Summary
Overview
Work history
Education
Skills
Certification
Affiliations
References
Quote
Timeline
Generic
SRINATH KASTALA

SRINATH KASTALA

Rugby

Summary

Proven SAP Security Architect and SAP Delivery Manager with over 17 years of experience with success in managing and delivering top notch security solutions for client's business requirements.


Extensive experience in implementing, reviewing, auditing SAP Security and related ITGC controls.

Overview

17
17
years of professional experience
5
5
Certification

Work history

SAP Delivery Manager

National Grid
Warwick, Warwickshire
05.2023 - Current
  • Responsible for Roles and Access Delivery across the organization
  • Responsible for full life cycle of the project: initiation, resourcing, execution, monitoring, control, and completion
  • Managed 8 Consultants offshore and onshore.
  • Participated in preparation of proposals and statements of work, developed project estimates, and estimated the resources needed to achieve ERP implementation success and ongoing support goals
  • Drive all phases of functional/technical implementation of the project from the planning to post go-live, ensuring the accomplishment of the desired scope, timeline, and quality
  • Collaborated with other project managers to plan scope, schedule, risk, stakeholder management, cross-team collaboration and the synchronization of effort across all other applications to drive project outcomes
  • Maintained plans and reported program status dashboards and provide regular monthly executive program status updates at Executive Steering Committee
  • Managed a high degree of change in a fast-paced, complex and demanding environment
  • Lead project(s) ensuring adherence
  • Coordinated with the Leadership team and other IT resources to solve complex problems, develop innovative solutions.
  • Solution Manage and communicate a clear vision of the project's objectives and motivated the project team to achieve them; create a project environment that enables peak performance by team members
  • Analyze risk, establish contingency plans and identify trigger events and responsibilities for initiating mitigating action
  • Escalate issues early about the project to account management or Leadership
  • Empowered project teams through motivational coaching, mentoring and development.
  • Introduced agile and lean methods to increase team capabilities.
  • Managed resources to yield high Return On Investment (ROI), raising cost-effectiveness.
  • Assessed backlogs and set key priorities to mitigate project delays.
  • Refined project policies and processes to build robust delivery systems.
  • Compromised on project objectives where outcomes could be improved with calculated risk.
  • Managed stakeholder expectations to limit concerns and queries during project delivery.
  • Set schedules of work and monitored progress to achieve timely programme delivery.
  • Directed daily operations to achieve maximum output and reduce costs.
  • Understood and balanced client and company priorities to achieve overall objectives.
  • Identified and managed risks to limit time and budget impacts.

Head of SAP

Luxfer (Chemical Industries)
Manchester
01.2021 - 04.2023

Responsibilities for Head of SAP ;


  • Responsible for the management, Development and Audit compliance of Luxfer MEL Technologies SAP S4 HANA System in the UK and the US
  • Managing key relationships with internal and external stakeholders including business end-users, management, Application support partners, SAP Consultants, Cloud hosting partner and internal/external auditing teams
  • Management and Architecting of the S4 HANA and GRC system to ensure business end-users can carry out essential business functions and are supported with issues, problems or change requests
  • Management of user roles and authorizations in line with security permissions
  • Implemented a Roadmap for S4HANA and SAP GRC Projects
  • Managed Multiple SAP Implementations
  • Technically led Change Management Board for all SAP Changes
  • Management of Azure Cloud Technologies where the SAP Servers are located
  • Project and Programme management of changes, developments, modifications and patching related activities that improve functionality or add value to the system for its end users
  • Responsible for Incident, Problem and Change Management
  • SAP IT Audit – management of several SAP applications, HANA DB and automated business General IT Controls, as part of the Sarbanes-Oxley (SoX) Programme
  • Management of AMS ticketing tool and budget allocation
  • Management of the SAP System Integrator.
  • Oversaw daily operations to achieve high productivity levels.
  • Applied critical thinking to analyse problems, evaluate solutions and select best decisions.

SAP Project Manager

TFL
London
10.2020 - 12.2020

Responsibilities of SAP Project Manager:


  • Implemented and maintained TfL's Consolidated Controls Framework (Risk maps, Process flowcharts, Risk and Control Matrices (RACM) in conjunction with operational business units
  • Developed and maintained the process for financial controls evaluation and documentation within the Control Framework-Continually developing and maintaining an effective program of controls evaluation and testing in conjunction with Group Internal Audit and TfL Finance policies
  • Overseeing the monitoring and testing of TfL's control effectiveness ensuring remediating actions and recommendations are driven through to completion
  • Supported internal and external Audit to efficiently plan and execute audits following through with closure of audit findings where necessary
  • Provided central control guidance and provided advice on an ad hoc basis and project basis as required.

