368,657open jobs
9,442companies
50,883added this week
Browse all
Salary
$67k – $165k per year (Estimated)
Location
In office (Singapore)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Kyndryl is the world's largest IT infrastructure services provider, having spun off from IBM in November 2021. The company designs, builds, manages, and modernizes mission-critical technology systems for thousands of enterprise clients globally. By partnering with leading technology vendors, Kyndryl helps businesses optimize their cloud environments, cybersecurity, and digital transformation initiatives.

Who We Are

At Kyndryl, we run and reimagine the mission-critical technology systems that drive advantage for the world’s leading businesses. We are at the heart of progress; with proven expertise and a continuous flow of AI-powered insight, enabling smarter decisions, faster innovation, and a lasting competitive edge. For our people-Kyndryls-that means doing purposeful work that powers human progress. Join us and experience a flexible, supportive environment where your well-being is prioritized and your potential can thrive.

The Role

We are looking for an SAP GRC and HANA Security Consultant to design, implement, and govern access controls across our SAP landscape.

This role sits at the intersection of technical security administration and compliance: you will build and maintain role architecture across S/4HANA, HANA database, and Fiori, run our GRC Access Control platform end to end, and act as the primary technical contact for internal and external auditors on SAP access matters.

This is a hands-on position for someone who is equally comfortable writing an analytic privilege in HANA Studio, remediating a segregation-of-duties conflict in ARA, and explaining both to a non-technical control owner.

Key Responsibilities

SAP GRC Access Control

· Configure, administer, and support SAP GRC Access Control 10.1/12.0 across all four modules: Access Risk Analysis (ARA), Access Request Management (ARM), Business Role Management (BRM), and Emergency Access Management (EAM/Firefighter).

· Maintain and customize the SoD ruleset - add custom risks, functions, and organizational rules; apply SAP-delivered ruleset updates and assess landscape impact.

· Design and maintain MSMP workflows, BRF+ rules, and approval paths for access requests and role change management.

· Perform periodic risk analysis at user, role, and profile level; drive remediation and design compensating/mitigating controls with business process owners.

· Administer User Access Reviews (UAR), SoD Review, and Firefighter log reviews; track completion and escalate exceptions.

· Support GRC Process Control, Risk Management, and Audit Management where in scope, and evaluate migration to SAP Cloud Identity Access Governance (IAG).

SAP HANA Security

· Administer HANA database security: catalog and repository roles, users, system/object/analytic/package/application privileges, and privilege inheritance design.

· Implement row- and column-level security through analytic privileges, and configure static and dynamic data masking for sensitive data.

· Manage HDI container security and XS Advanced (XSA) roles, role collections, and OAuth/UAA configuration.

· Configure and monitor HANA audit policies; produce audit trails for privileged activity and support forensic review.

· Manage encryption (data volume, redo log, backup), certificate management, and TLS/SSL configuration.

· Set up and support SSO and authentication methods including SAML 2.0, Kerberos, and X.509 certificates.

· Administer security through HANA Cockpit and HANA Cloud Central, including HANA Cloud tenant security where applicable.

SAP Application Security

· Design, build, and maintain PFCG roles for S/4HANA, ECC, BW/4HANA, and Solution Manager using SU24, SUIM, and authorization trace analysis (STAUTHTRACE/ST01).

· Build and maintain Fiori security: catalogs, groups, spaces and pages, tile-to-role mapping, and front-end/back-end role pairing.

· Support security for connected platforms - SAP BTP, SuccessFactors, Ariba, SAC, and CUA-managed systems.

· Lead security workstreams for S/4HANA implementations, upgrades, and greenfield/brownfield conversions, including role redesign and remediation of legacy authorization concepts.

· Troubleshoot authorization failures and performance issues, and provide L3 support for security incidents.

Compliance, Audit, and Governance

· Serve as SAP security subject matter expert for SOX ITGC, internal audit, and external audit walkthroughs; prepare evidence and respond to audit requests and findings.

· Enforce and improve access governance policy, including provisioning, deprovisioning, privileged access, and emergency access procedures.

