
Shamita Dixit
- SAP Security and GRC Lead
- Cupertino, CA
- Member Since May 07, 2023
SAP Security and Compliance lead, ITIL V3, SAP GRC Certified
Over 11 years of SAP SECURITY ADMINISTRATION & SOX COMPLIANCE EXPERTISE
Well experienced with multiple SAP security lifecycles (Analysis & Conception, Implementation, Quality Assurance & Tests and Cutover)
Extensive 9 years in Segregation of Duties compliance and Risk Assessment in adherence Audit Compliance Standards.
SAP Security Service Management experience:
SAP R/3 4.6c/4.7/ECC 5.0/6.0/ Security design, implementation and management across various SAP modules like PP/MM//WM/HR/FICO/SD and new dimension products BI/BW, HR, CRM, Solution Manager and HANA
Three full life cycle implementation of SAP Security projects from design to post-implementation phase using ASAP methodology
Expertise in gathering and analyzing requirements from Client, providing solution proposals and ensuring timely deliverables
Primary contact for client for all Security related issues and Audit support including Risk assessment and building controls
Expertise in remediation of SOX issues and implementing controls
Well versed with SSO solutions to enable user authentication and integration with Java portals/Enterprise portals across IDM systems
Proficient in HR structural authorizations security administration/position based security model (PBS)
Well versed in security implementation for the BI 7.0 Analysis Authorizations concept
Expert with Profile Generator (PFCG), designing derived, Composite and Single Roles. Troubleshooting R/3 Security issues (SU53, ST01), RSECADMIN for BI, setting up Central User Administration (CUA) and maintenance, role Transports (STMS)
Problem analysis and troubleshooting, ECATT Scripts, transporting roles, Security audit logging using SM19/SM20
Experience with Identity management and problem management tools - IBM Tivoli manager, Remedy, SMART tools, HP Service manager, Espresso/Radar
Manage Onshore/Offshore SAP Security project and Support teams
Develop Governance reports and dashboards for client meetings
Responsible for Estimation, Planning and Execution with specific focus on requirement analysis and design
Experience in leading and guiding the support delivery teams in Unit testing of the roles using the business process procedure (BPPs) and BRDs
GRC/Compliance Management experience:
Expertise in implementation of preventative, mitigating and compensation controls, ensuring protection and adherence to the goals of organizational SAP Security GRC strategy
Three Full life-cycle implementations of SAP GRC 5.3 (RAR, SPM suite) and GRC 10.0 (ARA/EAM/ARM/UAR workflow suite) based client needs using GRC BRF+ workflow and MSMP methodology.
Extensive experience with Firefighter/SPM/EAM, creating Fire Fighter IDs, designing and assigning Fire Fighter roles and monitoring Fire Fighter logs activities
Led SAP GRC projects focusing Risk Remediation and Mitigation of Segregation of Duty SOD conflicts on both Users and roles level, critical access review using SAP GRC 5.3/10.0
Experience using and integrating SAP SOD tool for rules design, SOD, remediation, migration controls and maintaining complete lifecycle blueprint from go-live to post go live for continuous compliance.
Experience handling SOX Audits and implementing proper controls to protect the applications Security with central point of contact for Internal/External audit efforts.
Responsible for delivery of IT audit and governance activities including reviewing of IT audit scope, feasibility of IT controls and refining IT General Computer Controls.
Tailor standard Rule Set to meet client’s needs and identified and cleaned up false positives
Projects handled:
GRC 5.3 and GRC 10.0 (2 lifecycles) end-to-end implementations for Access control ARA/EAM/ARM/BRM components
SAP Single sign-on (SSO) implementation across Production systems in a 3-tier SAP model involving challenges around access management for different person types.
SAP ECC 5.0 upgrade, EHP upgrades, Security design for various SAP ECC modules, Work management/plant maintenance/ HR structural authorizations design and Enhancement projects.
Industry Experience:
Computer hardware/software and Consumer electronics, Consumer Packaged goods (CPG), Electric and Gas Energy and Utility, Health care, Retail, IT services and solutions
CERTIFICATIONS:
Current Certifications |
Year Attained |
ITIL V3 foundation (License: 100321808) |
2012 |
(C_GRCAC_10) SAP GRC Business Objects Access Control 10.0 Certified Application Associate (Validation ID: 339398575) |
2016 |
Trainings:
SAP Project Management (C_PM_71) training in 2015.
