Overview
Company
Profile match
Impact
Conditions
Benefits
Hiring process
Similar jobs

RSM

RSM US LLP is the leading U.S. provider of assurance, tax and consulting services focused on the middle market.

We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled, inclusive culture and talent experience and our ability to be compelling to our clients. You’ll find an environment that inspires and empowers you to thrive both personally and professionally. There’s no one like you and that’s why there’s nowhere like RSM.

About RSM USI and Risk Consulting

RSM USI supports RSM U.S. engagement teams across risk consulting, transaction advisory, technical accounting, financial consulting, technology and management consulting, tax, and assurance by providing access to skilled professionals across an extended business day. RSM US Integrated Services India Private Limited is a member of RSM International, the sixth largest global network of independent accounting, tax, and consulting firms. RSM’s vision is to be the first-choice advisor to middle market leaders globally.

Risk Consulting helps clients address complex strategic, operational, compliance, technology, and governance challenges across dynamic business environments. The practice provides services across ERP advisory, automation and analytics, internal audit, SOX advisory, IT and technology audits, cybersecurity risk management, third-party risk management, SOC1/SOC2, governance risk and compliance, privacy and security risk, managed security services, digital forensics, incident response, and related risk advisory areas.

The Business Application Risk Solutions (BARS) practice supports consulting, internal audit, and external audit clients by bringing deep ERP, process automation, data analytics, security, controls, and governance capabilities. The ERP risk practice focuses on governance, risk, security, and compliance across the full lifecycle of core business applications, from implementation through steady-state operations.

About the Role

We are seeking an experienced SAP Security, GRC, and Controls Integration professional to help lead and scale the SAP Security, Controls and GRC capability within the BARS practice. The role will involve leading client engagements, overseeing delivery quality, developing team capability, supporting practice growth, and working closely with U.S. and India leadership.

The ideal candidate should be able to think strategically about risk, controls, and access governance, while also being hands-on and delivery-focused. This role requires experience scoping, supervising, and executing SAP implementation risk assessments, SAP Security, SAP GRC, segregation of duties, controls transformation, process automation, data analytics, continuous controls monitoring, and managed services engagements.

The candidate will play a key role in growing the practice, supporting billable client engagements, developing India-based delivery capability, identifying automation opportunities, and contributing to sales, solutioning, and practice development initiatives. The role will report to the U.S. BARS Director, with a dotted-line relationship to the U.S. BARS Practice Leader and India BARS Practice Leader.

Qualification and Minimum Entry Requirements

  • Bachelor’s or master’s degree in Engineering, Technology, Information Systems, Business, Finance, or a related discipline.
  • Minimum 10+ years of professional experience in SAP Security, SAP GRC, IT controls, risk advisory, technology consulting, managed services, or a related compliance domain.
  • Prior experience with a public accounting firm, large consulting organization, or global delivery environment is preferred.
  • Deep expertise in SAP Security across SAP ECC and SAP S/4HANA, including authorization concepts, role design, authorization object analysis, access troubleshooting, Fiori authorizations, and access remediation.
  • Strong hands-on experience with SAP GRC Access Control, including ARA, ARM, EAM, BRM, MSMP workflows, BRF+, connectors, synchronization jobs, ruleset maintenance, risk analysis, and mitigation controls.
  • Practical experience with SAP GRC Process Control, including control design, automated monitoring, business rules, data sources, control testing, and continuous controls monitoring.
  • Strong understanding of internal controls, SOX compliance, segregation of duties, sensitive access, user access management, IT application controls, and audit support requirements.
  • Experience leading complex SAP Security and GRC engagements across implementation, transformation, assessment, optimization, controls, and managed services programs.
  • Experience managing delivery teams, reviewing work products, mentoring resources, and building technical capability within SAP Security and GRC teams.
  • Ability to support business development through proposal support, solutioning, effort estimation, client discussions, practice credentials, and development of reusable assets.
  • Exposure to other GRC, identity governance, access management, compliance, control monitoring, or risk management tools will be an added advantage.
  • Exposure to SAP Joule, SAP BTP, SAP IAG, SAP Cloud Identity Services, automation, analytics, AI-enabled controls, and emerging SAP technologies would be beneficial.
  • Experience with SAP HANA, BW/BI, Ariba, IBP, MDG, SuccessFactors, BDC, SAC, or other SAP public cloud and integrated applications will be preferred.
  • Experience with SOX, COSO, COBIT, ISO, NIST, HIPAA, FDA, and other IT controls methodologies and frameworks is a plus.
  • Strong project management, stakeholder management, communication, analytical thinking, problem-solving, and leadership skills.
  • Ability to identify talent, groom resources, support structured capability development, and contribute to scaling the SAP Security and GRC practice.
  • Demonstrated ability to work in high-pressure client delivery environments while managing competing priorities and maintaining quality standards.
  • Excellent verbal, written, and interpersonal communication skills in English, as the position requires frequent communication with RSM International clients.
  • Relevant certifications such as SAP Security, SAP GRC, CISA, CRISC, CISSP, CISM, or equivalent certifications will be preferred.