· Support data privacy requirements (GDPR and equivalent) as they apply to SAP access and data exposure.

· Produce documentation: role design specifications, security concepts, runbooks, and control narratives.

Delivery and Collaboration

· Work with Basis, functional, development, and infrastructure teams on cross-functional design decisions.

· Partner with business process owners to translate compliance requirements into workable role and control design.

· Mentor junior security analysts and contribute to team standards and knowledge base.

Who You Are

Required Qualifications

· Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent practical experience.

· 5+ years of hands-on SAP security experience, including at least 3 years with SAP GRC Access Control 10.x or 12.0.

· Demonstrated hands-on experience with SAP HANA security administration - roles, privileges, analytic privileges, and audit policies - not solely at the application layer.

· Strong working knowledge of PFCG role design, authorization objects, SU24 maintenance, and trace-based troubleshooting.

· Experience with S/4HANA and Fiori security concepts, including catalog and space/page design.

· Practical experience supporting SOX ITGC or equivalent audit and compliance requirements in an SAP environment.

· Proven ability to analyze and remediate segregation-of-duties conflicts and design mitigating controls.

· Clear written and verbal communication, with the ability to explain technical access risk to business and audit stakeholders.

Preferred Qualifications

· Experience with SAP Cloud Identity Access Governance (IAG) or migration from GRC AC to IAG.

· Experience with SAP Identity Management (IDM), SAP Cloud Identity Services (IAS/IPS), or third-party IGA tools such as SailPoint or Saviynt.

· Exposure to SAP BTP security, including role collections, trust configuration, and destination security.

· Experience with HANA Cloud, HDI, and XSA-based development security.

· Full lifecycle S/4HANA implementation or conversion experience in a security lead capacity.

· Scripting or automation experience (ABAP, Python, PowerShell) for reporting and provisioning tasks.

· Certifications such as SAP Certified Application Associate - GRC Access Control 12.0, SAP Certified Technology Associate - SAP HANA, CISA, CISSP, or CRISC.

Being You

The “Kyn” in Kyndryl means kinship, which represents the strong bonds we have with each other, our customers and our communities. We focus on ensuring all Kyndryls feel included and we welcome people of all cultures, backgrounds, and experiences. Even if you don’t meet every requirement, we encourage you to apply. We believe in growth, and we’re excited to see what you can bring. At Kyndryl, employee feedback has told us that our number one driver of employee engagement is belonging. That sense of belonging - being a valued, respected, trusted member of the team - is fundamental to our culture and fueling great experiences for our customers. This dedication to welcoming everyone into our company means that Kyndryl gives you the ability to thrive and contribute to our culture of empathy and shared success. That’s The Kyndryl Way.

What You Can Expect

Your career with us isn’t just a job-it’s an adventure with purpose. We offer a dynamic, hybrid-friendly culture that supports your well-being and empowers you to grow. Our Be Well programs are thoughtfully designed to support your financial, mental, physical, and social health-because we know that when you feel your best, you do your best.

From your very first day, you’ll dive into impactful work that powers the systems our customers rely on every day. You won’t just contribute-you’ll make a difference, tackling meaningful projects that sharpen your skills and fuel your growth.

We’re here to champion your journey. With powerful tools to chart your career path, personalized development goals aligned with your ambitions, and continuous feedback to keep you inspired and on track, you’ll have everything you need to thrive and evolve. You’ll develop in-demand skills to grow your career and achieve your ambitions with access to cutting-edge learning opportunities-from certifications with Microsoft, Google, and Amazon to coaching and hands-on experiences. And through it all, you’ll be part of a culture that values empathy, restless learning, and a devotion to shared success.

We want you to thrive here-and we’re committed to helping you do just that. Ready to make an impact? Join us and help shape what’s next.

Get Referred!

