Senior SAP Security and GRC Consultant

Where exceptional talents scale what matters.

Swicon Minds is a curated community of 450+ senior top talents working on complex enterprise challenges, while operating within a stable, structured, and supportive ecosystem.

Talent Pool

Please provide your information!


Close

LEAP WITH CONFIDENCE.

SCALE THROUGH COMPETENCE.

Senior SAP Security and GRC Consultant

2026.08.27.

Summary

Budapest, HUN

Hybrid

Senior

Introduction

In this role, you will be the primary custodian of our SAP security frameworks, ensuring robust access controls, minimizing Segregation of Duties (SoD) conflicts, and driving compliance across our SAP landscape. You will bridge the gap between technical execution and business risk management by collaborating closely with internal stakeholders, functional teams, and external auditors.


Description

We are seeking a highly skilled Senior SAP Security and GRC Consultant with over 5 years of hands-on experience to design, implement, and maintain our enterprise-wide SAP security architecture.

In this role, you will be the primary custodian of our SAP security frameworks, ensuring robust access controls, minimizing Segregation of Duties (SoD) conflicts, and driving compliance across our SAP landscape. You will bridge the gap between technical execution and business risk management by collaborating closely with internal stakeholders, functional teams, and external auditors.

Tasks

We are seeking a highly skilled Senior SAP Security and GRC Consultant with over 5 years of hands-on experience to design, implement, and maintain our enterprise-wide SAP security architecture.

In this role, you will be the primary custodian of our SAP security frameworks, ensuring robust access controls, minimizing Segregation of Duties (SoD) conflicts, and driving compliance across our SAP landscape. You will bridge the gap between technical execution and business risk management by collaborating closely with internal stakeholders, functional teams, and external auditors.

Expectations

Technical Environment

  • Core ERP: SAP ECC 6.0 and SAP S/4HANA
  • Databases: SAP HANA
  • User Interfaces: SAP GUI, SAP Fiori Launchpad
  • Compliance Software: SAP GRC Access Control (v10.x, 12.0)
  • Cloud Environments: SAP BTP (Business Technology Platform), SuccessFactors, Ariba (preferred)

Key Responsibilities

1. SAP Security Architecture & Administration

  • Design, build, test, and maintain structural profiles, roles, and authorizations using transaction PFCG.
  • Develop security strategies for SAP S/4HANA transformations, migrating legacy role models to modern, catalog-based Fiori security architectures.
  • Configure and manage security parameters for SAP HANA databases, including analytical privileges and database user provisioning.
  • Troubleshoot complex, critical authorization issues using standard trace mechanisms (SU53, ST01, STAUTHTRACE).
  • Manage automated and manual user lifecycle operations, including onboarding, offboarding, and emergency access provisioning.

2. SAP GRC Implementation & Governance

  • Lead the configuration, maintenance, and optimization of SAP GRC Access Control modules:
  • Access Risk Analysis (ARA): Maintain the ruleset, configure functions, and conduct regular risk analysis.
  • Access Request Management (ARM): Design multi-stage, multi-path (MSMP) workflows and Business Rule Framework (BRF+) rules.
  • Business Role Management (BRM): Automate role definitions and maintenance methodologies.
  • Emergency Access Management (EAM): Manage the Firefighter ID framework, configure logs, and orchestrate review workflows.
  • Partner with business process owners to design and implement effective mitigating controls for unavoidable SoD violations.

3. Compliance, Audit & Risk Mitigation

  • Drive continuous compliance with IT General Controls (ITGC), SOX (Sarbanes-Oxley), and regional data privacy laws (GDPR, DPDP Act).
  • Coordinate internal and external audit cycles by extracting proof logs, interpreting reports, and translating audit findings into actionable remediation plans.
  • Perform quarterly user access reviews (UAR) and periodic role certifications through automated GRC workflows.

4. Leadership & Stakeholder Collaboration

  • Act as a trusted subject matter expert (SME) to functional modules (FI/CO, MM, SD, PP) to align business requirements with security best practices.
  • Author detailed technical specifications, security blueprints, disaster recovery runbooks, and end-user training documentation.
  • Mentor and provide technical guidance to junior security analysts within the team.

