Application Security & Access Control Operations Lead - Finance & Administration
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Audit @ 7
Compliance @ 4
Oracle @ 7
Project Management @ 4
Security @ 8
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
The Finance Application Security & Access Control team governs user access across the Finance application landscape, including provisioning, access reviews, Segregation of Duties (SoD), privileged access, and compliance controls.
The Finance Application Security & Access Control Lead will drive and govern access management processes across SAP, Oracle EPM, and cloud-based Finance applications. The role focuses on strengthening the control environment, improving access governance, managing risk, and modernizing the security and provisioning landscape.
Responsibilities
- Drive the technology roadmap for access governance and provisioning, evaluating new tools and capabilities to improve security, compliance, and operational efficiency.
- Govern user provisioning and lifecycle management processes across Finance applications.
- Lead user access reviews, role recertifications, and privileged access reviews.
- Manage Segregation of Duties (SoD) risks, mitigation controls, and remediation efforts.
- Govern Firefighter/Emergency Access Management processes and monitoring.
- Oversee privileged and administrative access monitoring across cloud and on-premises applications.
- Partner with Finance, Technology, Risk, and Audit teams to maintain a strong, audit-ready control environment.
- Drive continuous improvement of security and access control standards across the Finance landscape.
Requirements
- 10+ years of experience in IAM, Application Security, Access Governance, or ERP Security.
- Strong experience with SAP and/or Oracle security models.
- Hands-on experience with SAP GRC Access Control, including SoD analysis, access requests, and emergency access management.
- Expertise in RBAC, role provisioning, user access reviews, and recertification processes.
- Experience implementing and governing cloud application provisioning frameworks.
- Experience supporting SOX compliance, audit activities, and access-related controls.
- Strong analytical and risk assessment skills, with the ability to identify and remediate control gaps.
Nice-to-Have Skills
- Experience with Pathlock, Saviynt, or similar IAM/GRC platforms.
- Experience supporting SAP BDC security and access controls.
- Exposure to multi-platform access governance across SAP, Oracle, and SaaS applications.
- Familiarity with privileged access management and continuous control monitoring solutions.
- Experience in project management.
Additional Qualities
- A fresh perspective and willingness to challenge existing processes and controls.
- A passion for simplifying and modernizing access governance through automation and technology.
- Strong stakeholder management skills with the ability to influence across business and technology teams.
- A continuous improvement mindset focused on balancing security, compliance, and user experience.
Benefits
Benefits may include merit increases, incentive compensation for exempt roles, paid holidays, paid time off, medical, dental, vision, short- and long-term disability benefits, 401(k) matching, life insurance, and wellness programs.