If you know someone that works at Kyndryl, when asked ‘How Did You Hear About Us’ during the application process, select ‘Employee Referral’ and enter your contact's Kyndryl email address.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,657 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Singapore
$93k – $140k per year • In office • Full-Time • 5+ years exp
Node JS
TypeScript
JavaScript
Node JS
Nest.JS
AI/ML
EU AI Act
OpenAI
Frontend
React.js
DevOps
Azure
Cybersecurity
GDPR
Apply
$184k – $350k per year (Estimated) • Remote/Hybrid • Internship • 15+ years exp • Bachelor's Degree • Arlington
AI/ML
Computer Vision
AI Agents
DevOps
AWS
Platform Engineering
Cybersecurity
GDPR
Apply
$173k – $369k per year (Estimated) • Remote/Hybrid • Internship • 15+ years exp • Bachelor's Degree • San Francisco
AI/ML
Computer Vision
AI Agents
DevOps
AWS
Platform Engineering
Cybersecurity
GDPR
Apply
$148k – $286k per year (Estimated) • Remote/Hybrid • Contractor • 10+ years exp • Arlington
Python
AI/ML
Computer Vision
Embeddings
PyTorch
Time Series Forecasting
DevOps
AWS
CI/CD
Docker
GCP
Git
Kubernetes
Cybersecurity
GDPR
Apply
Staff Data Engineer 3 days ago
$213k – $255k per year • Equity • Remote • Full-Time • 5+ years exp
SQL
Databases
Apache Kafka
AI/ML
AI Agents
DevOps
Amazon EKS
CI/CD
Platform Engineering
AWS
Kubernetes
Cybersecurity
GDPR
Design
Webflow
Apply
$23k – $58k per year (Estimated) • In office • Full-Time • 6+ years exp • Noida
DevOps
Incident Management
SLI/SLO/SLA
Apply
$12k – $45k per year (Estimated) • In office • Full-Time • 3+ years exp • Bengaluru
Databases
SAP HANA
DevOps
AWS
Azure
GCP
Incident Management
SLI/SLO/SLA
Apply
$28k – $69k per year (Estimated) • In office • Full-Time • 10+ years exp • Mumbai
Cybersecurity
GDPR
HIPAA
ISO 27001
PCI DSS
SOC 2
Apply
Lead AI Engineer 4 days ago
$58k – $139k per year (Estimated) • In office • Full-Time • 5+ years exp • Madrid
Java
Python
AI/ML
RAG
LLMOps
AI Agents
DevOps
AIOps
AWS
Azure
Docker
GCP
Kubernetes
Apply
$26k – $64k per year (Estimated) • Remote • Full-Time • 6+ years exp • Bachelor's Degree • Bengaluru • Chennai
Java
Java
Gradle
Maven
Spring Boot
Spring Data JPA
Spring MVC
Databases
Apache Kafka
MySQL
PostgreSQL
RabbitMQ
DevOps
Azure
Azure DevOps
CI/CD
Docker
Dynatrace
GitLab CI
Jenkins
Kubernetes
Prometheus
Rest API
GitLab
Apply
$117k – $251k per year (Estimated) • Remote/Hybrid • Full-Time • Singapore
Apply
$74k – $126k per year (Estimated) • In office • Full-Time • Singapore
Python
Apply
$88k – $191k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Singapore
C++
Java
Kotlin
Python
Mobile
JUnit
DevOps
Git
gRPC
Jenkins
JFrog Artifactory
Shift-Left
Cybersecurity
Shift-Left Security
QA
Pytest
Robot Framework
TestNG
Apply
Senior AI Architect 6 hours ago
$138k – $304k per year (Estimated) • In office • Full-Time • 6+ years exp • Bachelor's Degree • Singapore
Python
SQL
Databases
Databricks
AI/ML
AI Agents
LangGraph
OpenAI
RAG
Spark
LangChain
DevOps
Azure
Apply
$64k – $189k per year (Estimated) • Remote/Hybrid • Full-Time • 1+ year exp • Bachelor's Degree • Singapore
Python
SQL
Databases
Apache Kafka
AI/ML
Amazon SageMaker
Kubeflow
MLFlow
Spark
Vertex AI
DevOps
AWS
Azure
Azure DevOps
CI/CD
Docker
GCP
GitLab
GitLab CI
Jenkins
Kubernetes
Apply
See all jobs
This is one of many
368,657 more open roles from verified company boards, updated every day.