hours to ensure sufficient overlap for regular calls and collaboration with colleagues across different time zones. Depending on business and team requirements, working hours may vary between morning and evening schedules, with evening working potentially extending up to 11:00pm IST.
The ideal candidate will have strong hands-on experience with SAP role design, user administration, authorization troubleshooting, Segregation of Duties (SoD), and SAP GRC Access Control, along with a good understanding of SAP BTP Security and SAP Change Request Management (ChaRM).
Key Responsibilities Include:
Support the end-to-end lifecycle of SAP user access, including user administration, role assignments, modifications, provisioning, de-provisioning, and access termination.
Design, build, modify, and maintain single, composite, and derived roles using PFCG, following role-design standards and least-privilege principles.
Analyze and troubleshoot SAP authorization issues using SU53, SUIM, ST01, STAUTHTRACE, and other relevant security tools.
Support SAP GRC Access Control, including Access Risk Analysis (ARA), Access Request Management (ARM), Emergency Access Management (EAM/Firefighter), and Business Role Management (BRM).
Perform Segregation of Duties (SoD) and critical/sensitive access risk analysis, and work with business and control owners on remediation and mitigation.
Maintain and support GRC rulesets, mitigating controls, Firefighter assignments, workflows, and access-control processes.
Support periodic user access reviews, role reviews, privileged-access reviews, and access certification activities.
Support SAP S/4HANA and Fiori Security, including business roles, catalogs, spaces/pages, OData services, and associated backend authorization requirements.
Support SAP BTP Security, including user and role administration, role collections, application authorizations, subaccount access, trust configuration, and integration with enterprise identity providers.
Assist with security configuration and troubleshooting involving SAP Cloud Identity Services (IAS/IPS) and authentication/federation technologies such as SAML and OIDC, where applicable.
Support SAP Solution Manager Change Request Management (ChaRM) processes, including ChaRM-related user access, security roles, authorization troubleshooting, transport/change-management workflows, and appropriate segregation of responsibilities across the change lifecycle.
Understand the security and compliance requirements associated with SAP transports and change management, including separation of development, approval, testing, and production deployment responsibilities.
Participate in SAP projects, enhancements, upgrades, migrations, and releases by performing security design, role changes, impact assessments, security testing, and access validation.
Assist internal and external auditors with access-related evidence, control testing, change-management controls, and remediation of audit findings.
Maintain security documentation, including role matrices, authorization standards, access procedures, GRC configurations, rulesets, mitigation controls, and security design documentation.
Manage incidents, service requests, and access-related tickets using ServiceNow or comparable ITSM platforms, ensuring adherence to established SLAs.
Collaborate effectively with geographically distributed business and technology teams, with flexibility to work morning or evening working hours as required to support regular collaboration across time zones. Evening work may extend up to 11:00pm IST.
Required Skills & Experience:
Typically 3–5 years of hands-on SAP Security and SAP GRC experience within an enterprise SAP environment.
Strong understanding of SAP authorization concepts, Role-Based Access Control (RBAC), PFCG role design, authorization objects, profiles, and user administration.
Hands-on experience with SAP GRC Access Control 10.x/12.x, particularly ARA, ARM, EAM/Firefighter, and BRM.
Practical experience supporting SAP S/4HANA, Fiori Security, B4HANA, GRC, SLT, PI.
Working knowledge of SAP BTP Security.
Working knowledge of SAP Solution Manager and ChaRM, particularly security, authorization, transport/change-management workflows, and access-control considerations.
Strong understanding of SoD, sensitive/critical access, privileged access, least privilege, and mitigating controls.
Experience troubleshooting complex SAP authorization and access issues.
Familiarity with access provisioning/de-provisioning, periodic access reviews, identity lifecycle management, and access governance processes.
Experience with ServiceNow or similar ITSM/ticketing platforms.
Strong analytical, troubleshooting, documentation, and communication skills.
Ability to effectively collaborate with technical teams, business stakeholders, control owners, security teams, and auditors.
Please note that this role is based in India. In order to enable us to meet statutory and regulatory obligations of the Indian immigration system you must have the appropriate immigration permission needed to work and reside in India for the duration of the employment.
Good to Have:
Experience with SAP Cloud Identity Services (IAS/IPS) and integration with enterprise identity providers.
Understanding of authentication and SSO technologies including SAML, OIDC, SNC.
Exposure to SAP HANA Security and SAP Cloud Connector security.
Understanding of RISE with SAP and hybrid/cloud SAP security architectures.
Experience with ChaRM transport controls, emergency changes, production change governance, and associated ITGC controls.
Understanding of IT General Controls (ITGC), SOX, audit requirements, access controls, and change management controls.
Experience supporting large-scale SAP S/4HANA implementations, upgrades, migrations, or transformation programs.
Exposure to automating repetitive SAP security related tasks using SAP tools.
Sony Pictures Entertainment is committed to equal opportunity in all its employment practices, policies and procedures. No worker or potential worker will therefore receive less favourable treatment due to any characteristic which is protected by applicable law, for example including their race, age, creed, sexual orientation, colour, nationality, ethnic origin, disability, religion, gender, marital status or Trade Union membership (if applicable).
If you require any reasonable adjustments with any part of the recruitment process, including the application or interview process, please contact us at spe_apac_talentacquisition@spe.sony.com. Please put Reasonable Adjustment Request in the subject line of the email.
Sony Pictures does not allow audio recording, video recording or use of AI note-taking tools during interviews. Candidates requiring these tools as an accommodation during an interview should submit a reasonable adjustment request at the point they are invited to interview.