Summary
Overview
Work History
Education
Skills
Certification
Current Profile
Timeline
Generic

Vinay Sharma

PUNE

Summary

16+ years of experience in Security and Compliance Framework, Design architecture, Identity and Access Governance, SAP Role Design, Segregation of Duties (SOD), access control and security Transformation. Strong expertise in SAP Security, SAP S/4HANA, SAP Fiori, role-based access control, business role design, SoD risk management, access provisioning, access reviews, role governance and compliance. Working as a POC for all Security and Compliance related issues raised by external Auditors and Business, currently leading a team of 7 members focused on nurturing positive working relationships. Expertise in SAP security Implementation in Germany as part of IBM India and Springer Nature India Team. Expertise in providing consultancy on Security and Compliance with Strong understanding of IAM/IAG concepts including Identity Lifecycle Management, RBAC, access governance, privileged access management, excellent communication skills and ability to easily learn and adapt to new technologies in a short time. Extensive experience of working and interacting with key stakeholders at multiple Client locations. Proficiency in concepts like SOD, Security Compliance, Mitigation, Remediation, Emergency Access Management, Business Role Management, Access Risk Analysis, Access Request Management etc.

Overview

1
1
Certification
18
18
years of professional experience

Work History

Project Manager

Springer Nature
Pune
11.2015 - Current
  • Working in Springer Nature Pune as Project Manager Lead and coordinate SAP Security and access governance initiatives from requirement definition through implementation, testing, deployment and operational handover currently doing the Upgrade of SAP S4 system along with Lift and Shift to AWS Cloud.
  • Manage project scope, deliverables, timelines, dependencies, resources, risks, issues and stakeholder expectations.
  • Lead SAP role design activities across business processes including P2P, O2C, R2R, Finance, Procurement and maintain SoD risk rulesets, business risk definitions, mitigating controls and remediation processes.
  • Work with Internal and External Audit and Compliance Team to evaluate security conflicts and consult with business unit's / Role owners in designing the SOD Plan.
  • Doing the Security Role implementation in APM and Xiting Tool and getting the SAP system audit relevant from Security perspective.
  • Managing Knowledge transfer sessions to team members and creating process documents for their reference.

Sr. Tech. Consultant

Accenture
Pune
01.2014 - 11.2015
  • Worked in Accenture as Sr. Tech. Consultant on SAP Security in Onsite/Offshore model in Henkel project primarily on Enhancements issue and support work for German Client.
  • Worked on the Audit Relevant Issues in R/3 as part of Audit requirement / cleanup work.
  • Provided training within the organization at the IDC level across various locations for other Security and Compliance modules like HR, BW and GRC.
  • Coordinated with the maintenance team on various issues like user request creation, workflow for GRC system and normal R/3 related issues or on any other issue which needed interaction between enhancement and maintenance team.

Sr. Tech. Consultant

KPIT CUMMINS
Pune
04.2012 - 12.2013
  • Worked in PITC (Paccar India Technical Centre) Pune as Sr. Tech. Consultant on SAP Security.
  • Coordinating with SAP Functional and Development Teams to arrive at sound SAP security solutions.
  • Looked into process improvement and automation activities where possible.
  • Ensure users are assigned to specific firefighting IDs with defined authorizations and validity dates, as well as documentation regarding reason for use.
  • Mitigation on the basis of alternative controls to mitigate risks and educate management about conflict approval and monitoring, document process to monitor mitigation controls.
  • Risk Analysis, Risk Identification, classification with reference to Business Process Owners, Identifying the Critical Transactions code within Business Processes.
  • Defining the Approval system, configuration based on organizational policies and business process.
  • Maintain Configuration settings in the system like Maintain Owners, Firefighters, Controllers, Reason Code Configuration, and Critical Transactions code.
  • Raising requests for New, Change, Lock/unlock and Delete user account in ARM.

