Shamita Dixit

  • SAP Security and GRC Lead
  • Cupertino, CA
  • Member Since May 07, 2023

Candidates About

 

Shamita Dixit

SAP Security and Compliance lead, ITIL V3, SAP GRC Certified

                                                                                                                                                                               

PROFESSIONAL SUMMARY:

Over 11 years of SAP SECURITY ADMINISTRATION & SOX COMPLIANCE EXPERTISE

Well experienced with multiple SAP security lifecycles (Analysis & Conception, Implementation, Quality Assurance & Tests and Cutover)

Extensive 9 years in Segregation of Duties compliance and Risk Assessment in adherence Audit Compliance Standards.

SAP Security Service Management experience:

SAP R/3 4.6c/4.7/ECC 5.0/6.0/ Security design, implementation and management across various SAP modules like PP/MM//WM/HR/FICO/SD and new dimension products BI/BW, HR, CRM, Solution Manager and HANA

Three full life cycle implementation of SAP Security projects from design to post-implementation phase using ASAP methodology

Expertise in gathering and analyzing requirements from Client, providing solution proposals and ensuring timely deliverables

Primary contact for client for all Security related issues and Audit support including Risk assessment and building controls

Expertise in remediation of SOX issues and implementing controls

Well versed with SSO solutions to enable user authentication and integration with Java portals/Enterprise portals across IDM systems

Proficient in HR structural authorizations security administration/position based security model (PBS)

Well versed in security implementation for the BI 7.0 Analysis Authorizations concept

Expert with Profile Generator (PFCG), designing derived, Composite and Single Roles. Troubleshooting R/3 Security issues (SU53, ST01), RSECADMIN for BI, setting up Central User Administration (CUA) and maintenance, role Transports (STMS)

Problem analysis and troubleshooting, ECATT Scripts, transporting roles, Security audit logging using SM19/SM20

 

 

Experience with Identity management and problem management tools - IBM Tivoli manager, Remedy, SMART tools, HP Service manager, Espresso/Radar

Manage Onshore/Offshore SAP Security project and Support teams

Develop Governance reports and dashboards for client meetings

Responsible for Estimation, Planning and Execution with specific focus on requirement analysis and design

Experience in leading and guiding the support delivery teams in Unit testing of the roles using the business process procedure (BPPs) and BRDs

GRC/Compliance Management experience:

Expertise in implementation of preventative, mitigating and compensation controls, ensuring protection and adherence to the goals of organizational SAP Security GRC strategy

Three Full life-cycle implementations of SAP GRC 5.3 (RAR, SPM suite) and GRC 10.0 (ARA/EAM/ARM/UAR workflow suite) based client needs using GRC BRF+ workflow and MSMP methodology.

Extensive experience with Firefighter/SPM/EAM, creating Fire Fighter IDs, designing and assigning Fire Fighter roles and monitoring Fire Fighter logs activities

Led SAP GRC projects focusing Risk Remediation and Mitigation of Segregation of Duty SOD conflicts on both Users and roles level, critical access review using SAP GRC 5.3/10.0

Experience using and integrating SAP SOD tool for rules design, SOD, remediation, migration controls and maintaining complete lifecycle blueprint from go-live to post go live for continuous compliance.

Experience handling SOX Audits and implementing proper controls to protect the applications Security with central point of contact for Internal/External audit efforts.

Responsible for delivery of IT audit and governance activities including reviewing of IT audit scope, feasibility of IT controls and refining IT General Computer Controls.

Tailor standard Rule Set to meet client’s needs and identified and cleaned up false positives

Projects handled:

GRC 5.3 and GRC 10.0 (2 lifecycles) end-to-end implementations for Access control ARA/EAM/ARM/BRM components

SAP Single sign-on (SSO) implementation across Production systems in a 3-tier SAP model involving challenges around access management for different person types.

SAP ECC 5.0 upgrade, EHP upgrades, Security design for various SAP ECC modules, Work management/plant maintenance/ HR structural authorizations design and Enhancement projects.

 

Industry Experience:

Computer hardware/software and Consumer electronics, Consumer Packaged goods (CPG), Electric and Gas Energy and Utility, Health care, Retail, IT services and solutions

 

 

 

CERTIFICATIONS:

 

Current Certifications

Year Attained

ITIL V3 foundation (License: 100321808)

         2012

(C_GRCAC_10) SAP GRC Business Objects Access Control 10.0 Certified Application Associate (Validation ID: 339398575)

2016

 

 

Trainings:

SAP Project Management (C_PM_71) training in 2015.

 

TECHNICAL SKILLS:

Skill Set

SAP version: SAP ECC 6.0 (latest EHP7), ECC 5.0, 4.7, 4.6C, 4.6B

SAP modules: SAP R/3 4.6B, 4.6C, 4.7, ECC 5.0, ECC 6.0, MM, FI/CO, HR, SD, PP

HCM Security

SAP BI 7.0, BW/BI, BOBJ, HANA

CRM, SRM, Solution Manager

SAP Enterprise Portal

GRC 5.3 (RAR/SPM), GRC 10.0 (ARA/EAM/ARM/BRM) components, GRC Process control 2.5

IDM tools: HP Service Manager, Access Manager, Sail point, IBM Tivoli manager, Espresso

Office tools: MS (MS-Word, MS-Access, MS-Excel, PowerPoint)

Databases: SQL, MS Access 2000/97, MS SqlServer2000

 

 

 

PROFESSIONAL EXPERIENCE:

 

Client: APPLE INC

Sunnyvale, CA, USA

Nov 2014– August 2016

Project Type

Consultant at APPLE Inc. (Nov 2014- August 2016)

Role

SAP Security and GRC Lead

 

