SAP ERP Prinicpal Security Arch
Providence, Providence County, Rhode Island, 02912, USA
Listed on 2026-03-01
-
IT/Tech
Cybersecurity, IT Consultant
Overview
As one of the largest investor-owned utility companies in the United States, PPL Corporation is committed to creating long-term, sustainable value for our customers and stakeholders. Our high-performing regulated utilities provide an outstanding experience for customers and communities, investing in infrastructure and technology to build a smarter, more reliable energy grid and advance a cleaner energy future.
The Cybersecurity organization advances the overall state of security at PPL through critical initiatives and coordination of large security and customer-focused projects. It develops systems to monitor and respond to attacks, educates the corporation on security best practices, and ensures third-party data sharing relationships securely protect PPL information.
PPL is seeking a highly skilled SAP/ERP Principal Security Architect to join the Cybersecurity organization. The SAP/ERP Principal Security Architect will serve as a hands-on guide and technical expert, responsible for defining and implementing robust security controls in our Customer, HR, and Finance platforms. This position will play a critical role in ensuring the secure operation and governance of our SAP/ERP landscape, with particular focus on role design, access controls, and regulatory compliance.
The ideal candidate will have hands-on experience with ECC and S/4
HANA systems, SAP GRC, and integration with modern IAM platforms.
- Design, implement, and maintain SAP security roles and authorizations (PFCG, SU24, SU01).
- Analyze and manage segregation of duties (SoD) risks using SAP GRC Access Control.
- Secure custom transactions, RFCs, BAPIs, and ABAP developments.
- Collaborate with business process owners to ensure roles align with least privilege principles.
- Monitor SAP security logs (SM20, STAD) and perform forensic investigations as needed.
- Support Fiori and SAP S/4
HANA application security, including OData and catalog roles. - Integrate SAP systems with identity providers like Entra
ID, Okta, or Ping for SSO. - Drive improvements in SAP security posture through continuous monitoring and proactive remediation.
- Evaluate, enhance, and document security configurations, procedures, and standards.
- Stay informed of SAP security trends, vulnerabilities, and best practices.
- Performs other duties as assigned.
- Complies with all policies and standards.
- Bachelor Degree in computer science, Information Security, and/or a related field or an equivalent level of work-related experience
- 10 plus years of SAP security experience, including ECC and/or S/4
HANA - Hands-on experience with SAP GRC Access Control modules
- Strong understanding of RBAC, SoD principles, and SAP authorization concepts
- Familiarity with SAP Fiori security and cloud security models
- Experience with integration into identity management platforms (e.g., Entra
ID, Okta, Cyber Ark) - Ability to interpret audit and compliance requirements into SAP controls
- Evaluate, enhance, and document security configurations, procedures, and standards
- Stay informed of SAP security trends, vulnerabilities, and best practices
- Drive improvements in SAP security posture through continuous monitoring and proactive remediation
- Previous experience with utilities or highly regulated industries
- Experience with conversions from legacy HR and Finance systems to SAP
- Experience with upgrades to existing versions of SAP
- Good communications skills with HR and Finance professionals as well as cybersecurity professionals
- Ability to translate business and compliance concerns into actionable protections within SAP
The company reserves the right to determine if this position will be assigned to work on-site, remotely, or a combination of both. Assigned work location may change. In the case of remote work, physical presence in the office/on-site may be required to engage in face-to-face interaction and coordination of work among direct reports and co-workers.
Equal Employment OpportunityOur company is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, national origin, protected veteran status, sexual orientation, gender identity, genetic information, disability status, or any other protected characteristic.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).