Kyndryl logo

Kyndryl

✓ Verified Sponsor

SAP GRC and HANA Security Consultant

🗓️ Posted 2026-08-24 Bukit Batok South, Singapore, South West, Singapore, Singapore Full-time Hybrid ICT

Company shared salary

NA

Market rate

S$8,000–S$13,000/mo (S$96,000–S$156,000/yr)

Based on similar roles (title + domain + location).

Responsibilities

  • At Kyndryl, we run and reimagine the mission-critical technology systems that drive advantage for the world's leading businesses. We are at the heart of progress; with proven expertise and a continuous flow of AI-powered insight, enabling smarter decisions, faster innovation, and a lasting competitive edge. For our people-Kyndryls-that means doing purposeful work that powers human progress. Join us and experience a flexible, supportive environment where your well-being is prioritized and your potential can thrive.
  • We are looking for an SAP GRC and HANA Security Consultant to design, implement, and govern access controls across our SAP landscape.
  • This role sits at the intersection of technical security administration and compliance: you will build and maintain role architecture across S/4HANA, HANA database, and Fiori, run our GRC Access Control platform end to end, and act as the primary technical contact for internal and external auditors on SAP access matters.
  • This is a hands-on position for someone who is equally comfortable writing an analytic privilege in HANA Studio, remediating a segregation-of-duties conflict in ARA, and explaining both to a non-technical control owner.
  • SAP GRC Access Control
  • Configure, administer, and support SAP GRC Access Control 10.1/12.0 across all four modules: Access Risk Analysis (ARA), Access Request Management (ARM), Business Role Management (BRM), and Emergency Access Management (EAM/Firefighter).
  • Maintain and customize the SoD ruleset - add custom risks, functions, and organizational rules; apply SAP-delivered ruleset updates and assess landscape impact.
  • Design and maintain MSMP workflows, BRF+ rules, and approval paths for access requests and role change management.
  • Perform periodic risk analysis at user, role, and profile level; drive remediation and design compensating/mitigating controls with business process owners.
  • Administer User Access Reviews (UAR), SoD Review, and Firefighter log reviews; track completion and escalate exceptions.
  • Support GRC Process Control, Risk Management, and Audit Management where in scope, and evaluate migration to SAP Cloud Identity Access Governance (IAG).
  • SAP HANA Security
  • Administer HANA database security: catalog and repository roles, users, system/object/analytic/package/application privileges, and privilege inheritance design.
  • Implement row- and column-level security through analytic privileges, and configure static and dynamic data masking for sensitive data.
  • Manage HDI container security and XS Advanced (XSA) roles, role collections, and OAuth/UAA configuration.
  • Configure and monitor HANA audit policies; produce audit trails for privileged activity and support forensic review.
  • Manage encryption (data volume, redo log, backup), certificate management, and TLS/SSL configuration.
  • Set up and support SSO and authentication methods including SAML 2.0, Kerberos, and X.509 certificates.
  • Administer security through HANA Cockpit and HANA Cloud Central, including HANA Cloud tenant security where applicable.
  • SAP Application Security