SAP Security & GRC Engineer
SAP Security & GRC Engineer
Job Title: SAP Security & GRC EngineerSalary Range: 100k$/Annum-150k$/Annum
Location: 100% Remote (Continental United States)
Position Type: In-house Bright Vision Technologies SOW engagement (no third-party client or vendor)
Experience: 5+ years
Sponsorship: No new H1B sponsorship available. H1B transfers welcomed for qualified candidates.
Employment Type: Full-time, direct W2 with Bright Vision Technologies (no C2C, no 1099, no third-party)
Engagement: Long-term, multi-year, aligned to the Bright Vision SOW delivery roadmap
Compensation: Competitive base salary commensurate with experience, plus benefits.
Employment Terms & Visa Policy
This is a 100% remote, full-time, direct W2 position with Bright Vision Technologies.
This role is part of Bright Vision Technologies’ in-house Statement of Work (SOW) engagement. The client, end customer, and employer for this position is Bright Vision Technologies — there is no third-party client, vendor, or implementation partner involved.
We do not engage in C2C, 1099, or third-party arrangements for this role.
BUT STRICTLY NO C2C/1099/3RD PARTY COMPANIES. ALL OUR ROLES ARE W2 AND NO 3RD PARTY BROKERING PLEASE.
Candidates must be willing to work directly as a full-time W2 employee of Bright Vision Technologies and contribute to our in-house SOW deliverables.
No new H1B sponsorship is available for this role.
However, candidates who are currently on a valid H1B visa and require a transfer are welcome to apply. We will support H1B transfers for qualified candidates.
For every role, a technical coding assessment is mandatory. Please apply only if you are confident in your technical abilities and hands-on experience.
Job Summary
We are seeking an experienced SAP Security and GRC (Governance, Risk, and Compliance) Engineer to design, implement, and operate security and access-control frameworks for complex SAP landscapes, including S/4HANA, ECC, BW/4HANA, Fiori, BTP, and SuccessFactors. In this role you will be responsible for SAP role design, user provisioning, segregation-of-duties analysis, audit support, and the technical operation of SAP GRC suites. The ideal candidate will combine deep expertise in SAP authorization concepts with strong hands-on experience operating SAP GRC Access Control and Process Control, and will partner closely with audit, compliance, and business teams to deliver a secure, auditable SAP environment.
Key Responsibilities
- Design and maintain SAP authorization concepts and role structures aligned with business processes and least-privilege principles.
- Build and maintain master, derived, composite, and business roles for S/4HANA, ECC, and Fiori applications.
- Configure and operate SAP GRC Access Control (ARA, ARM, BRM, EAM), including ruleset management, mitigating controls, and emergency access management.
- Perform segregation-of-duties analysis and remediation in collaboration with business process owners and internal audit.
- Configure user provisioning workflows in SAP GRC ARM, including request types, approval paths, and integration with IDM/IAM platforms.
- Operate SAP GRC Process Control for continuous controls monitoring and policy management.
- Implement security for Fiori applications, including catalogs, groups, and front-end authorizations.
- Configure and operate security for SAP BTP and cloud applications using XSUAA, IAS, and IPS.
- Support SAP audits (SOX, GxP, PCI) and respond to audit findings with documented remediation plans.
- Implement transport security, table logging, and audit logging in line with internal security policies.
- Monitor and remediate SAP Security Notes in coordination with Basis and DBA teams.
- Maintain comprehensive, current technical documentation — including architecture diagrams, design decisions, configuration references, runbooks, and operational procedures — so that the system remains supportable, auditable, and easy to onboard new engineers onto over time.
- Mentor junior team members and support knowledge transfer across the security team.
- Bachelor’s degree in Computer Science, Engineering, or a related technical discipline.
- Five or more years of SAP Security / GRC experience in enterprise landscapes.
- Strong hands-on experience with SAP authorization concepts and role design.
- Deep experience operating SAP GRC Access Control (ARA, ARM, BRM, EAM).
- Experience supporting SAP audits and remediation activities.
- Hands-on experience securing Fiori, BTP, and cloud SAP applications.
- Familiarity with SAP IDM or third-party IGA tooling.
- Working knowledge of SAP Process Control.
- Strong understanding of regulatory frameworks such as SOX, GxP, and PCI.
- Excellent communication and documentation skills.
- SAP-certified Security or GRC credentials.
- Experience with SAP Cloud Identity services (IAS, IPS) and SCIM-based integrations.
- Familiarity with HANA security and analytic privileges.
- Experience with continuous controls monitoring frameworks.
- Exposure to SAP RISE / Grow security operating models.
Would you like to know more about this opportunity?
For immediate consideration, please send your resume to [email protected] or contact us at (908) 650-6699. Learn more about Bright Vision Technologies at
We recognize that our people are our strength, and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company.
We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs.
Bright Vision Technologies is an Equal Opportunity Employer, including Disability/Veterans.
Position offered by “No Fee Agency.”
Equal Employment Opportunity (EEO) Statement
Bright Vision Technologies (BV Teck) is committed to equal employment opportunity (EEO) for all employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, veteran status, or any other protected status as defined by applicable federal, state, or local laws. This commitment extends to all aspects of employment, including recruitment, hiring, training, compensation, promotion, transfer, leaves of absence, termination, layoffs, and recall.
BV Teck expressly prohibits any form of workplace harassment or discrimination. Any improper interference with employees' ability to perform their job duties may result in disciplinary action up to and including termination of employment.
Recommended Jobs
Certified Medical Assistant
Job Description Job Description Pulse MD Urgent Care is hiring Medical Assistants for our Briarcliff location. ROLE AND RESPONSIBILITIES The medical assistant aids providers (MDs, NPs, PAs,…
Consulting-Bus Con-Digital and Product Strategy-Pdt Mgmt-Manager - Multiple Positions-1710256
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities. At EY, you’ll have the chance to build a career as unique as you are…
Field Service Engineer
IT Field Technician (1–3 Years of Experience) Applicants must have the flexibility to be away from home Monday through Friday. (ALL EXPENSES COVERED) Our client is seeking a well‑versed, technica…
New York - Legal Recruitment Consultant
An opportunity to join a global, partner-led legal recruitment firm as it builds out its New York City presence. This is the first of several hires for our clients NYC office, making it a standout ch…
Assistant Property Manager - The Ellsworth, Malta, NY 12020
Beware of Recruitment Fraud: We are committed to protecting job seekers from recruitment fraud. Please be aware that all official communication regarding opportunities with our firm will come exclus…
Specialist, Member Programs & Services
Job Description Job Description Salary: $76,700 - $95,875 Work Model & Compensation Eligibility: This role is eligible for incentive, bonus, or commission-based compensation. Relocation: …
Sr. Manager, Financial Planning & Analysis (FP&A)(NYC)
Location : This is a hybrid remote/in-office role. Medidata follows a hybrid office policy in which employees who are hired for an in-person position are expected to work on site a certain numb…
Nurse (Temporary)
Join a dedicated team at a New York State OASAS Certified Outpatient Substance Use Disorder Treatment Program, committed to providing high-quality, compassionate care to individuals with substance us…
Pizza Cook/ Line Cook
Decades is a pizzeria and small plates restaurant in Ridgewood, Queens. We are looking for one full time line cook with weekend availability. Pizza experience is not required, but is a plus. …
Equity Derivatives Strat - Institutional Equity - Vice President
Morgan Stanley's Equities Derivatives division is looking for a strategist/quantitative analyst for its Derivative Strat risk modelling team. Risk strategists are key participants, together with trad…