hirly

Duobridge Talent Solution

IT Audit - SAP Governance Risk & Compliance

Chennai, Tamil Nadu, India

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Duobridge Talent Solution first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.7M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Mid level
Country
IN
Work mode
On-site / unstated
First seen by hirly
26 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

SAP GRC

  • Location: Chennai
  • Department: GPO Reports to: GPO – Process Owner

About the Role

We are seeking an experienced SAP GRC resource to manage and strengthen our SAP Governance, Risk, and Compliance framework. The ideal candidate will bring hands-on expertise in SAP access controls, segregation of duties (SoD) risk analysis, and IT general controls (ITGC), combined with a strong background in IT audit. This role is critical to ensuring our SAP environment is secure, compliant, and aligned with internal control and regulatory requirements.

Key Responsibilities

Design, configure, and maintain SAP GRC Access Control, including access risk rulesets, mitigating controls, and remediation workflows.

Perform periodic reviews of SAP user access, role assignments, privileged access, and emergency access management (Firefighter) to identify and remediate segregation of duties (SoD) conflicts.

Review and monitor SAP access controls across key business cycles (procure-to-pay, order-to-cash, user access management) to ensure compliance with company policies and industry standards.

Assess IT general controls (ITGC), application controls, and infrastructure controls within SAP and related environments, benchmarking against frameworks such as NIST.

Partner with IT and Business stakeholders to investigate audit findings, track remediation progress, and drive continuous improvement in control effectiveness.

Support external and internal audit engagements, including planning, fieldwork, reporting, and issue follow-up for SAP-based systems.

Evaluate third-party service reports (e.g., ISAE 3402/SOC reports) for outsourced IT support functions.

Conduct vulnerability assessments and support broader IT security reviews in collaboration with the security team.

Develop and deliver training to key users, internal auditors, and auditees on GRC processes, tools, and controls.

Maintain and enhance audit issue tracking systems, ensuring workflows reflect current audit practices.

Required Qualifications

Bachelor's degree in Information Systems, Computer Science, Accounting, or a related field.

Minimum 8–12 years of combined experience in IT audit (internal and/or external) with a strong focus on SAP access controls and GRC.

Proven hands-on experience with SAP GRC (Access Control), including access risk analysis, mitigating control assignment, and SoD rulesets.

Working knowledge of SAP modules (MM, FI, PP, QM, PM, SD) and how they intersect with access risk.

Solid understanding of ITGC, application controls, and vulnerability management processes.

Experience with Identity & Access Management tools (e.g., CyberArk) and privileged access reviews.

Familiarity with audit and data analytics tools such as ACL and TeamMate.

Professional certification: CISA (Certified Information Systems Auditor) required; ITIL Foundation a plus.

Experience with vulnerability assessment tools (e.g., Nmap, Nessus) is advantageous.

Strong communication skills, with the ability to translate technical findings into actionable business recommendations.

Proficiency in Microsoft Office (Excel, Word, Visio, PowerPoint).

Preferred Attributes

Prior exposure to Big 4 audit methodology or large-scale internal audit functions.

Experience delivering GRC or access-control training to end users and auditors.

Fluency in English

What We Offer

Opportunity to lead and shape the SAP GRC function within a growing organization.

Exposure to cross-functional projects spanning IT, security, and business operations.

Competitive compensation and professional development support

Original posting on Duobridge Talent Solution's site ↗

Listed on hirly, a job board. hirly is not the employer: Duobridge Talent Solution is hiring for this role.

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job