Sr Manager/Director SAP Security

Requisition ID:  18056
Location: 

Chicago, IL, US, 60606 Nashville, TN, US, 37214

Pay Type:  Salary
Position type:  Full-time / Salary
Travel Requirement: 31-40%

COMPANY OVERVIEW
Amrize is building North America. From bridges and railways to data centers, schools, offices and homes, our solutions are inside the buildings and infrastructure that connect people and advance how we live. And we invite you to come and build with us.

As the partner of choice for professional builders, we offer advanced branded solutions from foundation to rooftop. Wherever our customers are, whatever their job, we’re ready to deliver. Our 19,000 colleagues work across 1,000 sites supported by an unparalleled distribution network. Infrastructure, commercial and residential, new build, repair and refurbishment: We’re in every construction market.

Amrize listed on the New York Stock Exchange and the SIX Swiss Exchange on June 23, 2025, following our spinoff as an independent company. Join us and build your ambition.

Learn more at www.amrize.com/careers

Description: 

[[logo]]

 

 

We’re seeking a Sr Manager/Director SAP Security who’s ready to put your skills to work on projects that matter — and build a career with a company that’s building North America. 

 

 

Job Title: Sr Manager/Director SAP Security   |   Req ID: 18056   |   Location: Chicago Office IL, Building Envelope - Corp Nashville, TN

 

 

ABOUT THE ROLE

This role sits at the heart of the Cybersecurity organization. The Sr Manager/Director will own the SAP security and access governance strategy across the full SAP landscape, ensuring robust SOX compliance, while also providing strategic direction for the broader enterprise.

The ideal candidate brings 15+ years of hands-on SAP security depth - from role design and SoD rule set management to GRC operations and audit excellence.

The preferred locations are Chicago or Nashville. The position can also be remote as long as you are able to do the travel.

 

WHAT YOU'LL ACCOMPLISH

  • Strategic Leadership & Team Management
  • Lead access governance activities including role design, user access reviews, Segregation of Duties assessments, risk remediation, access certifications and ongoing security compliance.
  • Act as a player-coach: provide hands-on SAP security guidance for complex role design, SoD, and GRC challenges
  • Own demand management, prioritization, and resource planning across both SAP Operations, SOX initiatives, S/4 Hana implementations, and upgrades.
  • Own all SAP controls supporting SOX compliance (ITGCs and application-level access controls)
  • Serve as the primary liaison for internal and external auditors on SAP access and security topics
  • Translate technical SAP controls into clear, business-aligned compliance narratives
  • Ensure high-quality, consistent audit evidence and drive remediation of any audit findings
  • Lead end-to-end SoD governance including definition, maintenance, and enforcement of SoD rule sets
  • Identify and document mitigating controls for approved SoD conflicts; own ongoing monitoring
  • Drive periodic access reviews and certification campaigns aligned to SOX requirements
  • Role Design & RBAC
  • Govern and evolve the enterprise SAP role catalog including business roles and single roles Lead transformation toward modern role-based and attribute-based access control (RBAC/ABAC) models Define and enforce role design standards, naming conventions, and governance frameworks Manage the full role lifecycle: design, testing, deployment, and ongoing maintenance
  • SAP GRC & Operations
  • Provide end-to-end ownership of SAP security across S/4HANA, ECC, BTP, and Fiori landscapes Oversee SAP GRC implementation and optimization: Access Risk Analysis (ARA), Access Request Management (ARM), Emergency Access Management (EAM), and Process Control Drive standardization, automation, and efficiency in day-to-day SAP security operations Manage transport security (STMS) implications and security patching cadence
  • Experience with constructing and presenting SAP Security, GRC, and SOX initiatives roadmap to C Suite,
  • Serve as a trusted advisor to senior leadership, IT, Finance, and business teams on SAP security, GRC and SOX Initiatives
  • Demonstrate a commitment to communicating, improving and adhering to health, safety and environmental policies in all work environments and areas. Promote a culture of safety and exhibit these behaviors.

