Senior Security Engineer
McKinsey & Company
McKinsey & Company
What you will do:
You will be responsible for the design, implementation and maintenance of the firm's SAP foot print in all aspects of security. Including, but not limited to, role management/design (utilizing single roles, business roles and enabler roles), security reviews for patches, custom development/custom t codes, upgrades and releases, maintenance/support of SAP products regarding security etc. You will create, develop and maintain application roles in accordance with leading practice design principles.
You will be accountable for the analysis of SAP release notes and their impact to the security models across the SAP landscape. You will be responsible for the required maintenance activities associated with any security items identified post the analysis of the release notes.
You will be responsible for delivering robust security solutions that support SAP Provisioning, Authentication, Authorization, and Application-level security. You will leverage your strong knowledge of ERP processes, and Information Security principles. You should be familiar with multi-layer role framework including both task role concepts and job role concepts and enabler role concepts.
You will architect solutions to keep pace with an ever-expanding SAP landscape, providing expertise to address more complicated requirements to meet various project goals. You will propose and be accountable for the successful completion of security solutions, both process and technical, to enhance and strengthen security in the environment.
You will support legal, audit and compliance activities and identify and evaluate risks and lead efforts for opportunities for control improvements. You will demonstrate professional skepticism to ensure evidence is sufficient when assessing the relevant controls.
You will be responsible for various aspects with SAP GRC AC12.0, (EAM, ARA, BRM) including but not limited to, implementation/maintenance with respect to configurations, business role design/maintenance, workflows, business andt, etc. You will be responsible for interpreting GRC compliance SoD and SA reports and translating business decisions around compliance to technical security model updates.
You will collaborate closely with business, security and technical teams to help maintain the integrity of the SAP environments. You will also lead educational sessions with them.
You will work in our Gurugram office as part of our core Financial Cloud Transformation team. The team is a virtual team and spread across different regions and time zones such as Europe, India, North America and Costa Rica. You will work collaboratively as part of the team but also be expected to work individually to maintain the integrity of the SAP security across all SAP environments utilized at the firm.
You will be relied upon to provide expert advice, leadership and guidance with regard to SAP security, role design, maintenance/support. This is a hands on security role. You will work with Information Security, Internal Audit, Compliance, Engineering and Project teams to find opportunities to continually advance SAP security.
There is a strong emphasis on knowledge sharing and ensuring that we raise everybody’s skills and expertise to ensure that we are all constantly learning from one another.
Who you will work with:
Driving lasting impact and building long-term capabilities with our clients is not easy work. You are the kind of person who thrives in a high performance/high reward culture - doing hard things, picking yourself up when you stumble, and having the resilience to try another way forward.
In return for your drive, determination, and curiosity, we'll provide the resources, mentorship, and opportunities you need to become a stronger leader faster than you ever thought possible. Your colleagues—at all levels—will invest deeply in your development, just as much as they invest in delivering exceptional results for clients. Every day, you’ll receive apprenticeship, coaching, and exposure that will accelerate your growth in ways you won’t find anywhere else.
When you join us, you will have:
Continuous learning:
Our learning and apprenticeship culture, backed by structured programs, is all about helping you grow while creating an environment where feedback is clear, actionable, and focused on your development. The real magic happens when you take the input from others to heart and embrace the fast-paced learning experience, owning your journey.
A voice that matters:
From day one, we value your ideas and contributions. You’ll make a tangible impact by offering innovative ideas and practical solutions. We not only encourage diverse perspectives, but they are critical in driving us toward the best possible outcomes.
Global community:
With colleagues across 65+ countries and over 100 different nationalities, our firm’s diversity fuels creativity and helps us come up with the best solutions for our clients. Plus, you’ll have the opportunity to learn from exceptional colleagues with diverse backgrounds and experiences.
World-class benefits:
On top of a competitive salary (based on your location, experience, and skills), we provide a comprehensive benefits package, which includes medical, dental, mental health, and vision coverage for you, your spouse/partner, and children.
Your background:
Bachelor’s degree in Info Tech, Computer Science or equivalent required
Compliance and security skills required. CISSP, CISA or CISM or equivalent a plus
SAP System Security Certification required
SAP implementation or project rollout experience required designing business roles & security design
6+ years, strong security experience of SAP S4Hana, Hana Database, BTP, SAP Analytics Cloud, SAP Payroll, AFC, SLT, CPI, IAS; including Fiori security
Strong hands on experience in SAP GRC AC 12.0 (EAM, ARA, BRM) for centralized risk management, compliant provisioning and role administration. Must have both MSMP + BRF experience
Deep knowledge of various aspects of SAP Security, both from a technical as well as business process perspective
Various user and role types, SAP Authorization Concept, Roles and Activity Groups, and User Administration on various SAP Platform
Managing Segregation of Duties (SOD) Risks, identifying/applying mitigation controls, monitoring sensitive access and elevated privileges
Strong knowledge of SAP authorization concepts for various SAP cloud offerings i.e. SAP BW, Portal, as well as S/4 HANA and new SAP Cloud solutions
Experience with integration to Identity Management Systems (e.g. SailPoint) for provisioning to SAP applications, with Directory Services for Authentication via SSO
Self starter to manage multiple projects and deadlines simultaneously
Ability to work independently and in a remote global team setting
Strong leadership, collaboration, organizational and interpersonal skills
Ability to take lead and communicate clearly, concisely and confidently with all levels of management
Ability to challenge status quo
SAP GRC Certification - strong plus
Ready to apply?
Sign up first — takes a minute — and you get Hiro’s take on this role, a resume tailored to it, and (if available) a referral from a real employee at McKinsey & Company. All free with your Pro gift.
Sign up to apply