As a recruitment partner and consulting firm specialized in information technology, NOVIPRO is currently supporting a leading organization in the manufacturing sector in its search for a technical specialist for a strategic mandate in SAP governance.
Key Details
Job Title: GRC SAP – CRUD Process Specialist
Mandate Duration: 6 months
Work Schedule: 35 hours per week
Location: 100% remote within Canada
Time Zone: Eastern Daylight Time (EDT)
Language: English or bilingual (French/English)
Employment Type: Contract mandate through NOVIPRO
Responsibilities
CRUD Control Review Process (Bi-weekly):
Conduct detailed reviews of custom SAP transactions (Create, Read, Update, Delete) across three SAP landscapes (2 ECC instances and 1 S/4HANA).
Extract and interpret data from SAP system tables to support documentation and analysis.
Prepare audit-ready working papers that log transactional changes and highlight items needing further scrutiny.
Collaborate closely with SAP technical teams to validate and update documentation.
Evaluate documentation for completeness and compliance with internal control frameworks.
Perform Segregation of Duties (SoD) assessments and risk mitigation reviews, including the analysis of system activity logs.
Archive all relevant evidence within designated compliance repositories.
Submit finalized analyses for BRP SOX Team validation and formal sign-off.
Daily Operations:
Monitor the dedicated custom transaction mailbox and address CRUD approval inquiries promptly.
Maintain and update internal tracking systems for CRUD-related activities.
Liaise with internal audit stakeholders to support ongoing approval workflows.
Coordinate follow-ups with technical teams post-implementation.
Ensure full approval cycle is completed in accordance with governance workflows before closure of items.
Required Experience and Expertise
Demonstrated experience with SAP Authorization concepts and user access control (SAP Security).
Working knowledge of ABAP-level security principles and SAP Authorization Objects.
Solid understanding of SAP GRC Access Control, including Rule Set configuration and SoD management.
Proficient in interpreting technical SAP system data and log outputs.
Strong skills in documentation and technical communication.
Experience in environments governed by SOX or audit-compliant frameworks is considered an asset.