Description:
Design, build, and maintain SAP S/4HANA authorization roles and profiles using PFCG, including single, composite, and derived roles.
Configure and secure Fiori Launchpad, including catalogs, groups, tiles, and spaces/pages for embedded and standalone Fiori deployments.
Maintain front-end (Fiori Gateway/BTP) and back-end (S/4HANA) role synchronization, ensuring correct mapping between OData services, ICF nodes, and backend authorization objects.
Perform user administration tasks: user creation, role assignment, mass user maintenance, and periodic access reviews.
Troubleshoot authorization errors using SU53, ST01/STAUTHTRACE, and SU24 to resolve missing authorizations quickly.
Support segregation of duties (SoD) analysis and remediation (risk analysis, mitigation, firefighter/emergency access management).
Build and maintain security for Fiori apps including transactional, analytical, and factsheet app types, and coordinate with functional teams to align role design with business process requirements.
Execute role redesign and cleanup projects, including authorization object trace analysis and role optimization (SU25 methodology).
Support S/4HANA upgrade and migration projects with authorization impact analysis, testing, and remediation.
Maintain documentation for role matrices, access provisioning procedures, and audit/compliance evidence.
Respond to and resolve day-to-day SAP security tickets within SLA.
Required Qualifications
5+ years of hands-on SAP Security experience, with solid, demonstrable experience in SAP S/4HANA security and Fiori/UI5 app authorizations.
Deep working knowledge of PFCG role maintenance, authorization objects, SU24 proposal maintenance, and derived/composite role structures.
Practical experience securing Fiori Launchpad (catalogs, groups, spaces, pages, tiles) in both embedded (S/4HANA) and standalone (SAP BTP) scenarios.
Experience with OData service authorization and Gateway (front-end) to back-end role alignment.
Strong troubleshooting skills using SU53, STAUTHTRACE/ST01, SUIM, and authorization trace tools.
Experience with SoD/risk analysis.
Familiarity with SAP Fiori app types (transactional, analytical, factsheet) and their authorization requirements.
Experience supporting S/4HANA implementation, upgrade, or migration projects from a security perspective.
Ability to work independently with minimal oversight and deliver hands-on configuration, not just documentation or strategy.