Submit Resume

SAP Security - ECC

  • Massachusetts, Boston

  • 08/13/2026

  • Contract

  • Active

Job Description:

  • Job Summary
    We are seeking an experienced SAP Security professional to lead security strategy and execution for ECC to S/4HANA brownfield transformations. The ideal candidate will have hands-on experience with SAP security conversion activities, enterprise role redesign, Fiori security, SoD analysis and remediation, and security validation throughout the migration lifecycle.

    Key Responsibilities
    • Lead SAP security strategy and execution for ECC to S/4HANA transformation and brownfield conversion projects.
    • Perform role impact analysis, cleanup, and remediation; execute SU25 conversion steps and validate role behavior in S/4HANA.
    • Design and implement a Fiori-first security model, including catalogs, groups, and business roles.
    • Secure and configure OData and SICF services supporting Fiori applications.
    • Configure and manage Security Weaver (Pathlock) controls or align SAP GRC rule sets where applicable.
    • Migrate SoD rule sets and control frameworks from ECC to S/4HANA and define interim compensating controls.
    • Conduct workshops with functional teams across FI/CO, MM, SD, and EWM, as well as Basis, Development, and Audit teams, to validate security models.
    • Support cutover, security testing, post-go-live authorization validation, and stabilization activities.

    Required Qualifications
    • Hands-on experience with a minimum of 2–3 full lifecycle ECC to S/4HANA brownfield migration projects.
    • Direct hands-on experience executing SU25 Phases 1–4 and role retrofit activities during ECC to S/4HANA conversion.
    • Experience implementing Fiori security, including catalogs, groups, business roles, OData activation, and SICF.
    • Experience with enterprise role redesign and remediation at scale; experience analyzing and remediating 1,000+ roles is preferred.
    • Experience with SAP Readiness Check and Simplification Item Catalog impact analysis.
    • Hands-on experience with Security Weaver (Pathlock) or SAP GRC Access Control for SoD analysis, simulation, remediation, and reporting.
    • Strong understanding of SoD rule design and risk mitigation strategies during ECC to S/4HANA transitions.
    • 10+ years of SAP Security experience across ECC and S/4HANA environments.
    • Strong communication skills and ability to lead cross-functional workshops.

    Preferred Qualifications
    • Proven track record of 2+ ECC to S/4HANA brownfield conversions.
    • Strong experience with Security Weaver (Pathlock).
    • Experience with SAP GRC Access Control in complex enterprise environments.
    • Experience working in SOX/ITGC-regulated environments and preparing audit evidence.

.

.

.