Skill Set |
SAP version: SAP ECC 6.0 (latest EHP7), ECC 5.0, 4.7, 4.6C, 4.6B SAP modules: SAP R/3 4.6B, 4.6C, 4.7, ECC 5.0, ECC 6.0, MM, FI/CO, HR, SD, PP HCM Security SAP BI 7.0, BW/BI, BOBJ, HANA CRM, SRM, Solution Manager SAP Enterprise Portal GRC 5.3 (RAR/SPM), GRC 10.0 (ARA/EAM/ARM/BRM) components, GRC Process control 2.5 IDM tools: HP Service Manager, Access Manager, Sail point, IBM Tivoli manager, Espresso Office tools: MS (MS-Word, MS-Access, MS-Excel, PowerPoint) Databases: SQL, MS Access 2000/97, MS SqlServer2000 |
PROFESSIONAL EXPERIENCE:
Client: APPLE INC |
Sunnyvale, CA, USA |
Nov 2014– August 2016 |
|
Project Type |
Consultant at APPLE Inc. (Nov 2014- August 2016) |
||
Role |
SAP Security and GRC Lead
|
||
Environment |
SAP ECC (6.0), SAP EP (7.0), Solution Manager, HANA, BI 7.0, GRC 10.0/10.1
|
||
Responsibilities |
· Lead SAP Security implementation, SOD Compliance Projects and Security production Support team · Track Security issues, role modifications with focus on SOD risk compliance · Build a strategy, vision and roadmap for attaining effective and efficient identity and access management controls · Lead the day-to-day activities of ERP advisory engagements for a variety of clients including process design, package implementation lifecycle support, and project reviews · Conduct meetings and working session workshops to discuss and implement the approved design · Draft design documents to cover all functionality configured for ongoing support · Work with the technical development teams to create custom function modules to enhance standard functionality to fit the complex cross process-id usage requirement · Built complex usage of multiple custom document objects using standard same message class and building custom notification template id's · Draft project plan and process design documents to cover all functionality offered vs. what is actually needed · Work with the SOX team to discuss implementation strategies for custom transactions and programs and to enable/disable rule set objects as required and approved · Development of tailored security and controls techniques in conjunction with system upgrade (i.e. ERP) · Handle multiple projects at various countries and time zones simultaneously
|
||
Hewlett Packard Enterprise Services |
Palo Alto, CA, USA |
Oct 2008–Oct 2014 |
|
Project Type |
The Clorox Company (CPG company) Service delivery lead |
||
Role |
SAP Security Service and Compliance Management |
||
Responsibilities |
· Manage day-to-day Security support and analyze/resolve complex issues on time. Lead the best shore Security support team (IT an SAP Security). · Work with the Business on a daily basis to analyze security concerns and areas of improvements/suggest new enhancements. · Recognize and evaluate potential dangers and risks within business process chains as it relates to security in order to protect Organization through the use of the Governance, Risk and Compliance tool. · Lead the deployment of global and consistent Identity and Access tool and processes. · Manage periodic CSA audit activities and relevant access remediation in support of External Audits. · Building a strategy, vision and roadmap for attaining effective and efficient identity and access management controls · Analyze reported problems, enhancement requests, and minor and major role redesign for feasibility and appropriateness; · Manage Risk control related matters including SAP security, role methodology and process and controls. · Engage other groups in finding solutions to identified compliance issues, plan and schedule work for the Security Technical Team, monitor and report on progress, and make adjustments as required; · Monitor completion of work assignments; track progress and ensure completion of all daily tasks involving User and authorization administration. · Developing Governance reports and progress dashboards for governance board meetings. · Assist the SAP Support group in developing strategy for optimizing the use of SAP, and assist in business case development and advise on the feasibility of potential future projects. · Maintain an awareness of SAP Security and GRC, best practices, and SAP trends and directions. · Recommend security strategies that are aligned with the City’s business strategy and are consistent with SAP’s enterprise architecture and strategic direction and computing platform standards. · Responsible for creating and maintaining supporting documentation for SAP security technical design and configuration. · Define the Audit sectors for each Fiscal year and reviewing the provisioning and maintenance procedures around those. · Past projects- SAP Upgrade, Identity & Access Management Integration Projects and SAP security outsourcing. |
||
Puget Sound Energy |
Seattle, WA, USA |
Jun 2007- Oct 2008 |
|
Project Type |
SAP implementation projects and application maintenance |
||
Role |
SAP Security team lead |
||
Responsibilities |
· Led Onsite Security Support team responsible for SAP Security role design, implementation and support for SAP ECC/HR/BI/CRM/SOLMAN on GUI and Net weaver platforms. · Designed an efficient security strategy for the company's future releases · Implemented HR Position based Security using Structural Authorization. · Developed Security solutions for HR Payroll Work management modules and supported SAP BI7.0 with analysis authorizations using RSECADMIN · Configured VIRSA CC 5.0 (former GRC Access control) across all ECC modules. · Identify potential IT & Process risks beyond traditional audit findings for SOX compliance · Fully documented security landscape, procedures, and notes for turn-over to client · Participated in requirements gathering, assessment, design, configuration and testing activities for SAP security.
|
||
Mentis Systems (Client :UHC ) |
NJ, USA |
Nov 2006-June 2007 |
|
Project Type |
United Health Care – IT development and support |
||
Role |
Sr. SAP Security Analyst |
||
Responsibilities |
· Designed SAP security using best practices and standards after gathering business requirements from end users.
|
||
HCL Technologies (Client: AMD) |
Noida, UP, India |
Jul 2004- Oct 2006 |
|
Project Type |
AMD (IT services and catalog management) |
||
Role |
IT Security Analyst |
||
Responsibilities |
|
||
· Bachelors of Technology (B.Tech) (Information technology) - ABES, UP technical University, UP India (2004)
· MBA (I.T.) – Symbiosis Center of Distance Learning, Pune, India (2006)