CareerScanCareerScan
JobsCompanies
BlogContact
For Employers
Sign InRegister Free
CareerScanCareerScan

India's verified job platform connecting candidates directly with employers. 100% free applications with instant ATS resume scoring.

Chennai, Bengaluru & Hyderabad
Jobs by location
Jobs in ChennaiJobs in BengaluruJobs in HyderabadJobs in PuneJobs in Mumbai
Popular roles
AR Caller JobsHealthcare Medical CodingReact / Full Stack DeveloperData & Power BI AnalystCustomer Support Executive
Top companies
TCS CareersCognizant JobsInfosys OpeningsApollo HospitalsOmega Healthcare
Career services
Free ATS Resume CheckerAI Resume Builder (Free)AI Job MatcherSalary Guide & BenchmarksJob Alerts on WhatsApp
© 2026 CareerScan India. All rights reserved.256-bit SSL encrypted & verified
Back to all jobs
  1. Home
  2. Jobs
  3. Risk Consulting - Digital risk - SAP GRC
EY
EY

Risk Consulting - Digital risk - SAP GRC

Trivandrum, KL, IN
3-6 years exp
Full-time
Posted 2d ago
0 views
Actively Hiring Urgent Opening Direct 1-Click Apply

Check Your Resume Match Score

Scan your resume against ATS criteria for this Risk Consulting - Digital risk - SAP GRC role at EY.

Apply for this position

Apply on Company Website
Notice a broken link or wrong info?

Job Description

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. 

 

 

 

 

Risk Consulting - SAP GRC / ITAC Senior

Role  :  SAP GRC / ITAC Senior

  • Primary skill: SAP GRC Access Control, SAP ITAC, ITGC, VA, PT, Web App PT, Configuration Review

 

Role overview

 

As part of Risk Consulting, the Senior will support client engagements related to SAP GRC, SAP IT application controls, IT general controls, Network and Web App PT, Configuration Audit for Cloud and IT Systems, Internal audit and risk management for clients across the MENA region. The role is intended for hands-on SAP GRC and ITAC professionals who can execute high-quality testing, documentation and analysis in a fast-growing SAP GRC practice.

 

 

The opportunity

 

We are looking for experienced professionals with SAP GRC, SAP security, ITAC and ITGC, Network PT and Web App PT  exposure to join the Risk Consulting - Digital Risk team. This role provides an opportunity to work on varied SAP GRC, VAPT and IT controls engagements, develop deeper consulting skills and contribute to building a strong SAP GRC delivery capability 

 

 

Your key responsibilities

 

  • Perform Network and Web App PT for IT and Cyber risk consulting projects

  • Conducting risk assessments and vulnerability analyses in cloud environments and propose mitigation strategies

  • Perform configuration review for OS, Server, Databases, applications, network & Security devices against CIS/Industry benchmarks

  • Evaluate secure cloud configuration against best practices.

  • Evaluate DevSecOps implementation to embed security into CI/CD pipelines and cloud deployments

  • Support execution of SAP GRC, SAP ITAC and IT risk consulting projects across SAP ECC and SAP S/4HANA environments.

  • Perform control walkthroughs, evidence review and testing for ITGC, ITAC and automated business controls in line with project methodology.

  • Assist in the assessment, design and documentation of SAP IT application controls and automated controls.

  • Conduct SoD and sensitive access reviews, including data analysis, rule set review, exception validation and remediation follow-up.

  • Support SAP GRC Access Control testing, including workflow validation, access risk analysis, emergency access and user access review activities as applicable.

  • Prepare and maintain project deliverables such as RCMs, testing workpapers, issue logs, evidence trackers and status updates.

  • Assist with data extraction and analysis for access management, control monitoring, process compliance and audit support.

  • Collaborate with internal teams, client stakeholders and audit teams to collect system/process information and close documentation gaps.

  • Follow firm quality standards for testing, documentation and deliverable preparation.

  • Ability to translate complex technical details into clear, business-understandable language for effective communication with stakeholders/business users

  • Good in report writing and convey the observations to the top management in layman’s language emphasizing on the business risks.

  • Communicate clearly and proactively to support issue resolution, follow-up and project delivery.

 

 

Skills and attributes for success

 

  • Strong spoken and written English with clear business communication skills.

  • Analytical, organized and detail-oriented approach to testing, documentation and evidence review.

