Job Description Summary:
Overview :
The Manager, SAP Security Controls & Governance serves as the technical lead for SAP security governance and ERP compliance controls within the IT Governance & Compliance organization. This role designs, administers, and continuously improves SAP security controls and SAP GRC capabilities, including Segregation of Duties (SoD), sensitive access, emergency access (Firefighter), role governance, and SAP GRC ruleset management.
The Manager partners with SAP Security, ERP delivery teams, business process owners, Finance, Internal Audit, and external auditors to strengthen the SAP control environment, support SOX compliance, and drive governance automation and continuous monitoring capabilities.
Key Responsibilities:
SAP Security Governance & SAP GRC:
Serve as the primary technical subject matter expert for SAP Security and SAP GRC Access Control.
Lead governance activities supporting:
Segregation of Duties (SoD)
Sensitive Access Reviews
Emergency Access Management (Firefighter)
Privileged Access Governance
User Access Reviews (UARs)
Role Owner Reviews (RORs)
Administer and maintain SAP GRC Access Control modules, including:
Access Risk Analysis (ARA)
Access Request Management (ARM)
Emergency Access Management (EAM)
Business Role Management (BRM)
Maintain SAP GRC rulesets, risk libraries, mitigating controls, and access risk reporting.
Partner with SAP Security teams to support role design, access provisioning, role optimization, and access risk remediation.
Perform risk assessments related to SoD conflicts, sensitive access, privileged access, and Firefighter activity.
Support governance activities across SAP ECC, SAP S/4HANA, SAP RISE, SAP Fiori, SAP BTP, and related SAP applications.
Control Architecture & Compliance:
Design, implement, and maintain SAP-focused IT General Controls (ITGCs) and compliance solutions supporting SOX requirements.
Develop mitigating and compensating controls to address SAP security and access governance risks.
Evaluate control effectiveness and recommend enhancements to strengthen the SAP control environment.
Support SAP transformations, migrations, upgrades, and ERP modernization initiatives by ensuring appropriate governance and compliance requirements are implemented.
Support audit and compliance activities by providing security risk analyses, evidence, reporting, and remediation support.
GRC Tools & Technology Enablement:
Configure, administer, and enhance SAP GRC and related governance technologies.
Drive automation of User Access Reviews, SoD reviews, Firefighter monitoring, and compliance reporting.
Develop dashboards, analytics, and reporting that improve visibility into access risks, control deficiencies, and remediation activities.
Collaborate with technology partners and vendors to optimize governance tools and compliance processes.
Evaluate emerging governance technologies, continuous controls monitoring capabilities, and automation opportunities.
Continuous Improvement & Monitoring:
Identify control gaps and recommend solutions to improve reliability, efficiency, and effectiveness.
Support continuous controls monitoring and compliance reporting initiatives.
Contribute to the development of governance policies, standards, procedures, and best practices.
Drive improvements that enhance automation, risk visibility, and compliance execution.
Stakeholder Collaboration:
Work closely with IT, Finance, SAP Security, Internal Audit, and business stakeholders to support compliance and governance objectives.
Provide technical guidance on SAP security controls, access governance, and risk mitigation strategies.
Support control owners and system administrators in addressing control deficiencies and remediation activities.
Qualifications:
Bachelor's degree in Information Technology, Information Systems, Cybersecurity, Computer Science, or a related field.
5+ years of experience supporting SAP Security, SAP GRC, access governance, or IT compliance programs.
Hands-on experience with:
SAP Security Authorization Concepts
Segregation of Duties (SoD)
Sensitive Access Management
Firefighter/Emergency Access Management
SAP Role Design and Governance
User Access Reviews
Experience administering SAP GRC Access Control solutions, including ARA, ARM, EAM, and BRM.
Strong understanding of SOX ITGCs and SAP compliance requirements.
Experience maintaining SAP GRC rulesets, mitigating controls, and reporting access risk.
Preferred:
Experience supporting SAP RISE, SAP S/4HANA, SAP Fiori, and SAP BTP environments.
Experience with controls automation, continuous controls monitoring, and governance analytics.
Professional certifications such as CISA, CISM, CRISC, SAP Security, or SAP GRC certifications.
What We’ll Do For You
Innovation: We embrace a culture of experimentation and innovation, providing you the opportunity to contribute to new, different, or better ways of doing things.
Agile Work Environment: We embrace agile with management that removes barriers, so you are empowered to experiment, iterate, and innovate.
Industry Leaders: Collaborate with industry leaders. Our team includes professionals who are experts in their fields, creating an environment where you can learn, grow, and make a significant impact.
Skills:
Information Technology (IT) Infrastructure, Information Technology (IT) Risk Management, Information Technology General Controls (ITGC), IT Compliance Management, IT Security ArchitecturePay Range:
United States: 124,600 - 148,200 USDBase pay offered may vary depending on geography, job-related knowledge, skills, and experience. A full range of medical, financial, and/or other benefits, dependent on the position, is offered.
Annual Incentive Reference Value Percentage:
15Annual Incentive reference value is a market-based competitive value for your role. It falls in the middle of the range for your role, indicating performance at target.
Location(s):
United States of AmericaCity/Cities:
AtlantaTravel Required:
00% - 25%Relocation Provided:
NoJob Posting End Date:
September 16, 2026Our Purpose and Growth Culture:
We are taking deliberate action to nurture an inclusive culture that is grounded in our company purpose, to refresh the world and make a difference. We act with a growth mindset, take an expansive approach to what’s possible and believe in continuous learning to improve our business and ourselves. We focus on four key behaviors - curious, empowered, inclusive and agile - and value how we work as much as what we achieve. We believe that our culture is one of the reasons our company continues to thrive after 130+ years. Visit Our Purpose and Vision to learn more about these behaviors and how you can bring them to life in your next role at Coca-Cola.
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, national origin, religion, sexual orientation, gender identity and/or expression, status as a veteran, and basis of disability or any other federal, state or local protected class. When we collect your personal information as part of a job application or offer of employment, we do so in accordance with industry standards and best practices and in compliance with applicable privacy laws.
