Proven SAP Security Architect and SAP Delivery Manager with over 17 years of experience with success in managing and delivering top notch security solutions for client's business requirements.
Extensive experience in implementing, reviewing, auditing SAP Security and related ITGC controls.
Overview
17
17
years of professional experience
5
5
Certification
Work history
SAP Delivery Manager
National Grid
Warwick, Warwickshire
05.2023 - Current
Responsible for Roles and Access Delivery across the organization
Responsible for full life cycle of the project: initiation, resourcing, execution, monitoring, control, and completion
Managed 8 Consultants offshore and onshore.
Participated in preparation of proposals and statements of work, developed project estimates, and estimated the resources needed to achieve ERP implementation success and ongoing support goals
Drive all phases of functional/technical implementation of the project from the planning to post go-live, ensuring the accomplishment of the desired scope, timeline, and quality
Collaborated with other project managers to plan scope, schedule, risk, stakeholder management, cross-team collaboration and the synchronization of effort across all other applications to drive project outcomes
Maintained plans and reported program status dashboards and provide regular monthly executive program status updates at Executive Steering Committee
Managed a high degree of change in a fast-paced, complex and demanding environment
Lead project(s) ensuring adherence
Coordinated with the Leadership team and other IT resources to solve complex problems, develop innovative solutions.
Solution Manage and communicate a clear vision of the project's objectives and motivated the project team to achieve them; create a project environment that enables peak performance by team members
Analyze risk, establish contingency plans and identify trigger events and responsibilities for initiating mitigating action
Escalate issues early about the project to account management or Leadership
Empowered project teams through motivational coaching, mentoring and development.
Introduced agile and lean methods to increase team capabilities.
Managed resources to yield high Return On Investment (ROI), raising cost-effectiveness.
Assessed backlogs and set key priorities to mitigate project delays.
Refined project policies and processes to build robust delivery systems.
Compromised on project objectives where outcomes could be improved with calculated risk.
Managed stakeholder expectations to limit concerns and queries during project delivery.
Set schedules of work and monitored progress to achieve timely programme delivery.
Directed daily operations to achieve maximum output and reduce costs.
Understood and balanced client and company priorities to achieve overall objectives.
Identified and managed risks to limit time and budget impacts.
Head of SAP
Luxfer (Chemical Industries)
Manchester
01.2021 - 04.2023
Responsibilities for Head of SAP ;
Responsible for the management, Development and Audit compliance of Luxfer MEL Technologies SAP S4 HANA System in the UK and the US
Managing key relationships with internal and external stakeholders including business end-users, management, Application support partners, SAP Consultants, Cloud hosting partner and internal/external auditing teams
Management and Architecting of the S4 HANA and GRC system to ensure business end-users can carry out essential business functions and are supported with issues, problems or change requests
Management of user roles and authorizations in line with security permissions
Implemented a Roadmap for S4HANA and SAP GRC Projects
Managed Multiple SAP Implementations
Technically led Change Management Board for all SAP Changes
Management of Azure Cloud Technologies where the SAP Servers are located
Project and Programme management of changes, developments, modifications and patching related activities that improve functionality or add value to the system for its end users
Responsible for Incident, Problem and Change Management
SAP IT Audit – management of several SAP applications, HANA DB and automated business General IT Controls, as part of the Sarbanes-Oxley (SoX) Programme
Management of AMS ticketing tool and budget allocation
Management of the SAP System Integrator.
Oversaw daily operations to achieve high productivity levels.
Applied critical thinking to analyse problems, evaluate solutions and select best decisions.
SAP Project Manager
TFL
London
10.2020 - 12.2020
Responsibilities of SAP Project Manager:
Implemented and maintained TfL's Consolidated Controls Framework (Risk maps, Process flowcharts, Risk and Control Matrices (RACM) in conjunction with operational business units
Developed and maintained the process for financial controls evaluation and documentation within the Control Framework-Continually developing and maintaining an effective program of controls evaluation and testing in conjunction with Group Internal Audit and TfL Finance policies
Overseeing the monitoring and testing of TfL's control effectiveness ensuring remediating actions and recommendations are driven through to completion
Supported internal and external Audit to efficiently plan and execute audits following through with closure of audit findings where necessary
Provided central control guidance and provided advice on an ad hoc basis and project basis as required.
SAP S/4 HANA Solutions Architect
HCL
London
03.2020 - 08.2020
Gathering requirements and documenting S/4 HANA Security Strategy and framework
Designing and building roles for S/4 HANA (Transactional / UI5), GRC 12, BW/4HANA, SOLMAN and various other systems
Implementation and configuration of GRC 12 with services for apps included in the ruleset
Designing roles for Fiori apps by adding Catalogs and Groups to S/4 HANA roles
Activating services for the Fiori apps in /IWFND/MAINT_SERVICE
Creating Catalogues and Groups using Fiori designer and creating catalogues using content manager /UI2/FLPCM_CONF
Documenting and implementing cut-over tasks for the S/4 HANA go-live
Troubleshooting and identifying the missing OData Services and authorization issues in /IWFND/ERROR LOG and notifying the Basis and Fiori configuration team to activate them
Optimizing the User Experience by reducing or removing unwanted groups and tiles within the groups to improve performance
Working with Fiori Configuration team to identify the areas where the inactive apps are generating frontend or backend authorization issues and customizing the catalogs to remove inactive apps
Working with business users to identify the issues with Fiori apps and resolving the authorization issues
Optimizing the performance by removing the unwanted apps that are not enabled from the catalogs and reducing the number of tiles on the home page which reduces the load time thereby improving the user experience
Providing support and issue resolution in quick turn-around during project implementation
Working on BW/4 HANA Security
Built roles for Developers, Modelers, Admin teams, Power and end users
Implemented/support GRC AC12, Configured GRC AC Access Risk Analysis (ARA) and Emergency Access Management (EAM) components and Access risk Management (ARM)
Configured MSMP workflows for addressing various user request types in Access Request Management
Successfully integrated LDAP active directory with SAP GRC Access control system
Configured the MSMP Firefighter log report workflow for getting the logs to firefighter controllers
Successfully implemented various MSMP Mitigation control workflows like mitigation control setup and assignment
Configured various BRF+ rule kinds like Initiator rule, Agent rule, Routing rule and Notification and variable rule
Successfully configured User Access Reviews (UAR) for assessing the user's access in all production environments.
