Über diese SAP Application Security Analyst Stelle bei State of North Carolina
Agency
Office of the State ControllerDivision
OSC Information TechnologyJob Classification Title
IT Security & Compliance Specialist II (NS)Position Number
60087206Grade
DT10About Us
The State Controller serves as an independent resource to protect the financial integrity of the State and to promote accountability in an objective and efficient manner through its accounting, disbursing, payroll, internal controls, data management, eCommerce, and financial reporting systems that serve state agencies, employees, and the public.
The foundational principles of the office are Integrity/Ethics, Objectivity, and Accountability. OSC’s overall goals are to optimize operational execution, manage risk effectively and efficiently, and foster a high-performance culture. OSC will provide excellent customer service while achieving those goals.
Description of Work
**Anticipated Vacancy**Internal to State Government: This vacancy is only available to current employees of the State of North Carolina including University employees.
Please Note: OSC does not use 3rd parties to conduct job interviews.
**OSC is interested in every qualified candidate who is eligible to work in the United States. However, we cannot sponsor visas at this time. **
**Successful candidate will be subject to a criminal background check. **
The mission of the Office of the State Controller (OSC) is to protect the financial integrity of the State and promote accountability in an objective and efficient manner.
NOTE: This job posting will close at 11:59 p.m. the night before the closing date.
Recruitment Range: The salary range for DT10 is $87,617 - $131,426. Salary will be based on experience and availability of funds.
The primary purpose of the Security Team within the HR/Payroll System and the NC Financial Systems is to implement and maintain all security aspects of the system landscape in a statewide security environment. The Security Team will report to the Applications Manager as well as receive directions from the HR/Payroll PMO Office and the NC Financial Systems division. This team will serve as gatekeepers for access to each functionality in the SAP Integrated HR/Payroll System, BI/BOBJ Reporting, NC Financial Systems and the Go Anywhere MFT systems. They will implement the role to position and structural authorizations concept for all users, whenever possible. This team processes all access requests for the HR / Payroll and the NC Financial Systems (NCFS) from all agencies.
The IT Security & Compliance Specialist II reports to the Applications Systems Manager and is responsible for all system and functional application security for the SAP Integrated HR/Payroll System, BI/BOBJ Systems, NC Financial Systems and monitors and assists with the implementation of new interfaces with the GoAnywhere MFT System. This position will be asked to lead security projects during agency reorganizations or the startup of a new agency due to legislative mandates.
The role is responsible for administering application security for the Oracle Fusion NC Financial System and the SAP HR/Payroll System, mentoring security team members.
Duties and Responsibilities are as follows.
Application Security Administration for Production Environments
• Maintain and support application security for the Oracle Fusion NC Financial System using industry best practices for Oracle Fusion Cloud.
• Maintain and support SAP HR/Payroll System security following SAP and industry standards.
• Adhere to statewide security documentation, policies, and procedures established by data owners.
• Process daily security requests submitted by security administrators across 60 agencies and universities via the Ivanti ticketing system.
• Apply SAP best practices for structural authorizations to ensure system efficiency and performance.
• Coordinate implementation of production role changes, new user accounts, and account enhancements.
• Maintain and protect service accounts used for batch and Boomi processing, ensuring password security and account integrity.
• Support technical and application security for tables, reports, programs, and interfaces in accordance with industry and OSC policy requirements.
Testing, QA and Training Environment Support
• Maintain and support four SAP HR/Payroll development and training landscapes and fourteen Oracle Fusion NC Financial System development and training instances.
• Manage production support staff accounts in Testing/QA environments and over 300 training accounts across multiple training clients.
Project Support
• Participate in requirements gathering, design, configuration, and testing activities for SAP security across multiple platforms.
• Research authorization objects, structural authorizations, and role enhancements required for projects.
• Establish test accounts for Oracle Fusion and SAP systems as needed.
Application Security Analysis
• Research and analyze reported security issues.
• Evaluate and design new roles or enhancements to existing roles.
• Identify potential performance issues and segregation of duties (SoD) conflicts; advise functional and technical teams on remediation.
Application Security review support with agencies
• Conduct quarterly application security reviews for OSC.
• Generate and distribute manager-level reports for sign-off.
• Assist 60 agencies and universities with quarterly reviews to ensure compliance with statewide security standards under G.S. 147 33.110.
Advance Access Control
• Support AAC monitoring jobs and processes.
• Produce quarterly SoD conflict reports for agency and university Oracle NCFS security administrators, guiding remediation or risk acceptance.
Technical Documentation/Training/Knowledge Transfer
• Develop and maintain comprehensive security documentation and procedures for OSC’s Oracle Fusion NCFS and SAP HR/Payroll Systems.
• Support cross-training and audit readiness through clear, accurate technical documentation.
Knowledge Skills and Abilities/Management Preferences
• Thorough knowledge of HR / Payroll Systems, Financial and budgetary methods and operations/practices. Ability to comprehend, analyze and interpret organizational issues/procedures to make alterations in existing systems that support the organization.
• Ability to prepare detailed and comprehensive reports and to present information clearly and concisely
• Thorough knowledge of and experience with operations/systems administration analysis and automation programming/scripting, employing complex and specialized tools/utilities, techniques, and methodologies
• Detailed understanding of technical issues to design architecture for emerging and stable technologies
• Thorough knowledge of security rules and how to grant/deny access based on users or groups
• Thorough knowledge of how data is accessed within a database and how access can be controlled
• Ability to provide and communicate security knowledge and information to other managers and agency data owners on a regular basis
• Thorough knowledge of technology architecture in a multi-layered environment, two-factor authentication, active directory integration, SAP proprietary roles and authorization objects as well as Oracle Fusion custom job roles and duty roles in a cloud-based environment
• Ability to manage statewide moderate to complex projects that can have significant impact on NC Employees in a fast-paced environment
• Knowledge of designing, developing, configuring, documenting, prototyping, testing, and implementing security protocols across multiple systems or platforms.
• Strong analytical skills and able to make proactive decisions regarding technical modifications to prevent future problems, assessing all viable options and weighing all potential consequences.
• Thorough knowledge of security rules and how to grant/deny access based on users or groups
Minimum Education and Experience
Some state job postings say you can qualify by an “equivalent combination of education and experience.” If that language appears below, then you may qualify through EITHER years of education OR years of directly related experience, OR a combination of both. See the Education and Experience Equivalency Guide for details.
Bachelor’s degree in computer science or a related IT field or closely related field from an appropriately accredited institution and two years of progressive experience in IT Security or closely related area; or Associate degree in computer science or a related IT field or closely related field from an appropriately accredited institution and three years of progressive experience in IT security or closely related area; or an equivalent combination of education and experience.
EEO Statement
The State of North Carolina is an Equal Employment Opportunity Employer and dedicated to providing employees with a work environment free from all forms of unlawful employment discrimination, harassment, or retaliation. The state provides reasonable accommodation to employees and applicants with disabilities; known limitations related to pregnancy, childbirth, or related medical conditions; and for religious beliefs, observances, and practices.
Recruiter:
Pamela Denise HammRecruiter Email:
[email protected]