Advantages

Nincs infó erről

Employer's offer

Required Qualifications & Experience

Educational & Professional Background

  • Education: Bachelor’s degree in Computer Science, Information Technology, Information Security, or a related quantitative field.
  • Experience: Minimum of 5+ years of dedicated, continuous experience in SAP Security and SAP GRC Access Control administration.
  • Project Lifecycle: Proven participation in at least 2 full-lifecycle SAP implementations, upgrades, or major S/4HANA migration projects.

Core Technical Competencies

  • Deep conceptual understanding of SAP security tables (e.g., AGR*, USR*), authorization objects, and organizational levels.
  • Strong, practical expertise configuring Fiori security elements, including Catalogs, Groups, Spaces, and Pages.
  • Extensive experience maintaining SAP GRC Rulesets, custom risk IDs, and writing custom BRF+ logic.
  • Familiarity with SAP Central User Administration (CUA) or integrations with Identity and Access Management (IAM) systems like SailPoint, Okta, or Azure AD

 

 

Apply for this position

Are you suitable for this positon? Click on the apply button and upload your CV!

Share this position

Share this position on your social media platform to help a friend to find his/her dreamjob!

Senior SAP Security and GRC Consultant

Please provide your information!


Close

Similar Positions

SAP BASIS Administrator

Hybrid2026.08.26.
SAP,sap specialist HUN Budapest hybrid senior…

valaki

Hybrid2026.08.03.
Oracle,finance HUN Budapest hybrid medior We…

Appdev Engineer

Remote2026.07.24.
frontend,engineer HUN Budapest remote senior…

AI-Driven SAP Developer

Hybrid2026.07.22.
SAP,developer HUN Pécs hybrid senior ncvvncvbnvbn…

DEVOPS Mérnők

Hybrid2026.05.28.
engineer,linux HUN Budapest hybrid medior A…

UCX SME lending TEST MANAGER

Hybrid2026.04.23.
test management,software testing HUN Budapest…

pom pom

Hybrid2026.03.31.
Project management,business management HUN Székesfehérvár…

vonatkerékpumpáló

Hybrid2026.02.27.
active directory,analyst HUN Budapest hybrid…

Swicon Stories

Real people. Real challenges. Real impact.

„The whole hiring process was a really positive experience for me. I was given the opportunity to move forward professionally and to test myself in a new, more senior role. I was trusted from the start, and I had all the support I needed to take the next step in my career with confidence. They connected me with the right technical contact, and every question I had was answered quickly and clearly, so I never felt left on my own. Communication was smooth, each step built on the one before, and the whole process moved surprisingly fast and without a hitch.”

K. R. – Solution Architect

“Looking back over more than 15 years, Swicon gets top marks from me: it has built itself into a fast-growing multinational, and all the while it has backed its people professionally across the board — it even supported my PMP certification with a proper training course.”

B. T. – Sr. Projectmanager

“I’ve been working with SWICON for almost a year and a half now, and it’s been a positive experience from start to finish. Both the hiring process and the admin side of things ran smoothly, and whenever I had a question, help came quickly. I particularly appreciate how kind and helpful my colleagues are, and the fact that the company genuinely invests in building a community — there are regular programmes and events.
I’ve grown a lot professionally in my time here, too. My tasks and my responsibilities have kept widening, I’ve been able to take on more complex challenges, and I’ve also had the chance to support and mentor others. On the IT side I’ve been given opportunities that made a real difference to where I am professionally, so on the whole I see SWICON as a supportive place that gives you genuine room to grow.”

