SAP ERP Security Specialist APAC
Merck Group · Bengaluru, Karnataka, India
Merck Group · Bengaluru, Karnataka, India
Work Your Magic with us! Ready to explore, break barriers, and discover more? We know you’ve got big plans – so do we! Our colleagues across the globe love innovating with science and technology to enrich people’s lives with our solutions in Healthcare, Life Science, and Electronics. Together, we dream big and are passionate about caring for our rich mix of people, customers, patients, and planet. That's why we are always looking for curious minds that see themselves imagining the unimaginable with us. The SAP ERP Security Specialist is responsible for safeguarding the security architecture across SAP S/4HANA and SAP ECC landscapes, ensuring alignment with enterprise security frameworks. This role involves managing user access governance, compliance management, and integrating security controls into critical business processes. Additionally, the specialist will monitor SAP systems for vulnerabilities, conduct risk assessments, and drive continuous improvement in security processes. Collaboration with cross-functional teams and strategic leadership in security governance are key aspects of this position, ensuring effective communication of security risks to stakeholders and counterparts. Key Accountabilities Process and System Responsibility - Enterprise SAP Security Strategy & Architecture Ownership- Ensure architecture and security level meet the IT/OT Cyberscurity SOP. Support the end-to-end security architecture across SAP S/4HANA and SAP ECC landscapes. Define and govern role design standards, authorization concepts, Fiori security architecture, and cross-system integration controls. Ensure alignment with enterprise security frameworks and business process requirements. - Implement and enforce Zero Trust – enable security principles within SAP ERP landscapes, ensuring strict identity verification, least-privilege access, and continuous authentication across SAP applications, users, and integrated systems. Learn the new trend, threat, and new challenges in cybersecurity area. Like Zero Trust, Double Zero - Access Governance & Compliance Management- Manage user access provisioning, modifications, and de-provisioning in line with internal policies and regulatory standards (e.g., SOX, GDPR where applicable). Perform regular access reviews, SoD analysis, and audit support to ensure ongoing compliance. - System Monitoring & Risk Management- Monitor SAP systems for security risks, vulnerabilities, and unauthorized activities. Conduct risk assessments, support remediation plans, and ensure timely resolution of security incidents related to SAP ERP platforms. - Process Ownership & Security Integration- Act as the security process owner for SAP ERP environments, embedding security controls into business processes such as Finance, Procurement, Supply Chain, and HR. Collaborate with functional teams to ensure secure configuration and change management practices. - Continuous Improvement & Stakeholder Collaboration- Drive continuous improvement of SAP security processes, including automation, Cybesecurity tool optimization, and documentation updates. Provide guidance and training to business users, IT teams, and management on SAP security best practices and governance standards. Collaboration - Security & Governance Stewardship- Provide the SAP security governance across S/4HANA and ECC platforms. Support security review boards, define policy standards, and ensure consistent enforcement of global SAP access and control frameworks. Support to resoluve the daily incidnets and tasks related to security topics. - Cross-Functional & Executive Collaboration- Partner closely with Business Process Owners, IT leadership, Internal Audit, Risk & Compliance, and external auditors to align SAP security with enterprise risk strategy. Translate technical security risks into business-impact language for executive stakeholders and steering committees. - Transformation & Change- Lead security workstreams during SAP implementations, upgrades, rollouts, and S/4HANA and ECC transformation programs. Drive organizational change by promoting secure-by-design principles, influencing stakeholders, and ensuring security requirements are embedded early in project lifecycles Impact and Performance Management - Supportive for the liaison & enablement team’s results, impacting performance of related Cybersecurity Operation teams through effective demand, capacity and change management. - Meet key KPIs (e.g., demand throughput, lead times, change success rate, capacity utilization, compliance) and drives performance improvements. - Develops and applies policies and guidelines to enhance cybersecurity operational efficiency and process consistency in Cybersecurity Operation liaison and enablement. - Efficent and Effevively support the cybersecurity tasks to meet the SOP and KPI. Complex Problem-Solving - Analyzing skills-Analyzes complex information (e.g., audit findings, security advisories, demand/capacity data, vendor input) to support sound decision-making. - Sustanable and Reslience solution- Addresses operational challenges across demand, security, testing, release and lifecycle processes with sustainable solutions. **Technology Skills** - Minimum 2 years of experience in SAP solution consulting, with a strong track record in solution design, and full-cycle product implementations. - Good knowledge on SAP system components, architecture, technical integration concept, ABAP and API. - Experience on SAP BASIS, Unix system administrator. - Deep understanding of SAP security and authorization concepts, including access control, authentication and data protection. - Hands-on experience with SAP security administration and risk management (roles/profiles, provisioning, policy maintenance, risk assessment) and relevant security/compliance standards (e.g., NIS, KRITIS, GDPR, SOX). - Proficiency with test and release management tools, ticketing systems, SAP security tools/tra