Key Responsibilities
- SAP Ecosystem Support:
- Manage and support SAP on-premise systems such as ECC, HCM, SCM, BW, and CRM.
- Oversee SAP Cloud systems, including Identity Access Governance, Identity Services (IAS/IPS), Concur, Ariba, Commerce Cloud, C4C, and BTP.
- Administer non-SAP systems integrated into the employee identity lifecycle, including Microsoft Active Directory and Azure Entra ID.
- Role Design & Maintenance:
- Design and implement secure SAP authorization roles following the principle of least privilege.
- Maintain detailed role documentation for clear understanding among users, approvers, and reviewers.
- Regularly review and update roles to align with business process changes and system updates.
- User Access Management:
- Resolve user access issues related to authorizations and permissions.
- Collaborate with application, process, and functional owners to address access requests.
- Maintain documentation of user access issues and resolutions in ticketing tools.
- SSO Configuration & Management:
- Configure and manage SAP's integration with SSO solutions, including Azure, SAP Secure Login Service, and SAP Identity Authentication Service.
- Partner with infrastructure teams and application owners to ensure a seamless and secure SSO experience.
Qualifications
Required Skills and Experience:
- 5+ years of experience in SAP Role Design principles, including Master-Derived roles, Composite roles, and Business Role Concepts.
- Strong understanding of SAP authorization objects and system traces.
- Proven experience in role design, segregation of duties conflict remediation, and addressing access requirements.
- Expertise in large enterprise ERP implementations (technical design, development, testing, deployment, and support).
- Familiarity with Microsoft Office tools, including Outlook, Excel, PowerPoint, and Visio.
- Excellent communication, analytical, and problem-solving skills.
- Bachelor’s degree in Information Technology, Business Administration, Information Systems, or a related field.
- Willingness to travel domestically and internationally (up to 25%).
Preferred Skills:
- Proficiency in Spanish and/or French.
- Hands-on experience with SAP Identity Access Governance or Cloud Identity Services.
- Knowledge of SAP Datawarehouse tools such as BW, DataSphere, and SAP Analytics Cloud (SAC).
- Familiarity with S/4HANA architecture and migration strategies.
- Working knowledge of SSO authentication methods like SAML2.0 and OAuth