Overview
Skills
Job Details
Job Overview:
BrightSol is seeking a skilled SAP professional to join our consulting practice in a remote role that combines expertise in SAP Security, GRC, and secure ABAP development. This role is ideal for a consultant who brings a blend of functional SAP security and technical ABAP experience or someone highly skilled in one area with the flexibility to support both.
Key Responsibilities:
< data-start="934" data-end="964">SAP Security & GRC Focus:</>Lead client engagements in SAP GRC, SAP Security, and controls optimization.
Evaluate and enhance SAP security and compliance controls across business cycles.
Identify risks, recommend security and GRC improvements, and support audit readiness.
Provide mentorship and training to internal teams.
Deliver detailed reports, documentation, and compliance procedures.
Develop and maintain ABAP programs with strong security design.
Implement SAP security controls in custom code (e.g., authority-check, SU24).
Analyze and remediate security vulnerabilities in ABAP (SQL/code injection, etc.).
Collaborate with SAP security and compliance teams to ensure secure coding practices.
Support security audits with insights into custom developments.
Required Qualifications:
Bachelor s degree in Computer Science, Information Systems, or related field (preferred).
3+ years of experience in SAP Security, GRC, or Controls.
5+ years of ABAP development experience in SAP ECC and/or S/4HANA.
Experience in one or more of the following:
SAP IT controls & audit (SOX, GDPR)
SAP GRC Access Control implementation
SAP security role design/redesign (PFCG, SU24, etc.)
Secure ABAP development & custom object review
SAP Code Inspector / ATC / security scan tools
S/4HANA security, Fiori authorization
Managed services or support in SAP security and controls
Preferred Skills:
Strong understanding of SAP authorization concepts and risk frameworks.
Experience with SAP GRC modules (AARM, BRM, EAM, etc.).
Familiarity with security in enhancements, BADIs, user exits, and custom reports.
Exposure to internal controls frameworks and audit procedures.