SAP S/4 HANA Solutions Architect

HCL
London
03.2020 - 08.2020
  • Gathering requirements and documenting S/4 HANA Security Strategy and framework
  • Designing and building roles for S/4 HANA (Transactional / UI5), GRC 12, BW/4HANA, SOLMAN and various other systems
  • Implementation and configuration of GRC 12 with services for apps included in the ruleset
  • Designing roles for Fiori apps by adding Catalogs and Groups to S/4 HANA roles
  • Activating services for the Fiori apps in /IWFND/MAINT_SERVICE
  • Creating Catalogues and Groups using Fiori designer and creating catalogues using content manager /UI2/FLPCM_CONF
  • Documenting and implementing cut-over tasks for the S/4 HANA go-live
  • Troubleshooting and identifying the missing OData Services and authorization issues in /IWFND/ERROR LOG and notifying the Basis and Fiori configuration team to activate them
  • Optimizing the User Experience by reducing or removing unwanted groups and tiles within the groups to improve performance
  • Working with Fiori Configuration team to identify the areas where the inactive apps are generating frontend or backend authorization issues and customizing the catalogs to remove inactive apps
  • Working with business users to identify the issues with Fiori apps and resolving the authorization issues
  • Optimizing the performance by removing the unwanted apps that are not enabled from the catalogs and reducing the number of tiles on the home page which reduces the load time thereby improving the user experience
  • Providing support and issue resolution in quick turn-around during project implementation
  • Working on BW/4 HANA Security
  • Built roles for Developers, Modelers, Admin teams, Power and end users
  • Implemented/support GRC AC12, Configured GRC AC Access Risk Analysis (ARA) and Emergency Access Management (EAM) components and Access risk Management (ARM)
  • Configured MSMP workflows for addressing various user request types in Access Request Management
  • Successfully integrated LDAP active directory with SAP GRC Access control system
  • Configured the MSMP Firefighter log report workflow for getting the logs to firefighter controllers
  • Successfully implemented various MSMP Mitigation control workflows like mitigation control setup and assignment
  • Configured various BRF+ rule kinds like Initiator rule, Agent rule, Routing rule and Notification and variable rule
  • Successfully configured User Access Reviews (UAR) for assessing the user's access in all production environments.

SAP Project Manager

INFORMA UK
07.2018 - 03.2020
  • Strong knowledge of designing of roles & authorizations and implementation of a complex security framework and role matrix for SAP HANA Enterprise platform
  • Project managed the HANA upgrade from 1.0 to 2.0, created roles in system db, and configured audit policy, password policy in system DB and HANA cockpit user administration
  • Configured MSMP workflows IN GRC 10.0 for different user provisioning scenarios like new, change, terminate, lock and unlock user accounts, create complex BRF plus rules and workflows to meet the existing user management processes
  • Implemented Emergency Access Management for handling firefighter IDs, configured automatic workflows for managing emergency ID assignment and review of the firefighter logs, build firefighter IDs in remote systems, identify FF owners and reviewers and schedule batch jobs for log generation
  • Extracting and analyzing various system reports (UAR, Critical actions, SOD reports, Security parameter settings, etc.) to make sure the SAP systems are compliant
  • Established and managed a strong SAP security capability, with responsibility for security design, governance, operational support, project planning, design and execution
  • Extensive Use of ServiceNow for Incident, Problem and Change Management
  • Evaluate business risks associated with security design, implement appropriate controls to address those risks and provided recommendations on ways to simplify and streamline the security design
  • Delivering robust Access Control solutions for several applications, including identification and management of Privileged Access
  • Joiner, Mover, and Leaver processes defined and embedded with technical controls and monitoring defined
  • Development and review of key security Policies and Standards including Acceptable Use Policy, Network Security Standard, and Access Management Standard.

SAP Risks and Controls Consultant

JAGUAR LAND ROVER, UK
05.2017 - 06.2018
  • Designed and Implemented the Risk and Controls Matrix across different Business Processes
  • I.e., Finance, Manufacturing and HR
  • Liaised with different areas of the Business to understand the risks in their process and designed the mitigating controls
  • Liaising with the Business Assurance to ensure the risks and controls matrix is according to the SOX standards Controls
  • Designed IT SOX Controls Responsible for delivering a bespoke IT Access Controls Framework for a Major Transformation Programme, covering complex local legal and group compliance requirements
  • Supporting global process owners with operation and validation of mitigating controls to ensure compliance with SOX requirements and adherence to JLR policies and procedures
  • Developed the role design to fit with the Target Operating Model and ensure users have appropriate levels of access as per company policy and remediation of users with excessive system access.

