Introduction
A career in IBM Consulting is built on long-term client relationships and close collaboration worldwide. You’ll work with leading companies across industries, helping them shape their hybrid cloud and AI journeys. With support from our strategic partners, robust IBM technology, and Red Hat, you’ll have the tools to drive meaningful change and accelerate client impact. At IBM Consulting, curiosity fuels success. You’ll be encouraged to challenge the norm, explore new ideas, and create innovative solutions that deliver real results. Our culture of growth and empathy focuses on your long-term career development while valuing your unique skills and experiences.
Your role and responsibilities
The primary objective is to secure SAP landscapes and ensure compliance with regulations and standards. This involves:
- Protecting sensitive business data (financial, HR, supply chain).
- Preventing unauthorized access and fraud.
- Ensuring governance, risk, and compliance (GRC).
- Supporting audits and regulatory requirements (e.g., SOX, GDPR, LGPD).
Responsible for designing and maintaining secure SAP environments:
- User Access Management.
- Create, modify, and deprovision user accounts.
- Implement role-based access control (RBAC).
- Enforce Segregation of Duties (SoD).
- Authorization Design.
- Define roles and profiles aligned with business functions.
- Minimize excessive privileges (principle of least privilege).
- Authentication & Identity Controls.
- Integrate SAP with identity providers (SSO, MFA).
- Manage secure authentication mechanisms.
Required technical and professional expertise
Governance, Risk & Compliance (GRC)
Strong understanding of:
- Segregation of Duties (SoD) principles.
- Risk identification and mitigation strategies.
- Internal controls frameworks (e.g., SOX, COSO).
- Access risk analysis and remediation.
- Control design, testing, and documentation.
- Audit lifecycle (planning → execution → evidence → remediation).
Regulatory & Data Privacy Knowledge
Familiarity with regulations such as:
- SOX (financial controls).
- GDPR / LGPD (data privacy).
- ISO 27001 / NIST frameworks.
- Translate regulatory requirements into SAP controls.
- Support audit readiness and compliance reporting.
Stakeholder & Communication Skills
Ability to collaborate with:
- Translating technical risks into business impact.
- Writing policies, procedures, and audit documentation.
- Leading access reviews and governance meetings.
Risk Management & Analytical Thinking
Ability to:
- Prioritize vulnerabilities based on impact.
- Balance security vs. usability/business needs.
Preferred technical and professional experience
SAP Security Implementation Knowledge (Preferred):
- Experience with implementing security controls and solutions to protect SAP systems from cyber threats, ensuring compliance with relevant regulations and standards, would be beneficial.
- Compliance Advisory Expertise: Familiarity with advising clients on SAP cybersecurity and compliance best practices, identifying areas for improvement and providing recommendations for remediation, is advantageous.
- Security Solution Validation Skills: Knowledge of testing and validating the effectiveness of security controls and solutions implemented in SAP environments would be an asset.
IBM is committed to creating a diverse environment and is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, caste, genetics, pregnancy, disability, neurodivergence, age, veteran status, or other characteristics. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.