We use cookies to offer you the best possible website experience. Your cookie preferences will be stored in your browser’s local storage. This includes cookies necessary for the website's operation. Additionally, you can freely decide and change any time whether you accept cookies or choose to opt out of cookies to improve the website's performance, as well as cookies used to display content tailored to your interests. Your experience of the site and the services we are able to offer may be impacted if you do not accept all cookies.
Job Title: SAP Roles and Authorizations Consultant / SAP Security Administrator
An SAP Roles and Authorizations job focuses on managing user access, ensuring security compliance, and aligning system permissions with business needs. It’s a critical role in SAP security and governance.
SAP Roles and Authorizations Job Description Key Responsibilities • Design and maintain SAP roles and authorization concepts o Create single and composite roles using PFCG o Define authorization objects and field-level restrictions • User access management o Assign roles to users based on job functions o Handle user provisioning and de-provisioning across SAP modules (ECC, S/4HANA, BW, CRM, etc.) • Compliance and audit support o Ensure SoD (Segregation of Duties) compliance using tools like SAP GRC o Prepare for internal/external audits by documenting access controls • Troubleshooting and support o Resolve authorization errors and access issues (SU53, ST01) o Analyze and correct role conflicts or missing permissions
Required Skills and Experience • Strong knowledge of SAP authorization concepts, including: o Authorization objects, profiles, and role design o SU01, PFCG, SUIM, ST01, SU53 • Experience with SAP GRC Access Control • Familiarity with audit and compliance frameworks (e.g., SOX) • Ability to interpret business requirements into secure access models • Excellent documentation and communication skills
Typical Background • Degree in IT, Computer Science, or related field • 10–15 years of experience in SAP security or Basis administration • SAP certifications in security or GRC are a plus
Nice-to-Have Fiori Skills for Roles & Auths
• Experience designing Fiori roles using catalogs, groups, and apps in PFCG • Ability to configure and manage the Fiori Launchpad layout and user experience • Understanding of OData service activation and backend authorization requirements • Proficiency in troubleshooting Fiori access issues using SU53, ST01, and /IWFND/ERROR_LOG • Familiarity with navigating the SAP Fiori App Library to identify app IDs and business roles • Knowledge of integrating Fiori access requests and SoD checks within SAP GRC workflows • Awareness of CDS view authorizations and UI5 role implications in S/4HANA • Experience with Fiori tile personalization and role testing across devices • Ability to support functional teams during Fiori rollout and cutover activities • Understanding of Fiori-specific transport packaging and dependency handling
Soft Skills & Collaboration • Stakeholder Communication o Translating technical access needs into business language o Supporting functional and project teams during cutovers and go-lives • Documentation & Training o Creating role catalogs, access matrices, and user guides o Training end users and auditors on access flows
Get empowered by NTT DATA Business Solutions!
We transform. SAP® solutions into Value
NTT DATA Business Solutions is a fast-growing international IT company and one of the world’s leading SAP partners. We are a full service provider delivering everything from business consulting to implementation of SAP solutions, including hosting services and support.
When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. Because we respect your right to privacy, you can choose not to allow some types of cookies. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.
Required Cookies
These cookies are required to use this website and can't be turned off.
Required Cookies
Provider
Description
Enabled
SAP as service provider
We use the following session cookies, which are all required to enable the website to function:
"route" is used for session stickiness
"careerSiteCompanyId" is used to send the request to the correct data centre
"JSESSIONID" is placed on the visitor's device during the session so the server can identify the visitor
"Load balancer cookie" (actual cookie name may vary) prevents a visitor from bouncing from one instance to another
Advertising Cookies
These cookies serve ads that are relevant to your interests. You may freely choose to accept or decline these cookies at any time. Note that certain functionality that these third parties make available may be impacted if you do not accept these cookies.
Advertising Cookies
Provider
Description
Enabled
LinkedIn
LinkedIn is an employment-oriented social networking service. We use the Apply with LinkedIn feature to allow you to apply for jobs using your LinkedIn profile. Opting out of LinkedIn cookies will disable your ability to use Apply with LinkedIn. Cookie Policy Cookie Table Privacy Policy Terms and Conditions