SAP Security Analyst - Consultant
Job Location: Sunnyvale, CA
Duration: 12 months
Shift Schedule: Onsite
Summary:
Join our team in Sunnyvale, CA, as an SAP Security Analyst - Consultant, where you'll play a pivotal role in designing, building, and maintaining SAP S/4HANA security systems. This is an onsite position with a 12-month duration, offering a competitive pay rate. We are seeking local candidates who are ready to make a significant impact on our SAP security infrastructure.
Responsibilities:
- Design, build, and maintain SAP S/4HANA authorization roles and profiles using PFCG, including single, composite, and derived roles.
- Configure and secure Fiori Launchpad, including catalogs, groups, tiles, and spaces/pages for embedded and standalone Fiori deployments.
- Maintain front-end (Fiori Gateway/BTP) and back-end (S/4HANA) role synchronization, ensuring correct mapping between OData services, ICF nodes, and backend authorization objects.
- Perform user administration tasks: user creation, role assignment, mass user maintenance, and periodic access reviews.
- Troubleshoot authorization errors using SU53, ST01/STAUTHTRACE, and SU24 to resolve missing authorizations quickly.
- Support segregation of duties (SoD) analysis and remediation (risk analysis, mitigation, firefighter/emergency access management).
- Build and maintain security for Fiori apps including transactional, analytical, and factsheet app types, and coordinate with functional teams to align role design with business process requirements.
- Execute role redesign and cleanup projects, including authorization object trace analysis and role optimization (SU25 methodology).
- Support S/4HANA upgrade and migration projects with authorization impact analysis, testing, and remediation.
- Maintain documentation for role matrices, access provisioning procedures, and audit/compliance evidence.
- Respond to and resolve day-to-day SAP security tickets within SLA.
Required Skills:
- 5 years of hands-on SAP Security experience, with solid, demonstrable experience in SAP S/4HANA security and Fiori/UI5 app authorizations.
- Deep working knowledge of PFCG role maintenance, authorization objects, SU24 proposal maintenance, and derived/composite role structures.
- Practical experience securing Fiori Launchpad (catalogs, groups, spaces, pages, tiles) in both embedded (S/4HANA) and standalone (SAP BTP) scenarios.
- Experience with OData service authorization and Gateway (front-end) to back-end role alignment.
- Strong troubleshooting skills using SU53, STAUTHTRACE/ST01, SUIM, and authorization trace tools.
- Experience with SoD/risk analysis.
- Familiarity with SAP Fiori app types (transactional, analytical, factsheet) and their authorization requirements.
- Experience supporting S/4HANA implementation, upgrade, or migration projects from a security perspective.
- Ability to work independently with minimal oversight and deliver hands-on configuration, not just documentation or strategy.