Cube Hub Inc.
Website:
cube-hub.com
Job details:
Job Title: SOD Internal Controls Consultant
SAP GRC SOD & Internal Controls Consultant (SAP Security)
Job Location: Pune, India 1-2 days week)
• Must be based in Pune India (in office – as per client policies) and able to cover US Eastern time zones through 11am
Position is for 12 months duration with the possibility to extend, but not guaranteed.
The candidates a lot of technical SAP Security experience (User Access, User Roles, understand t-codes/auth objects, etc.) also need much experience/knowledge with understanding the business risk and how to map that with the SAP technical to mitigate SOD risk and build and maintain an SOD rule set. For this position, we need someone that understands SAP Security but also business process risks such that they can guide the business and know what to approve vs reject with authority. "
Skills
Leadership, conflict resolution and stakeholder management skills that we need.
Your understanding of SoD concepts and why they are important.
How business process risks relate to SAP Security.
Identifying and evaluating SoD conflicts.
Experience with SoD rule sets, including creating, maintaining, or using them.
How you determine whether to approve or reject an access request based on risk.
Examples of working with business stakeholders to assess and mitigate SoD risks.
How SAP Security controls help reduce business and compliance risk
Highlights on the requirements
We are seeking an experienced SAP GRC Segregation of Duties (SoD) & Internal Controls Consultant with 7–10+ years of experience in SAP Security, Internal Controls, and Access Governance. This role requires a strong combination of technical SAP Security expertise, business process knowledge, leadership, and stakeholder management skills.
The successful candidate will lead Segregation of Duties (SoD) risk management activities, partnering with global Finance, IT, Internal Controls, Audit, and SAP Security teams to strengthen SAP access governance, improve internal controls, and reduce business risk across enterprise SAP environments.
This role is highly consultative and requires someone who can confidently connect SAP Security with business process risk, provide practical recommendations, influence stakeholders, and support large-scale SAP transformation programs including SAP S/4HANA implementations.
Key Responsibilities
SAP Security & SoD Governance
- Lead Segregation of Duties (SoD) governance and access risk management activities.
- Design, maintain, and optimize SoD rulesets and sensitive access rules.
- Review SAP role designs, user assignments, and access requests to ensure compliance with internal controls.
- Identify, assess, and remediate SoD conflicts and sensitive access risks.
- Evaluate proposed role changes, user access changes, and ruleset modifications.
- Review and approve or reject access requests based on business need, compliance requirements, and risk assessment.
- Ensure SAP Security role design follows the principle of least privilege.
- Support user provisioning, role design, authorization concepts, and access governance activities.
Business Process & Risk Management
- Understand end-to-end business processes including Procure-to-Pay (P2P), Purchase Orders, Receiving, Finance, Order-to-Cash, and Supply Chain.
- Translate business process risks into effective SAP Security controls.
- Assess how SAP Security impacts financial reporting, compliance, and operational risk.
- Design preventive and mitigating controls to reduce business and compliance risk.
- Provide recommendations that balance business requirements with security and regulatory obligations.
SAP Projects & Transformation
- Support SAP S/4HANA implementations and enterprise transformation initiatives.
- Provide SAP Security and SoD guidance during:
- SAP S/4HANA implementations
- Kenvue NAS4 Integration
- EMEA ES4
- LAOES4
- Coupa implementations
- Robotics and automation initiatives
- Organizational and Shared Service Centre transitions
- Develop comprehensive test scenarios and execute User Acceptance Testing (UAT) for security-related changes.
- Support system implementations by ensuring SoD and access control requirements are embedded throughout the project lifecycle.
Leadership & Stakeholder Management
- Act as the lead consultant for SoD governance and access control decisions.
- Provide technical leadership and guidance to SAP Security and Internal Controls teams.
- Build trusted relationships with Finance, IT, Process Owners, Control Owners, Internal Controls, Internal Audit, External Audit, and business leadership.
- Confidently challenge inappropriate access requests and provide risk-based recommendations.
- Manage stakeholder expectations and resolve conflicts through effective communication and negotiation.
- Influence decision-making while balancing operational needs with compliance requirements.
- Demonstrate strong ownership, accountability, and independent decision-making.
Audit & Compliance
- Support Internal and External Audit activities.
- Prepare KPI reporting and management dashboards.
- Monitor SoD conflicts and remediation activities.
- Recommend continuous improvements to SAP Security governance.
- Ensure compliance with company policies and regulatory requirements.
Key Risk Areas
The successful candidate will manage risks including:
- Segregation of Duties (SoD) conflicts resulting from inappropriate role combinations.
- Sensitive and critical access capable of overriding business controls.
- Excessive SAP authorizations beyond business requirements.
- Financial reporting risks caused by inappropriate access.
- Weak role design and access governance.
- Delayed remediation of SoD violations.
- Deficiencies in SoD rulesets and access governance processes.
Required Technical Skills
- 7–10+ years of SAP Security experience.
- Strong SAP Security administration and role design expertise.
- Hands-on experience with:
- SAP Security Transaction Codes
- Authorization Objects
- User Administration
- Single Roles
- Composite Roles
- Derived Roles
- Role Assignments
- User Provisioning
- Strong understanding of SAP authorization concepts and how authorization object values determine transaction risk.
- Experience designing and maintaining SoD rulesets.
- Experience identifying and evaluating SoD conflicts.
- Experience with:
- SAP ERP
- SAP ECC
- SAP S/4HANA
- SAP Security
- SAP GRC (preferred)
- Saviynt
- Pathlock
- Experience supporting SAP Security ticketing and production environments.
Business & Functional Knowledge
The ideal candidate should possess strong business process knowledge including:
- Procure-to-Pay (P2P)
- Purchase Orders
- Receiving
- Finance
- Order-to-Cash (O2C)
- Record-to-Report (R2R)
- Supply Chain
- Internal Controls
- Financial Controls
- Compliance
- Access Governance
The candidate should understand how business process risks translate into SAP Security risks and SoD conflicts.
Leadership Competencies
The successful candidate should demonstrate:
- Leadership skills
- Stakeholder management
- Conflict resolution
- Strong communication skills
- Decision-making ability
- Analytical thinking
- Business partnering
- Influencing skills
- Ability to push back when business requests introduce unacceptable risk
- Ability to explain technical SAP Security concepts to business users
- Strong ownership and accountability
- Ability to work independently with minimal supervision
Working Environment
- Based in Pune, India (Onsite).
- Ability to support US Eastern Time Zone through 11:00 AM EST.
- Work with global teams across:
- North America
- Europe
- Latin America
- Asia Pacific
- Comfortable working in a fast-paced international environment.
Customers & Stakeholders
This role partners closely with:
- Finance
- IT Internal Controls
- SAP Security
- Process Owners
- Control Owners
- Internal Audit
- External Audit
- Compliance Teams
- Business Leadership
- Global IT Teams
Click on Apply to know more.