Environment

SAP ECC (6.0), SAP EP (7.0), Solution Manager, HANA, BI 7.0, GRC 10.0/10.1

 

Responsibilities

·         Lead SAP Security implementation, SOD Compliance Projects and Security production Support team

·         Track Security issues, role modifications with focus on SOD risk compliance

·         Build a strategy, vision and roadmap for attaining effective and efficient identity and access management controls

·         Lead the day-to-day activities of ERP advisory engagements for a variety of clients including process design, package implementation lifecycle support, and project reviews

·         Conduct meetings and working session workshops to discuss and implement the approved design

·         Draft design documents to cover all functionality configured for ongoing support

·         Work with the technical development teams to create custom function modules to enhance standard functionality to fit the complex cross process-id usage requirement

·         Built complex usage of multiple custom document objects using standard same message class and building custom notification template id's

·         Draft project plan and process design documents to cover all functionality offered vs. what is actually needed

·         Work with the SOX team to discuss implementation strategies for custom transactions and programs and to enable/disable rule set objects as required and approved

·         Development of tailored security and controls techniques in conjunction with system upgrade (i.e. ERP)

·         Handle multiple projects at various countries and time zones simultaneously

 

       

 

 

Hewlett Packard

Enterprise Services

Palo Alto, CA, USA

Oct 2008–Oct 2014

Project Type

The Clorox Company (CPG company) Service delivery lead

Role

SAP Security Service and Compliance Management

Responsibilities

·         Manage day-to-day Security support and analyze/resolve complex issues on time. Lead the best shore Security support team (IT an SAP Security).

·         Work with the Business on a daily basis to analyze security concerns and areas of improvements/suggest new enhancements.

·         Recognize and evaluate potential dangers and risks within business process chains as it relates to security in order to protect Organization through the use of the Governance, Risk and Compliance tool.

·         Lead the deployment of global and consistent Identity and Access tool and processes.

·         Manage periodic CSA audit activities and relevant access remediation in support of External Audits. 

·         Building a strategy, vision and roadmap for attaining effective and efficient identity and access management controls

·         Analyze reported problems, enhancement requests, and minor and major role redesign for feasibility and appropriateness;

·         Manage Risk control related matters including SAP security, role methodology and process and controls. 

·         Engage other groups in finding solutions to identified compliance issues, plan and schedule work for the Security Technical Team, monitor and report on progress, and make adjustments as required;

·         Monitor completion of work assignments; track progress and ensure completion of all daily tasks involving User and authorization administration.

·         Developing Governance reports and progress dashboards for governance board meetings.

·         Assist the SAP Support group in developing strategy for optimizing the use of SAP, and assist in business case development and advise on the feasibility of potential future projects.

·         Maintain an awareness of SAP Security and GRC, best practices, and SAP trends and directions.

·         Recommend security strategies that are aligned with the City’s business strategy and are consistent with SAP’s enterprise architecture and strategic direction and computing platform standards.

·          Responsible for creating and maintaining supporting documentation for SAP security technical design and configuration.

·          Define the Audit sectors for each Fiscal year and reviewing the provisioning and maintenance procedures around those.

·          Past projects- SAP Upgrade, Identity & Access Management Integration Projects and SAP security outsourcing.



       

 

Puget Sound Energy

Seattle, WA, USA

Jun 2007- Oct 2008

Project Type

SAP implementation projects and application maintenance

Role

SAP Security team lead

Responsibilities

·         Led Onsite Security Support team responsible for SAP Security role design, implementation and support for SAP ECC/HR/BI/CRM/SOLMAN on GUI and Net weaver platforms.

·         Designed an efficient security strategy for the company's future releases

·         Implemented HR Position based Security using Structural Authorization.

·         Developed Security solutions for HR Payroll Work management modules and supported SAP BI7.0 with analysis authorizations using RSECADMIN

·         Configured VIRSA CC 5.0 (former GRC Access control) across all ECC modules.

·         Identify potential IT & Process risks beyond traditional audit findings for SOX compliance

·         Fully documented security landscape, procedures, and notes for turn-over to client

·         Participated in requirements gathering, assessment, design, configuration and testing activities for SAP security.

 

       

 

Mentis Systems

(Client :UHC )

 NJ, USA

Nov 2006-June 2007

Project Type

United Health Care – IT development and support

Role

Sr. SAP Security Analyst

Responsibilities

  • Completed a SAP security enhancement on MM Purchasing functionality.

·         Designed SAP security using best practices and standards after gathering business requirements from end users.

  • Completed a Business Process Reengineering project for implementing SAP R/3. Implemented business controls in SAP through the definition of a controls process.
  • Designed and maintained Security roles using PCFG/profile generator/CATT /LSMW scripts.
  • Performed auditing and SOD check using compliance calibrator tools.
  • Performed high-risk analyses for MM and SD business processes to assess all high-risk transactions and analyzed all the company's legacy interfaces with SAP.
  • Assisted in implementing SOLMAN for raising Change requests for Production.
       

 

HCL Technologies (Client: AMD)

Noida, UP, India

Jul 2004- Oct 2006

Project Type

AMD (IT services and catalog management)

Role

IT Security Analyst

Responsibilities

  • Performed User administration and assigning them to SAP security policies and groups
  • Tier 2/3 level support as part of SAP Security Administration
  • Responsible for maintenance of Oracle 9i and Oracle 8i Database running on Windows/Unix platforms.
  • Job involved planning and installation of Oracle 9i Databases.
  • Resolved database performance related issues in production environment.
  • Responsible for backups and recovery for Oracle Database.

 

       

 

EDUCATION:

·         Bachelors of Technology (B.Tech) (Information technology) - ABES, UP technical University, UP India (2004)

·         MBA (I.T.) – Symbiosis Center of Distance Learning, Pune, India (2006)