Über diese Global Senior Solution Engineer: SAP GRC Stelle bei Sandoz
Job Description Summary
The SAP GRC SME is accountable for the end-to-end ownership, governance, and continuous improvement of SAP Roles, Authorizations, and Governance, Risk & Compliance (GRC) processes across the enterprise SAP landscape. The role serves as the functional and technical authority for SAP access governance, ensuring regulatory compliance, segregation of duties (SoD) integrity, and risk-based access controls that support business operations and digital transformation initiatives.Job Description
Global Senior Solution Engineer: SAP GRC
Sandoz continues to go through an exciting and transformative period as a global leader and pioneering provider of sustainable Biosimilar and Generic medicines. As we continue down this new and ambitious path, unique opportunities will present themselves, both professionally and personally. Join us, the future is ours to shape!
Job Summary
The SAP GRC SME is accountable for the end-to-end ownership, governance, and continuous improvement of SAP Roles, Authorizations, and Governance, Risk & Compliance (GRC) processes across the enterprise SAP landscape. The role serves as the functional and technical authority for SAP access governance, ensuring regulatory compliance, segregation of duties (SoD) integrity, and risk-based access controls that support business operations and digital transformation initiatives.
Your Key Responsibilities
Your responsibilities include, but are not limited to:
Major accountabilities:
SAP Security & Authorization Ownership
- Own and govern the SAP role design, authorization concept, and access control framework across the enterprise SAP ecosystem. Serve as the primary Subject Matter Expert for SAP Security, Roles, Authorizations, and GRC solutions.
- Define and maintain role design standards, authorization governance policies, and access management procedures.
- Ensure role structures remain scalable, compliant, and aligned with evolving business processes.
- Lead periodic reviews and optimization of user access and security models.
- Governance, Risk & Compliance (GRC)Accountable for global SAP GRC governance, including Access Risk Analysis, Emergency Access Management, Access Request Management, and Role Management processes.
- Establish and maintain Segregation of Duties (SoD) controls and risk mitigation strategies.
- Ensure adherence to internal control frameworks, regulatory requirements, and pharmaceutical compliance standards.
- Lead remediation of audit findings and continuously enhance control effectiveness.
- Develop governance mechanisms to proactively identify and mitigate access-related risks.
Compliance & Audit Management
- Act as the primary liaison for internal and external audits related to SAP security and access controls.
- Support regulatory inspections and compliance assessments.
- Ensure evidence collection, control documentation, and audit readiness across all SAP environments.
- Drive closure of audit observations through sustainable corrective and preventive actions.
Stakeholder Management
- Partner with Global Process Owners, Compliance, Quality, Internal Controls, Audit, Digital & IT organizations.
- Influence decision-making through expert guidance on security, risk, and compliance matters.
- Communicate complex authorization and risk topics to both technical and business audiences.
Key performance indicators:
- Stable -compliant -secure -and cost-effective operations measured by Availability -Performance -Capacity Metrics along with continuous cost reductions YOY -Responsiveness and Recovery Speed of critical incidents / issues in business -Automation led Programmable Infrastructure and Platform Services
Minimum Requirements
What you’ll bring to the role:
- 15+ years of experience in SAP Security, Roles & Authorizations, and SAP GRC.
- Strong expertise in SAP ECC, S/4HANA, SAP GRC Access Control, and enterprise authorization concepts.
- Proven experience designing and governing global role-based access control models.
- Deep understanding of Segregation of Duties (SoD), risk management, and audit requirements.
- ITIL Foundation Certification.
- SAP Security and/or SAP GRC certifications.
- Experience with SAP S/4HANA transformation programs.
- Experience with Identity & Access Management (IAM) solutions and enterprise security frameworks.
- Pharmaceutical, Life Sciences, Healthcare, Manufacturing, or other regulated industry experience is a plus but not mandatory.
- Exposure to GxP-compliant or validated environments is advantageous.
Skills:
- Deep knowledge of SAP Roles & Authorizations design and governance
- Ability to translate business requirements into security solutions
- Role-based access control (RBAC) design and optimization
- Authorization troubleshooting and risk assessment.
- Security architecture and secure-by-design principle
- IT Service Management.
- Problem Solving Skills.
- System Integration.
- Vendor Management.
Qualifications
- Bachelor’s degree in Computer Science, Information Technology or related disciplines
Why Sandoz?
Generic and Biosimilar medicines are the backbone of the global medicines industry. Sandoz, a leader in this sector, provided more than 900 million patient treatments across 100+ countries in 2024 and while we are proud of this achievement, we have an ambition to do more!
With investments in new development capabilities, production sites, new acquisitions, and partnerships, we have the opportunity to shape the future of Sandoz and help more patients gain access to low-cost, high-quality medicines, sustainably.
Our momentum is powered by an open, collaborative culture driven by our talented and ambitious colleagues, who, in return for applying their skills experience an agile and collegiate environment with impactful, flexible-hybrid careers, where diversity is welcomed and where personal growth is supported!
Join us!
#Sandoz
Skills Desired
Communication Skills, IT Infrastructures, IT Operations, IT Service Management, Problem Solving Skills, System Integration, Vendor Management