 

WHAT WE’RE LOOKING FOR

 

Education: Bachelor's degree

 

Additional Education Preferred: Master's degree

 

Field of Study Preferred:

Information security, Computer Science, Finance, or related field required

 

Required Work Experience:

  • 15+ years in SAP Security, SAP GRC, and bolt on apps, with the majority of tenure in hands-on SAP security roles and GRC 10.1/12.0, including implementation experience with all GRC Access Control Modules
  • Big 4 experience strongly preferred
  • Extensive experience delivering SAP Security and Authorization solutions across complex SAP environments, with strong expertise in SAP S/4HANA Security, Role Design and Authorization Concepts, and SAP Security Roles and Authorizations.
  • Deep hands-on knowledge of SAP user administration, authorization objects, landscape security, and GRC MSMP/BRF+ configurations.
  • 5+ years in leadership roles managing teams and programs; experience leading both SAP and Governance initiatives
  • Proven capability engaging business and technical stakeholders, conducting access and risk assessments, resolving security issues, and producing high-quality security design, governance and compliance documentation
  • Experience supporting SAP transformation and cloud adoption programs across SAP S/4HANA and SAP BTP environments.
  • Experience with Licensing Optimization in SAP S/4 Cloud Instances
  • Experience with Cross-System Risk Analysis and Ruleset construction from Scratch

 

Required Training/Certifications:

  • CISSP, CISM, CISA, or CRISC (preferred)
  • SAP Security or SAP GRC certifications (preferred)

 

Required Technical Skills: SAP Security Must Have:

  • S/4HANA Security
  • ECC Security
  • BTP & Fiori
  • HANA DB Security
  • SAP GRC ARA
  • SAP GRC ARM
  • SAP GRC EAM
  • Process Control
  • SoD Rule Sets
  • Mitigating Controls
  • RBAC / Role Design
  • SOX / ITGC Compliance

 

Travel Requirements: 30-40%

 

Additional Requirements:

  • Strategic thinker with strong hands-on execution in SAP security environments
  • Deep technical credibility in SAP security coupled with broad SOX and Governance awareness
  • Exceptional communication skills — able to translate SoD and access risks into business impact
  • Collaborative leader who can influence without authority across IT, Finance, and Compliance
  • Ability to manage complexity across multiple SAP instances, GRC and S/4 Hana
  • Successful candidates must adhere to all safety protocols and proper use of Amrize approved Personal Protection Equipment ("PPE"), including but not limited to respirators. Subject to applicable law, employees that are required to wear respirators must be clean shaven where the respirator seal meets the face in order to pass the qualitative and quantitative fit tests.

 

WHAT WE OFFER    

  • Competitive salary
  • Retirement Savings: Choose from 401(k) pre-tax and/or Roth after-tax savings
  • Employee Stock Purchase Plan 
  • Medical, Dental, Disability and Life Insurance  
  • Holistic Health & Well-being programs
  • Health Savings Accounts (HSAs) & Flexible Spending Accounts (FSAs) for health and dependent care
  • Vision and other Voluntary benefits and discounts
  • Paid time off & paid holidays
  • Paid Parental Leave (maternity & paternity)
  • Educational Assistance Program
  • Dress for your day

#LI-SZ1

 

Amrize is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

We thank all applicants for their interest; however, only those selected for an interview will be contacted.

 

 

 

BUILDING INCLUSIVE WORKSPACES
At Amrize, there is endless opportunity for you to play your part. Whether you’re in a technical, managerial, or frontline role, you can shape a career that works for you. We're seeking builders, creative thinkers and innovators. Come put your expertise to work while developing the knowledge and skills to drive your career forward. With us you’ll have the chance to build your ambition!   

Amrize North America Inc. takes pride in our hiring processes and our commitment that all qualified applicants will receive consideration for employment without regard to age, race, color, ethnicity, religion, creed, national origin, ancestry, gender, gender identity, gender expression, sex, sexual orientation, marital status, pregnancy, parental status, genetic information, citizenship, physical or mental disability, past, current, or prospective service in the uniformed services, or any other characteristic protected by applicable federal, state or local law. Amrize North America Inc, and its respective subsidiaries are Equal Opportunity Employers, deciding all employment on the basis of qualification, merit and business need.  Amrize Canada Inc. is committed to the principles of employment equity and encourages the applications from women, visible minorities, and persons with disabilities. Amrize North America Inc. participates in E-Verify and will provide the federal government with your I-9 information to confirm that you are authorized to work in the United States.

In compliance with the ADA Amendments Act (ADAAA), if you have a disability and would like to request accommodation in order to apply for a position with us, please email recruiting-accommodations@amrize.com. This email address should only be used for accommodations and not general inquiries or resume submittals. In Ontario, our organization/business is committed to fulfilling our requirements under the Accessibility for Ontarians with Disabilities Act. Under the Act, accommodations are available on request for candidates taking part in all aspects of the selection process.

While we sincerely appreciate all applications, only candidates selected for an interview will be contacted.

PROTECT YOURSELF FROM RECRUITMENT FRAUD
The only way to apply for a position at Amrize is through our official Careers website. Be cautious of unsolicited offers or requests for information from other sources. Learn how to protect yourself from recruitment fraud here: Fraudulent Job Offers Policy


Nearest Major Market: Chicago