Sr Mgr, SAP & Enterprise Applications Security Specialist
Newell Brands
- Location
- Atlanta, Georgia, US
- Work model
- On-Site
- Level
- Senior
Skills
About this role
Job ID: 16314 Alternate Locations: Newell Brands is a leading consumer products company with a portfolio of iconic brands like Graco®, Coleman®, Oster®, Rubbermaid®, Sharpie® and Yankee Candle® - and 24,000 talented teammates around the world. Our culture is built on values in action: Integrity, Teamwork, Passion for Winning, Ownership, and Leadership. We work together to win, grow, and make a real impact—supported by a high-performing, inclusive, and collaborative environment where you can be your best, every day. Position Title: SAP & Enterprise Applications Security Specialist Location: Atlanta, GA / Remote Reports To: Senior Manager, IT SAP & Enterprise Applications Security Role Overview: The SAP & Enterprise Applications Security Specialist owns the design, engineering and governance of access across Newell’s SAP landscape — ECC, S/4HANA, SAP GRC Access Control, SuccessFactors, Ariba, IBP, VisualFabriq and the broader SAP cloud environment. SAP is the anchor of the role, with scope extending to any in-scope enterprise application. This position sits within the Identity and Access Management organization and works closely with SAP functional and Basis teams, application owners, business process owners, and internal and external audit. It partners closely with the Identity Governance and Access Operations teams, supplying the role designs and entitlement definitions that onboarding and provisioning processes depend on. The ideal candidate thinks in terms of how access should work, stays current on where SAP security and identity are heading, and knows where to spend review effort and where to automate. Key Responsibilities:
Design, build and maintain SAP authorization roles (single, composite and derived) and application-level roles, following consistent naming, transport and change management standards. Lead role redesign efforts, including authorization concept work for S/4HANA and Fiori. Apply the appropriate access model for each system — RBAC as the foundation, ABAC or PBAC where they fit. Enforce least privilege across SAP and application roles (including Ariba, IBP and VisualFabriq), right-sizing roles and removing excessive or dormant access over time. Support periodic user access reviews and certifications, applying both role-based and risk-based approaches. Operate SAP GRC Access Control (ARA, ARM, BRM and EAM), including emergency and firefighter access administration. Run access risk analysis at the user and role level and drive remediation of conflicts and critical access, in support of the Governance team’s SOD ruleset. Support SOX IT general controls, audits and the annual review of SAP and SailPoint integration controls. Supply role designs and entitlement definitions to the Identity Governance and Access Operations teams for use in onboarding and provisioning. Serve as security liaison on SAP and S/4HANA projects, building roles to requirements and meeting delivery milestones. Support security across the broader enterprise application portfolio, including Ariba, IBP, VisualFabriq, SuccessFactors, SAP Cloud Identity Services (IAS/IPS), HANA, BTP and Fiori. Troubleshoot SAP authorization errors (SU53) and develop solutions in accordance with company standards.
Required Qualifications
7+ years of hands-on SAP security and authorizations experience across ECC and S/4HANA, including role engineering with single, composite and derived roles. Strong understanding of access risk management and hands-on SAP GRC Access Control experience (ARA, ARM, BRM and EAM), including access risk analysis and mitigating controls. Working knowledge of RBAC, with practical exposure to ABAC and PBAC concepts. Experience with access reviews and certifications using both role-based and risk-based approaches. Working understanding of how SAP and application roles integrate with an IGA platform such as