Job Description: SAP GRC Risk Management Consultant (Senior / Lead)
Experience required: 8+ years total, with 4+ years in SAP GRC (Risk Management, Process
Role Summary
We are looking for an experienced SAP GRC Risk management consultant to own the end-to-end lifecycle of our SAP GRC Risk Management solution, from design and configuration through testing, go-live, and ongoing support. The role also leads deployment and optimization of SAP GRC Process Control and supports Access Control. You will work closely with audit partners, risk and compliance teams, and business stakeholders to strengthen controls and drive effective risk processes.
Key Responsibilities
Risk identification, assessment, and monitoring
- Identify and assess access-related and broader business risks across SAP systems and processes.
- Maintain risk libraries and control frameworks.
- Define, assign, and monitor mitigating controls.
- Perform periodic risk assessments and track remediation to closure.
- Configure assessment cycles, risk matrices, KRIs, loss events, issues, and action plans.
Solution design and deployment
- Lead deployment, configuration, and optimization of SAP GRC Risk Management and Process Control.
- Translate business requirements into functional and technical designs.
- Design the enterprise risk framework (risk universe, hierarchy, categories, taxonomy).
- Configure Process Control: control library, control-to-risk mapping, test plans, self-assessments, and issue remediation.
- Build workflows and approval routing, including BRFplus rules.
- Ensure SAP access controls align with compliance requirements (SOX, internal policies, applicable regulations).
- Support Access Control: SoD rulesets, risk analysis, mitigating controls, and access reviews.
Reporting and stakeholder collaboration
- Deliver risk reports and dashboards (heat maps, risk profiles, trends, control status) for management and audit teams, including integrated reporting across the three GRC modules.
- Collaborate with internal and external auditors and business stakeholders to enhance controls and strengthen compliance posture.
- Run workshops, present to senior management, and clearly document risk assessments, control activities, and process changes for cross-functional use.
Integration, support, and continuous improvement
- Integrate Risk Management with Process Control, Access Control, S/4HANA / ERP, SAP BW, and third-party sources.
- Coordinate with Basis and security teams on connectors, RFC setup, and transports.
- Provide L2/L3 support, troubleshooting, enhancements, and upgrade support to keep the solution stable.
- Prepare specifications, test scripts, and training material; lead UAT and cutover.
Required Qualifications
- Bachelor's degree in IT, Finance, Risk, Engineering, or a related field.
- 8+ years of SAP experience, including 4+ years of hands-on SAP GRC implementation and/or support.
- Strong hands-on experience in Risk Management and Process Control; working experience in Access Control.
- At least 2 full-lifecycle SAP GRC implementations in a lead or senior role.
- Knowledge of SAP GRC 10.x / 12.0, workflows, and BRFplus.
- Understanding of COSO, ISO 31000, and SOX requirements.
- Experience working with audit teams on control design, testing, and remediation.
- Strong stakeholder management, communication, and documentation skills.
- Preferred SAP GRC, CRISC or CISA certification.
- Experience with S/4HANA and SAP BTP or cloud GRC solutions will be an added advantage
- Experience in regulated industries (ISU Retail, Consumer industry) preffered