Risk Consulting - Digital risk - SAP GRC - ITAC - Senior
About this role
The opportunity
We are looking for experienced professionals with SAP GRC, SAP security, ITAC and ITGC exposure to join the Risk Consulting - Digital Risk team. This role provides an opportunity to work on varied SAP GRC and IT controls engagements, develop deeper consulting skills and contribute to building a strong SAP GRC delivery capability in Kerala.
Your key responsibilities
- Support execution of SAP GRC, SAP ITAC and IT risk consulting projects across SAP ECC and SAP S/4HANA environments.
- Perform control walkthroughs, evidence review and testing for ITGC, ITAC and automated business controls in line with project methodology.
- Assist in the assessment, design and documentation of SAP IT application controls and automated controls.
- Conduct SoD and sensitive access reviews, including data analysis, rule set review, exception validation and remediation follow-up.
- Support SAP GRC Access Control testing, including workflow validation, access risk analysis, emergency access and user access review activities as applicable.
- Prepare and maintain project deliverables such as RCMs, testing workpapers, issue logs, evidence trackers and status updates.
- Assist with data extraction and analysis for access management, control monitoring, process compliance and audit support.
- Collaborate with internal teams, client stakeholders and audit teams to collect system/process information and close documentation gaps.
- Follow firm quality standards for testing, documentation and deliverable preparation.
- Communicate clearly and proactively to support issue resolution, follow-up and project delivery.
Skills and attributes for success
- Strong spoken and written English with clear business communication skills.
- Analytical, organized and detail-oriented approach to testing, documentation and evidence review.
- Ability to work well under pressure and deliver quality outputs within defined deadlines.
- Strong collaboration skills with the ability to work with internal teams, clients and auditors.
- Good understanding of project discipline, task ownership and quality expectations.
- Proficiency in MS Office, working knowledge of Excel, Power BI, ACL or similar data analysis tools is preferred.
- Flexibility to travel to onsite locations at short notice, based on client and engagement requirements.
To qualify for the role, you must have
- 3-6 years of experience in SAP GRC, SAP security, SAP ECC, SAP S4 HANA, IT audit, compliance testing or technology risk consulting.
- Exposure to SAP is required, exposure to SAP ECC/S/4HANA security, Oracle security or other ERP security models is preferred.
- Understanding of ERP system landscapes, access control concepts, SoD, sensitive access and user access review processes.
- Knowledge of ITGC, ITAC, RCM documentation, testing methodology and issue documentation.
- Exposure to SOX, ICOFR, internal audit or IT risk standards.
- Strong Excel and documentation skills with attention to evidence completeness and workpaper quality.
- Bachelor’s degree in Information Systems, Computer Science, Accounting, Finance or a related discipline.
Ideally, you will also have
- SAP GRC, CISA, ISO 27001, Oracle security or other relevant certifications.
- Experience supporting SAP GRC Access Control implementation/testing or SAP security role review projects.
- Exposure to S/4HANA access, user provisioning workflows, SoD rule set testing or controls automation.
- Prior experience supporting MENA clients, internal audit teams or external audit engagements.
What working at EY offers
At EY, you will work on meaningful and varied client engagements while developing through coaching, practical experience and structured feedback. You will be part of an interdisciplinary environment that values quality, knowledge sharing and professional growth.
- Support, coaching and feedback from engaging colleagues.
- Opportunities to develop new SAP GRC, IT risk and audit skills.
- The freedom and flexibility to handle your role in a way that is right for you.
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.
- Start applying with LinkedIn
- Apply Now Start
-
Please wait...
- Connect with us
- Our locations
- My EY
- Site map
- Legal and privacy
- Labor condition applications
- Cookie Consent Manager
-
Opens in a new tab.
-
Opens in a new tab.
-
Opens in a new tab.
-
Opens in a new tab.
-
Opens in a new tab.
EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.
×Cookie Consent Manager
When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. Because we respect your right to privacy, you can choose not to allow some types of cookies. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.
Required Cookies
These cookies are required to use this website and can't be turned off.
Required Cookies Show More Details Required Cookies Provider Description Enabled