  • Ability to work well under pressure and deliver quality outputs within defined deadlines.

  • Strong collaboration skills with the ability to work with internal teams, clients and auditors.

  • Good understanding of project discipline, task ownership and quality expectations.

  • Hands on experience will security testing tools/frameworks like Burp Suite, Nessus, Qualys etc.

  • Good knowledge of OWASP and Secure SDLC standards

  • Should have good understanding of the cloud services (AWS, Azure and GCP), its architecture, potential attack vectors and mitigation plans

  • Hands on experience with of the programming languages like Python/Perl/PowerShell/C#

  • Proficiency in MS Office, working knowledge of Excel, Power BI, ACL or similar data analysis tools is preferred.

  • Flexibility to travel to locations at short notice, based on client and engagement requirements.

 

 

To qualify for the role, you must have

 

  • 3-6 years of experience in SAP GRC, SAP security, SAP ECC, SAP S4 HANA, IT audit, compliance testing or technology risk consulting.

  • Exposure to SAP is required, exposure to SAP ECC/S/4HANA security, Oracle security or other ERP security models is preferred.

  • Understanding of ERP system landscapes, access control concepts, SoD, sensitive access and user access review processes.

  • Knowledge of ITGC, ITAC, RCM documentation, testing methodology and issue documentation.

  • Exposure to SOX, ICOFR, internal audit or IT risk standards.

  • Strong Excel and documentation skills with attention to evidence completeness and workpaper quality.

  • Bachelor’s degree in Information Systems, Computer Science, Accounting, Finance or a related discipline.

 

 

Ideally, you will also have

 

  • SAP GRC, CISA, ISO 27001, Oracle security, OSCP, CEH or other relevant certifications.

  • Experience with infrastructure/web application penetration testing and vulnerability assessments

  • Experience supporting SAP GRC Access Control implementation/testing or SAP security role review projects.

  • Exposure to S/4HANA access, user provisioning workflows, SoD rule set testing or controls automation.

  • Prior experience supporting MENA clients, internal audit teams or external audit engagements.

 

 

What working at EY offers

 

At EY, you will work on meaningful and varied client engagements while developing through coaching, practical experience and structured feedback. You will be part of an interdisciplinary environment that values quality, knowledge sharing and professional growth.

  • Support, coaching and feedback from engaging colleagues.

  • Opportunities to develop new SAP GRC, VAPT, IT risk and audit skills.

  • The freedom and flexibility to handle your role in a way that is right for you.

 

 

EY | Building a better working world

 

EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.  

 

Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.  

 

Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

Benefits & Perks

visioning workflows, SoD rule set testing or controls automation.

Frequently Asked Questions

How to apply for Risk Consulting - Digital risk - SAP GRC at EY?

Click the "Apply on Company Website" button on this page to submit your application directly on the employer's official portal.

What is the salary for this role?

Salary details will be discussed during the interview.

What experience is required?

3-6 years of experience is required.

Is this position still open?

Yes, currently active and accepting applications.

ApplicationActively Hiring
Apply on Company Website
Broken link or expired?
EY

EY

Visit Company Website

More jobs at EY

Pricing and Commercial Architect-Supervising Associate

Bengaluru, KA, IN

Technology Consulting - Power BI Developer - Senior

Trivandrum, KL, IN

Risk Analytics - Full Stack Engineer - Senior

Kochi, KL, IN

Share this Opening

Job Alerts for other

Receive email alerts whenever new other roles in Trivandrum are posted.

Set Free Alert →

Similar Openings

Explore related active roles in other

View all
Actively Hiring
Granicus
Senior Facilitator, Experience, Granicus Experience Group
Granicus Verified
5+ years
₹6.4L/mo
Remote, US
otherFull-timeRemote
Posted 20h ago
Apply Now
Actively Hiring
829studios
AI Innovation Engineer
829studios Verified
5+ years
₹7.6L – ₹9.3L/mo
Remote
otherFull-timeRemote
Posted 20h ago
Apply Now
UrgentActively Hiring
Prizepicks
Strategic Insights, Senior Researcher [Market Insights]
Prizepicks Verified
5+ years
₹9L/mo
Atlanta, GA preferred, Remote
otherFull-timeRemote
Posted 20h ago
Apply Now

Risk Consulting - Digital risk - SAP GRC

EY · Trivandrum

Apply on Company Website