SAP Project Manager
INFORMA UK
07.2018 - 03.2020
Strong knowledge of designing of roles & authorizations and implementation of a complex security framework and role matrix for SAP HANA Enterprise platform
Project managed the HANA upgrade from 1.0 to 2.0, created roles in system db, and configured audit policy, password policy in system DB and HANA cockpit user administration
Configured MSMP workflows IN GRC 10.0 for different user provisioning scenarios like new, change, terminate, lock and unlock user accounts, create complex BRF plus rules and workflows to meet the existing user management processes
Implemented Emergency Access Management for handling firefighter IDs, configured automatic workflows for managing emergency ID assignment and review of the firefighter logs, build firefighter IDs in remote systems, identify FF owners and reviewers and schedule batch jobs for log generation
Extracting and analyzing various system reports (UAR, Critical actions, SOD reports, Security parameter settings, etc.) to make sure the SAP systems are compliant
Established and managed a strong SAP security capability, with responsibility for security design, governance, operational support, project planning, design and execution
Extensive Use of ServiceNow for Incident, Problem and Change Management
Evaluate business risks associated with security design, implement appropriate controls to address those risks and provided recommendations on ways to simplify and streamline the security design
Delivering robust Access Control solutions for several applications, including identification and management of Privileged Access
Joiner, Mover, and Leaver processes defined and embedded with technical controls and monitoring defined
Development and review of key security Policies and Standards including Acceptable Use Policy, Network Security Standard, and Access Management Standard.
SAP Risks and Controls Consultant
JAGUAR LAND ROVER, UK
05.2017 - 06.2018
Designed and Implemented the Risk and Controls Matrix across different Business Processes
I.e., Finance, Manufacturing and HR
Liaised with different areas of the Business to understand the risks in their process and designed the mitigating controls
Liaising with the Business Assurance to ensure the risks and controls matrix is according to the SOX standards Controls
Designed IT SOX Controls Responsible for delivering a bespoke IT Access Controls Framework for a Major Transformation Programme, covering complex local legal and group compliance requirements
Supporting global process owners with operation and validation of mitigating controls to ensure compliance with SOX requirements and adherence to JLR policies and procedures
Developed the role design to fit with the Target Operating Model and ensure users have appropriate levels of access as per company policy and remediation of users with excessive system access.
SAP Senior IDM Security Consultant
Danfoss A/S Denmark
05.2016 - 03.2017
Independently lead and managed the implementation of SAP GRC 10.1 (ARA, ARM, BRM and EAM) and integration with IDM 7.2
Worked on SuccessFactors project and successfully Implemented Role-based permissions for SuccessFactors systems and migrated HR users from ECC to SuccessFactors
Designing the RBP's (Role Based Permissions) in SuccessFactors Employee Central
Creation of Permission Groups, Permission roles and granting roles to groups and assigning target population to role
Designing test cases for RBP Configuration
SAP Security Manager
Manchester Airport Group, UK
06.2015 - 05.2016
Understand the agreed current and future security requirements of the business and the existing security policy and plans
Responsible for the Security Project Plan and also the Integrated Technical Plan
Responsible for Implementation of GRC Access Controls and automated workflows
Review of Functional Design Documents to ensure appropriate access control points are designed and are fit for purpose
Gained extensive experience in gaining Business Process knowledge while developing the Business Process Master List to use for Security Design
Impact assessed any changes from a functional point of view in relation to security
Conducted security risk assessments to quantify the level of risk associated with the Programme
Understand business requirements and translate them into efficient and integrated SAP control frameworks
Led the role mapping process and was responsible for User to Role Mapping Document
Provide an assurance over the Security Strategy and Technical Design Documents
SAP Security/GRC Consultant
United Utilities, UK
11.2012 - 05.2015
Lead the implementation of Auto User Provisioning, Password self-service and design of business roles
Configured and designed the HR Triggers
Configured MSMP workflows with BRF+ Application
Customize SOD Rules – Create Function Ids, Risk ids and Rule set
Identified composite roles containing SOD risks and critical action risks and generated a plan to perform the clean-up which included unit testing, user acceptance testing and transporting it into production
SAP Security Consultant
HCL AXON
Brentford, City of London
04.2012 - 11.2012
SAP Security Consultant
British American Tobacco
London
01.2011 - 02.2012
SAP Security Consultant
Xerox
London
06.2009 - 12.2010
Role Mapping Expert
UNILEVER UK
London
10.2007 - 11.2008
Education
Cybersecurity Risk Management - Cyber Security
HARVARD University
Boston
Cybersecurity Risk Management - Cyber Security
HARVARD University
Boston
Skills
Communication skills
Public speaking
Strategic planning
Team building
Leadership
Problem-solving
Calm under pressure
Problem Management
Certification
SAP Certified Technology Professional – SAP Systems Security Architect
SAP Certified Technology Associate – SAP Fiori System Administration
SAP Certified Application Associate – SAP Access Control 12.0 (GRC)
SAP Certified Associate – SAP Activate Project Manager
SAP Certified Technology Associate - SAP HANA 2.0 (SPS04)