IBM
Gurgaon
05.2010 - 08.2011
  • Total E&P is an oil production company with branches all across the world.
  • I was working in this project on the security aspect of SAP and have worked in collaboration with my team to provide solution to our customer within the SLA agreement Defined and in a way that is easy for them to understands and Analyze.
  • Handling Production Support issues and training end users on SAP Security.
  • Analyzing the User Access Problems and Providing Authorization reports through User Information System.
  • Coordinating with SAP Functional and Development Teams to arrive at sound SAP security solutions.
  • Providing End User Support and resolved all the end user related issues.
  • Traced missing authorizations objects and recommending appropriate roles for the end users.
  • Analyzed root cause of security failures to resolve help desk tickets, support unit and integration testing of roles.

IBM
Gurgaon
07.2009 - 04.2010
  • In IBM GBS did onsite implementation for the client in Germany (Global Foundries) which is the part of AMD Group and specializes in the chip manufacturing process with a production plant in Dresden, Germany.
  • Business Requirement Analysis, Design, Testing, Deployment and Support of SAP roles in SAP ECC systems.
  • Set up security roles and user accounts for End User for primary Go Live.
  • Handling production support issues and training end users on SAP Security.
  • Sap User Creation, assigning profile and User maintenance.
  • Worked on creating customized transactions for Tables and programs as per business requirements.
  • Risk Analysis by executing analytical reports, estimate cleanup efforts, analyzing roles and users, modifying the rules based on analysis and setting alert mechanism if required.
  • Generating User reports (Log summary Report, Reason/Activity Report, Transaction usage Report, Log Report, SOD Violation Report, Configure change History report).
  • Determine and report if any risks will be introduced by simulating and Identifying potential SOD issues before assigning new roles to the user.
  • Worked for identifying risks, mitigation control for the risks, generating various security reports from user access point of view.

SAP Security Analyst

Patni Computers
Mumbai
06.2008 - 07.2009
  • In this project our responsibilities were to support the client in all security related issues varying from user creation, password reset, role creation and their maintenance.
  • Proactively kept the customer informed on the status of their request/problem resolutions. Advise the customer on all SAP access security matters Liaised with other members in the team (expert in their Field) to full fill the customer's needs User administration: creating changing, deleting, lock/unlock and password reset of users. Monitored the system to ensure that users were not assigned to sap delivered roles or roles do not have a wildcard
  • In the authorization objects in T Codes. Simulate changes to roles and users, Mapping of missed / extra Authorization objects in T codes.
  • Working as SAP Security Analyst with excellent knowledge on User Roles, Profiles, Authorizations and Activity Groups.
  • Analyzed failed authorization and resolve the same.
  • Documentation and End User Training.

Education

Post-Graduation - Foreign Trades

Pune University
01-2008

Bachelor's - electrical engineering

Jammu University
01-2005

Skills

  • Provided trainings within the organization on IDC level in Accenture India
  • An ardent analyst with a flair for adapting quickly to dynamic business environments and resolving complex business issues; dept in interacting with clients, understanding current business processes, gathering new business user requirements and mapping them into system Requirements
  • Proven ability to coordinate with Security, Infrastructure, Enterprise Architecture, Application, Compliance, Audit, Business and external service providers to deliver security initiatives aligned with business objectives, regulatory requirements and organizational risk appetite

Certification

  • ITIL ( Information Technology Infrastructure Library )
    SAP GRC ( Governance Risk and Compliance )
    CISA ( Certified Information Systems Auditor )
    CISM ( Certified Information Security Manager )
    CISSP ( Certified Information Systems Security Professional )
    PMP ( Project Management Professional )

Current Profile

Project Manager SAP/GRC/IAG Security

Timeline

Project Manager

Springer Nature
11.2015 - Current

Sr. Tech. Consultant

Accenture
01.2014 - 11.2015

Sr. Tech. Consultant

KPIT CUMMINS
04.2012 - 12.2013

IBM
05.2010 - 08.2011

IBM
07.2009 - 04.2010

SAP Security Analyst

Patni Computers
06.2008 - 07.2009

Post-Graduation - Foreign Trades

Pune University

Bachelor's - electrical engineering

Jammu University
Vinay Sharma