SAP Security Engineer (GRC – Technical)

<span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Bright Vision Technologies is a forward-thinking software development company dedicated to building innovative solutions that help businesses automate and optimize their operations. We leverage cutting-edge technologies to create scalable, secure, and user-friendly applications.</span></span><br><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">As we continue to grow, we’re looking for a skilled SAP Security Engineer (GRC – Technical) to join our dynamic team and contribute to our mission of transforming business processes through technology.</span></span><br><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">This is a fantastic opportunity to join an established and well-respected organization offering tremendous career growth potential.</span></span><br><br><span style="font-size:15pt;"><span style="font-family:Arial, sans-serif;"><span style="font-weight:bold;">SAP Security Engineer (GRC – Technical)</span></span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;"><b>Job Title:</b> SAP Security Engineer (GRC – Technical)</span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;"><b>Location:</b> 100% Remote (Continental United States)</span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;"><b>Position Type:</b> In-house Bright Vision Technologies SOW engagement (no third-party client or vendor)</span></span><br><b>Salary: $100K - $150K / Annum</b><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;"><b>Experience:</b> 5+ years</span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;"><b>Sponsorship:</b> No new H1B sponsorship available. H1B transfers welcomed for qualified candidates.</span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;"><b>Employment Type:</b> Full-time, direct W2 with Bright Vision Technologies (no C2C, no 1099, no third-party)</span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;"><b>Engagement:</b> Long-term, multi-year, aligned to the Bright Vision SOW delivery roadmap</span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;"><b>Compensation:</b> Competitive base salary commensurate with experience, plus benefits.</span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;"><b><span style="font-size:13pt;">Employment Terms & Visa Policy</span></b></span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;"><b>This is a 100% remote, full-time, direct W2 position with Bright Vision Technologies.</b></span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;"><b>This role is part of Bright Vision Technologies’ in-house Statement of Work (SOW) engagement.</b> The client, end customer, and employer for this position is Bright Vision Technologies — there is no third-party client, vendor, or implementation partner involved.</span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">We do not engage in C2C, 1099, or third-party arrangements for this role.</span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;"><b>BUT STRICTLY NO C2C/1099/3RD PARTY COMPANIES. ALL OUR ROLES ARE W2 AND NO 3RD PARTY BROKERING PLEASE.</b></span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Candidates must be willing to work directly as a full-time W2 employee of Bright Vision Technologies and contribute to our in-house SOW deliverables.</span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">No new H1B sponsorship is available for this role.</span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;"><b>However, candidates who are currently on a valid H1B visa and require a transfer are welcome to apply. We will support H1B transfers for qualified candidates.</b></span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">For every role, a technical coding assessment is mandatory. Please apply only if you are confident in your technical abilities and hands-on experience.</span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;"><b><span style="font-size:13pt;">Job Summary</span></b></span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">We are seeking an experienced SAP Security and GRC (Governance, Risk, and Compliance) Engineer to design, implement, and operate security and access-control frameworks for complex SAP landscapes, including S/4HANA, ECC, BW/4HANA, Fiori, BTP, and SuccessFactors. In this role you will be responsible for SAP role design, user provisioning, segregation-of-duties analysis, audit support, and the technical operation of SAP GRC suites. The ideal candidate will combine deep expertise in SAP authorization concepts with strong hands-on experience operating SAP GRC Access Control and Process Control, and will partner closely with audit, compliance, and business teams to deliver a secure, auditable SAP environment.</span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;"><b><span style="font-size:13pt;">Key Responsibilities</span></b></span></span><ul style="margin-bottom:4px;"><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Design and maintain SAP authorization concepts and role structures aligned with business processes and least-privilege principles.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Build and maintain master, derived, composite, and business roles for S/4HANA, ECC, and Fiori applications.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Configure and operate SAP GRC Access Control (ARA, ARM, BRM, EAM), including ruleset management, mitigating controls, and emergency access management.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Perform segregation-of-duties analysis and remediation in collaboration with business process owners and internal audit.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Configure user provisioning workflows in SAP GRC ARM, including request types, approval paths, and integration with IDM/IAM platforms.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Operate SAP GRC Process Control for continuous controls monitoring and policy management.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Implement security for Fiori applications, including catalogs, groups, and front-end authorizations.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Configure and operate security for SAP BTP and cloud applications using XSUAA, IAS, and IPS.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Support SAP audits (SOX, GxP, PCI) and respond to audit findings with documented remediation plans.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Implement transport security, table logging, and audit logging in line with internal security policies.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Monitor and remediate SAP Security Notes in coordination with Basis and DBA teams.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Maintain comprehensive, current technical documentation — including architecture diagrams, design decisions, configuration references, runbooks, and operational procedures — so that the system remains supportable, auditable, and easy to onboard new engineers onto over time.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Mentor junior team members and support knowledge transfer across the security team.</span></span></li></ul><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;"><b><span style="font-size:13pt;">Required Qualifications</span></b></span></span><ul style="margin-bottom:4px;"><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Bachelor’s degree in Computer Science, Engineering, or a related technical discipline.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Five or more years of SAP Security / GRC experience in enterprise landscapes.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Strong hands-on experience with SAP authorization concepts and role design.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Deep experience operating SAP GRC Access Control (ARA, ARM, BRM, EAM).</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Experience supporting SAP audits and remediation activities.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Hands-on experience securing Fiori, BTP, and cloud SAP applications.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Familiarity with SAP IDM or third-party IGA tooling.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Working knowledge of SAP Process Control.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Strong understanding of regulatory frameworks such as SOX, GxP, and PCI.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Excellent communication and documentation skills.</span></span></li></ul><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;"><b><span style="font-size:13pt;">Preferred Qualifications</span></b></span></span><ul style="margin-bottom:4px;"><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">SAP-certified Security or GRC credentials.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Experience with SAP Cloud Identity services (IAS, IPS) and SCIM-based integrations.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Familiarity with HANA security and analytic privileges.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Experience with continuous controls monitoring frameworks.</span></span></li><li style="margin-bottom:4px;margin-left:8px;"><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Exposure to SAP RISE / Grow security operating models.</span></span></li></ul><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;"><b><span style="font-size:13pt;">How to Apply</span></b></span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Would you like to know more about this opportunity?</span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">For immediate consideration, please send your resume to venkat.r@bvteck.com or contact us at (908) 505-3899. Learn more about Bright Vision Technologies at www.bvteck.com.</span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">We recognize that our people are our strength, and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company.</span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs.</span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Bright Vision Technologies is an Equal Opportunity Employer, including Disability/Veterans.</span></span><br><span style="font-size:11pt;"><span style="font-family:Arial, sans-serif;">Position offered by “No Fee Agency.”</span></span><br> <p>Equal Employment Opportunity (EEO) Statement</p> <p>Bright Vision Technologies (BV Teck) is committed to equal employment opportunity (EEO) for all employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, veteran status, or any other protected status as defined by applicable federal, state, or local laws. This commitment extends to all aspects of employment, including recruitment, hiring, training, compensation, promotion, transfer, leaves of absence, termination, layoffs, and recall.</p> <p>BV Teck expressly prohibits any form of workplace harassment or discrimination. Any improper interference with employees' ability to perform their job duties may result in disciplinary action up to and including termination of employment.</p>

Back to blog