M. L. – Software developer

Powering mission – critical operations across Europe

200+

successful transformation programs

$1.5B

business value created

50M

secure transactions every month

20+

years of enterprise expertise

450+

senior experts

Trusted by enterprise leaders across the world

SAP,cyber security HUN Budapest hybrid senior In this role, you will be the primary custodian of our SAP security frameworks, ensuring robust access controls, minimizing Segregation of Duties (SoD) conflicts, and driving compliance across our SAP landscape. You will bridge the gap between technical execution and business risk management by collaborating closely with internal stakeholders, functional teams, and external auditors. We are seeking a highly skilled Senior SAP Security and GRC Consultant with over 5 years of hands-on experience to design, implement, and maintain our enterprise-wide SAP security architecture.In this role, you will be the primary custodian of our SAP security frameworks, ensuring robust access controls, minimizing Segregation of Duties (SoD) conflicts, and driving compliance across our SAP landscape. You will bridge the gap between technical execution and business risk management by collaborating closely with internal stakeholders, functional teams, and external auditors. We are seeking a highly skilled Senior SAP Security and GRC Consultant with over 5 years of hands-on experience to design, implement, and maintain our enterprise-wide SAP security architecture.In this role, you will be the primary custodian of our SAP security frameworks, ensuring robust access controls, minimizing Segregation of Duties (SoD) conflicts, and driving compliance across our SAP landscape. You will bridge the gap between technical execution and business risk management by collaborating closely with internal stakeholders, functional teams, and external auditors. Technical EnvironmentCore ERP: SAP ECC 6.0 and SAP S/4HANADatabases: SAP HANAUser Interfaces: SAP GUI, SAP Fiori LaunchpadCompliance Software: SAP GRC Access Control (v10.x, 12.0)Cloud Environments: SAP BTP (Business Technology Platform), SuccessFactors, Ariba (preferred) Key Responsibilities1. SAP Security Architecture & AdministrationDesign, build, test, and maintain structural profiles, roles, and authorizations using transaction PFCG.Develop security strategies for SAP S/4HANA transformations, migrating legacy role models to modern, catalog-based Fiori security architectures.Configure and manage security parameters for SAP HANA databases, including analytical privileges and database user provisioning.Troubleshoot complex, critical authorization issues using standard trace mechanisms (SU53, ST01, STAUTHTRACE).Manage automated and manual user lifecycle operations, including onboarding, offboarding, and emergency access provisioning.2. SAP GRC Implementation & GovernanceLead the configuration, maintenance, and optimization of SAP GRC Access Control modules:Access Risk Analysis (ARA): Maintain the ruleset, configure functions, and conduct regular risk analysis.Access Request Management (ARM): Design multi-stage, multi-path (MSMP) workflows and Business Rule Framework (BRF+) rules.Business Role Management (BRM): Automate role definitions and maintenance methodologies.Emergency Access Management (EAM): Manage the Firefighter ID framework, configure logs, and orchestrate review workflows.Partner with business process owners to design and implement effective mitigating controls for unavoidable SoD violations.3. Compliance, Audit & Risk MitigationDrive continuous compliance with IT General Controls (ITGC), SOX (Sarbanes-Oxley), and regional data privacy laws (GDPR, DPDP Act).Coordinate internal and external audit cycles by extracting proof logs, interpreting reports, and translating audit findings into actionable remediation plans.Perform quarterly user access reviews (UAR) and periodic role certifications through automated GRC workflows.4. Leadership & Stakeholder CollaborationAct as a trusted subject matter expert (SME) to functional modules (FI/CO, MM, SD, PP) to align business requirements with security best practices.Author detailed technical specifications, security blueprints, disaster recovery runbooks, and end-user training documentation.Mentor and provide technical guidance to junior security analysts within the team. Nincs infó erről Required Qualifications & ExperienceEducational & Professional BackgroundEducation: Bachelor’s degree in Computer Science, Information Technology, Information Security, or a related quantitative field.Experience: Minimum of 5+ years of dedicated, continuous experience in SAP Security and SAP GRC Access Control administration.Project Lifecycle: Proven participation in at least 2 full-lifecycle SAP implementations, upgrades, or major S/4HANA migration projects.Core Technical CompetenciesDeep conceptual understanding of SAP security tables (e.g., AGR*, USR*), authorization objects, and organizational levels.Strong, practical expertise configuring Fiori security elements, including Catalogs, Groups, Spaces, and Pages.Extensive experience maintaining SAP GRC Rulesets, custom risk IDs, and writing custom BRF+ logic.Familiarity with SAP Central User Administration (CUA) or integrations with Identity and Access Management (IAM) systems like SailPoint, Okta, or Azure AD