The Solution Architect – SAP Security & GRC will play a key role in supporting and enhancing Clorox’s enterprise SAP landscape, with a focus on hands on security design, governance, and operations across S/4HANA and supporting systems based on experience.
Contribute to the overall SAP security architecture strategy for Clorox, spanning ECC, S/4HANA, GRC, and cloud-based SAP platforms.
Hands-on for review, inspection, debug (using fire fighter) and verification on all SAP and security platforms.
Support ongoing SAP security operations and maintenance, with a focus on role design, licensing impact and cost recommendations, risk remediation, system access control, audit readiness, and audit reporting / remediation.
Drive our SAP and Security strategy across our different security teams.
Updating our SAP security Architecture as we evolve to meet our security strategy and implementations.
Provide subject matter expertise in SAP GRC Access Control (ARA, BRM, ARM, EAM), including integration with SailPoint IGA where applicable.
Guide and support secure implementation and integration of cloud applications (e.g., IAS, IAG, BTP, SAC, Enable Now, Ariba, etc.).
Provide technical guidance on SSO configuration, SAML assertion handling, secure key maintenance, and related authentication patterns.
Troubleshoot and support SAP access provisioning failures across platforms (GRC, MyAccess, AD/SSO integration).
Collaborate with Enterprise Architecture, IAM, and Cybersecurity to ensure alignment with company-wide identity and access strategies.
Support and contribute to the shift from project-based delivery to stable, long-term SAP security operations post-Vista.
Architect and support SAP IAG Bridge integrations with GRC Access Control, including configuration of Identity Authentication (IAS) and Identity Provisioning Services (IPS), secure SAP Cloud Connector, and BTP subaccount administration.
Requirements
8+ years of SAP Security/GRC experience
Deep expertise in SAP Security and GRC Access Control (GRC 12.0 or later)
Hands-on experience with IAS/IAG, SAP BTP, and SAP S/4HANA security models
Experience supporting security for SAP cloud applications and authentication technologies (SSO, SAML, Secure Key Exchange)
Strong knowledge of compliance and control frameworks including SOX, ITGCs, and SOD
Ability to troubleshoot SAP access provisioning issues across hybrid environments
Strong collaboration skills and ability to work with cross-functional teams, including audit, infrastructure, IAM, and business stakeholders
Experience in security design and support for SAP transformation programs
Familiarity with SailPoint or similar for integration between GRC and IGA platforms
Experience supporting large-scale user migrations and cutover activities
Exposure to SAP development lifecycle, ABAP code review, and security vulnerability triage
Familiarity with JSON structure and its use in API integrations, access provisioning workflows, or troubleshooting cloud-based identity systems (e.g., SAP IAG, SailPoint, MyAccess)
Excellent documentation, communication, and facilitation skills
A continuous improvement mindset and a strong sense of ownership
Proven ability to work independently and drive solutions forward.
Benefits
robust health plans
a market-leading 401(k) program with a company match
flexible time off benefits (including half-day summer Fridays depending on location)
inclusive fertility/adoption benefits
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
SAP SecurityGRC Access ControlS/4HANAIASIAGSAP BTPSSOSAMLABAPJSON