SAP Senior IDM Security Consultant

Danfoss A/S Denmark
05.2016 - 03.2017
  • Independently lead and managed the implementation of SAP GRC 10.1 (ARA, ARM, BRM and EAM) and integration with IDM 7.2
  • Worked on SuccessFactors project and successfully Implemented Role-based permissions for SuccessFactors systems and migrated HR users from ECC to SuccessFactors
  • Designing the RBP's (Role Based Permissions) in SuccessFactors Employee Central
  • Creation of Permission Groups, Permission roles and granting roles to groups and assigning target population to role
  • Designing test cases for RBP Configuration

SAP Security Manager

Manchester Airport Group, UK
06.2015 - 05.2016
  • Understand the agreed current and future security requirements of the business and the existing security policy and plans
  • Responsible for the Security Project Plan and also the Integrated Technical Plan
  • Responsible for Implementation of GRC Access Controls and automated workflows
  • Review of Functional Design Documents to ensure appropriate access control points are designed and are fit for purpose
  • Gained extensive experience in gaining Business Process knowledge while developing the Business Process Master List to use for Security Design
  • Impact assessed any changes from a functional point of view in relation to security
  • Conducted security risk assessments to quantify the level of risk associated with the Programme
  • Understand business requirements and translate them into efficient and integrated SAP control frameworks
  • Led the role mapping process and was responsible for User to Role Mapping Document
  • Provide an assurance over the Security Strategy and Technical Design Documents

SAP Security/GRC Consultant

United Utilities, UK
11.2012 - 05.2015
  • Lead the implementation of Auto User Provisioning, Password self-service and design of business roles
  • Configured and designed the HR Triggers
  • Configured MSMP workflows with BRF+ Application
  • Customize SOD Rules – Create Function Ids, Risk ids and Rule set
  • Identified composite roles containing SOD risks and critical action risks and generated a plan to perform the clean-up which included unit testing, user acceptance testing and transporting it into production


SAP Security Consultant

HCL AXON
Brentford, City of London
04.2012 - 11.2012

SAP Security Consultant

British American Tobacco
London
01.2011 - 02.2012

SAP Security Consultant

Xerox
London
06.2009 - 12.2010

Role Mapping Expert

UNILEVER UK
London
10.2007 - 11.2008

Education

Cybersecurity Risk Management - Cyber Security

HARVARD University
Boston

Cybersecurity Risk Management - Cyber Security

HARVARD University
Boston

Skills

  • Communication skills
  • Public speaking
  • Strategic planning
  • Team building
  • Leadership
  • Problem-solving
  • Calm under pressure
  • Problem Management

Certification

  • SAP Certified Technology Professional – SAP Systems Security Architect
  • SAP Certified Technology Associate – SAP Fiori System Administration
  • SAP Certified Application Associate – SAP Access Control 12.0 (GRC)
  • SAP Certified Associate – SAP Activate Project Manager
  • SAP Certified Technology Associate - SAP HANA 2.0 (SPS04)
  • Certified Ethical Hacker (CEH) – Cyber Security Certification

Affiliations

  • Cricket, Travel

References

References available upon request.

Quote

There is a powerful driving force inside every human being that, once unleashed, can make any vision, dream, or desire a reality.
Tony Robbins

Timeline

SAP Delivery Manager

National Grid
05.2023 - Current

Head of SAP

Luxfer (Chemical Industries)
01.2021 - 04.2023

SAP Project Manager

TFL
10.2020 - 12.2020

SAP S/4 HANA Solutions Architect

HCL
03.2020 - 08.2020

SAP Project Manager

INFORMA UK
07.2018 - 03.2020

SAP Risks and Controls Consultant

JAGUAR LAND ROVER, UK
05.2017 - 06.2018

SAP Senior IDM Security Consultant

Danfoss A/S Denmark
05.2016 - 03.2017

SAP Security Manager

Manchester Airport Group, UK
06.2015 - 05.2016

SAP Security/GRC Consultant

United Utilities, UK
11.2012 - 05.2015

SAP Security Consultant

HCL AXON
04.2012 - 11.2012

SAP Security Consultant

British American Tobacco
01.2011 - 02.2012

SAP Security Consultant

Xerox
06.2009 - 12.2010

Role Mapping Expert

UNILEVER UK
10.2007 - 11.2008

Cybersecurity Risk Management - Cyber Security

HARVARD University

Cybersecurity Risk Management - Cyber Security

HARVARD University
SRINATH KASTALA