SAP Security and GRC Consultant - Capgemini Business Services India Pvt Ltd
(2024-02)
Working on Unilever [U2K2] project as SAP Security & GRC Consultant. Environment: SAP SAP Security, Solution Manager, GRC 12.0. Unilever is a British-Dutch multinational company owning many of the world's consumer product brands in foods, beverages, cleaning agents and personal care products. Unilever operates in over 180 countries with over 170 billion products bought by consumers globally yearly.
- Critical authorization objects such as S_TABU_DIS, S_PROGRAM, and S_DEVELOP were restricted and monitored.
- Provided Post Go-live support on role modification
- Used SU24 for new custom T-Code update.
- Created and maintained Single, Composite, Derived, and Business Roles using PFCG.
- Performed SU24 proposal maintenance, and authorization impact analysis during S/4HANA implementations and upgrades.
- Designed organization-level security using Company Code, Plant, Sales Organization, Purchasing Organization, and other organizational values.
- Implemented SAP Fiori Security by creating and maintaining Catalogs, Business Catalogs, Spaces, Pages, and Launchpad Roles.
- Configured and authorized OData services using /IWFND/MAINT_SERVICE and activated required SICF services.
- Assigned Business Roles, Business Catalogs, and Fiori Launchpad roles to end users based on business requirements.
- Maintained SAP Fiori Launchpad content and role-based tile visibility.
- Supported SAP S/4HANA migration, security remediation, and post go-live authorization support.
- Resolved SAP GUI and SAP Fiori authorization issues using SU53, ST01, SU56, SUIM, STAUTHTRACE, and browser diagnostics.
- Building SAP roles and define jobs by coordinating with functional project team members
- Experienced in Role administration like creating and modifying Roles (Single, Derived & Composite).
- Regularly generated internal audit reports.
- Used SU10 for mass changes of roles, role assignment to users and users' access modification e.g. Licensing, Validity change etc.
- Involved in GSK Project Horicks takeover activity to Unilever ERP.
- Performing SOD level analysis at user level on monthly basis and identifying, analysing and mitigating any open risks in the system.
- Creating SOD reporting on monthly basis and sharing with business owners.
- Analysing and processing Access requests of users and preparing the GRC Access requests reporting on monthly basis and sharing with the business owners.
- Creating FFID monthly reporting and sharing the FFID usage logs with respective controllers on monthly basis
- Involved in U2K2 role management team in creation and maintenance of business roles
- Analysing SOD conflicts at role level to identify the risks that are occurring within and cross business process and assist business in remediating or mitigating the risk.
- Created new roles for O2C, P2P and R2R processes and sub processes as per business requirements.
- Involved in design & creation of new roles in ECC, BI and APO systems as part of project requirement.
- Troubleshoot security/authorization related problems using SU53, ST01 and SUIM.
- Locking/Unlocking and changing the validity date for the users.
Authorization Specialist [AR] - Kraft BPO Solutions Pvt Ltd
(2023-05 - 2024-02)
Worked on Trinity Health Care - US project as SAP Security & GRC Access Control specialist. Environment: SAP SAP Security, GRC 12.0. Trinity Health is one of the largest not-for-profit, faith-based health care systems in the nation with 121,000 colleagues and nearly 36,500 physicians and clinicians caring for diverse communities across 27 states. The system includes 101 hospitals, 126 continuing care locations, 136 urgent care locations and many other health and well-being services.
- Complete user maintainance and Role maintainance.
- Assigning roles and authorization profiles to users.
- Extensively worked with Prof