Position and Key Responsibilities

  • Lead the SAP Security and GRC team within the Business Application Risk Solutions practice and support capability growth across delivery, people development, methodologies, and market-facing initiatives.
  • Lead end-to-end SAP Security and GRC engagements across implementation, transformation, assessment, optimization, controls transformation, and managed services programs.
  • Manage SAP Security and controls workstreams in SAP ECC and SAP S/4HANA environments, including requirements gathering, solution design, role build, testing, deployment, cutover, hypercare, and post-go-live support.
  • Lead SAP Security design and access governance activities, including role design, role redesign, authorization troubleshooting, Fiori authorizations, SoD analysis, sensitive access reviews, emergency access management, user access reviews, and access remediation.
  • Lead SAP GRC Access Control implementation and enhancement activities across ARA, ARM, EAM, BRM, MSMP workflows, BRF+, ruleset design, risk analysis, mitigation controls, connectors, synchronization jobs, and related GRC configuration activities.
  • Support SAP GRC Process Control initiatives, including control framework mapping, risk and control configuration, automated monitoring, business rules, data sources, control testing, and continuous controls monitoring.
  • Translate business process, compliance, audit, and internal control requirements into practical SAP Security and GRC solutions aligned with client risk and regulatory requirements.
  • Advise clients on SAP Security and access governance considerations across integrated SAP landscapes, including Fiori, HANA, BW/BI, BTP, Ariba, IBP, MDG, SuccessFactors, and other SAP applications, as applicable.
  • Manage client stakeholders, engagement plans, project timelines, issue resolution, deliverable quality, and team performance across multiple concurrent engagements.
  • Provide a first-choice advisor experience to clients by delivering practical recommendations, maintaining strong client relationships, and ensuring high-quality engagement outcomes.
  • Lead, groom, and mentor SAP Security and GRC team members through technical guidance, quality reviews, coaching, training, and structured capability development.
  • Identify talent, hire, mentor, coach, and ensure the continuous professional development of staff is being met.
  • Develop reusable methodologies, solution accelerators, delivery templates, training materials, knowledge repositories, and other practice assets to support consistent and scalable delivery.
  • Contribute to business development activities, including opportunity qualification, proposal development, solution design, effort estimation, client presentations, and practice credentials.
  • Work collaboratively with automation, analytics, business process, application controls, and risk advisory specialists to address client ERP risk management needs in a holistic manner.
  • Maintain awareness of emerging SAP technologies, including SAP Joule, SAP BTP, SAP IAG, SAP Cloud Identity Services, automation, analytics, and AI-enabled risk and controls solutions.
  • Support execution of the practice growth strategy by contributing to internal initiatives related to talent development, methodology enhancement, market offerings, and capability scaling.
  • Ensure engagement documentation, deliverables, and work products are compliant with firm quality standards and demonstrate sound professional judgment.
  • Experience working with a team to provide services to numerous clients simultaneously.
  • Must exhibit and have demonstrated excellent organization and project management, communication, interpersonal, and team collaboration skills.

Professional Conduct and Firm Expectations

  • Successfully integrate the strategy and core values of the firm.
  • Heighten the firm brand by demonstrating thought leadership and embracing the firm's marketing campaigns and related programs supported by the firm.
  • Professionally presents themselves at all times at the office and the client’s meetings. This includes but is not limited to appearance, communication, and actions.
  • Exercise professional skepticism, maintain confidentiality, and adhere to applicable professional standards, firm policies, and code of ethics while delivering client engagements.
  • Work collaboratively as a part of the team and communicate effectively with RSM consulting professionals, supervisors, and senior management in the U.S. on a daily basis.

At RSM, we offer a competitive benefits and compensation package for all our people. We offer flexibility in your schedule, empowering you to balance life’s demands, while also maintaining your ability to serve clients. Learn more about our total rewards at https://rsmus.com/careers/india.html.

RSM does not tolerate discrimination and/or harassment based on race; colour; creed; sincerely held religious beliefs, practices or observances; sex (including pregnancy or disabilities related to nursing); gender (including gender identity and/or gender expression); sexual orientation; HIV Status; national origin; ancestry; familial or marital status; age; physical or mental disability; citizenship; political affiliation; medical condition (including family and medical leave); domestic violence victim status; past, current or prospective service in the Indian Armed Forces; Indian Armed Forces Veterans, and Indian Armed Forces Personnel status; pre-disposing genetic characteristics or any other characteristic protected under applicable provincial employment legislation.

Accommodation for applicants with disabilities is available upon request in connection with the recruitment process and/or employment/partnership. RSMis committed to providing equal opportunity and reasonable accommodation for people with disabilities. If you require a reasonable accommodation to complete an application, interview, or otherwise participate in the recruiting process, please send us an email at [email protected].

Recommended for you based on this role

Similar stack
Same company
In your city
$78k – $147k per year • In office • Full-Time • San Francisco
Cybersecurity
HIPAA
ISO 27001
PCI DSS
SOC 2
Apply
Career impact
Discover how this job can transform your career
Get a personal career forecast for this job - salary uplift, next-level role, skill boost and a 3-year financial impact, all calculated from your profile.
Personal salary uplift vs. your current pay
Your 3-year career trajectory
Skills you will level up in this role
3-year financial impact in dollars
Create free account
Free forever • Less than a minute • No credit card

Work setup

Location
Gurgaon
Remote work
In office
Employment
Full-Time

Compensation

Benefits
Professional development