SAP Security Lead (S/4HANA, GRC, IDM)
Norfolk SouthernAbout the role
Requisition 38026: B4 SAP Security Lead (S/4HANA, GRC, IDM)
A resume helps you stand out to hiring managers and recruiters; your resume communicates your experience and your brand. While it is not required, we encourage you to include an up-to-date resume along with a completed job application to give you the best opportunity to be considered. A complete resume helps us to better understand your unique background, relevant experiences, and passions. We look forward to learning about you.
Norfolk Southern offers a unique opportunity to be part of our proud legacy that spans nearly 200 years. We are a customer-centric, operations-driven team dedicated to advancing safety, serving communities, and driving innovation for tomorrow's rail. As part of Norfolk Southern, you’ll join a collaborative team where there are opportunities for growth across the organization. We are building a culture where everyone can thrive by owning and driving exceptional results, being humble and leading with trust, serving our customers with excellence, and collaborating and coaching to win.
Job Description
The SAP Security Lead is responsible for managing and enhancing the security framework across SAP environments, including SAP S/4HANA, GRC (Governance, Risk & Compliance), IDM (Identity Management), SAP BTP IAS and IPS, and other related systems. This role involves leveraging SAP best security practices, using SAP-provided roles as a foundation, and developing customized roles to meet business needs. The SAP Security Lead will create strategic roadmaps for security improvements, optimization of processes, providing automation for role management and firefighting access, and staying current with SAP security technologies. This position requires a proactive leader who can collaborate with cross-functional teams to drive continuous improvements in security and compliance.
Responsibilities
- Lead the design, implementation, and management of SAP S/4HANA security, focusing on role-based access controls (RBAC) and segregation of duties (SoD) using GRC.
- Use SAP-delivered roles as a baseline and develop new roles to meet specific business requirements, ensuring minimal conflicts and optimal efficiency.
- Develop and implement a long-term security roadmap that aligns with business goals, IT strategy, and regulatory requirements.
- Identify opportunities for optimization, risk reduction, and improved efficiency in the SAP security landscape by implementing process improvements, new innovation and maximizing NS current tools.
- Oversee the configuration and management of SAP GRC modules (Access Control, Process Control, Risk Management) and ensure compliance with internal and external audit requirements.
- Implement and manage SoD rulesets and workflows, ensuring secure and compliant user access provisioning, emergency access (firefighter) management, and role audits.
- Manage SAP IDM processes, ensuring efficient and compliant user provisioning, de-provisioning, and role management.
- Automate user lifecycle management, integrating SAP IDM with GRC and other systems to streamline security operations.
- Administer and monitor firefighter (emergency access) usage, ensuring proper controls, logging, and audit trails are in place.
- Implement solutions to automate firefighter access management and reporting to minimize manual efforts and improve oversight.
- Design and implement efficient processes for role development, optimization, and automation, reducing complexity while maintaining compliance.
- Lead efforts to standardize and simplify role management across multiple SAP systems, ensuring scalability and security.
- Evaluate current SAP security processes and identify areas for improvement, automation, and streamlining.
- Introduce best practices for periodic access reviews, security patch management, and user access risk mitigation.
- Monitor security logs, events, and user activities to detect anomalies, unauthorized access, and potential security incidents.
- Perform regular security assessments, audits, and risk evaluations to ensure compliance with industry standards such as SOX, GDPR, and internal policies.
- Act as the primary point of contact for all SAP security-related issues, guiding and training teams on security best practices.
- Work closely with stakeholders, including IT, business, and compliance teams, to gather requirements, design security solutions, and implement policies.
Education
- Bachelor's degree in computer science, computer information systems, or related technology field is required.
Skills Required
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s