Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal SAP Security Architect (S/4HANA & Government Systems)

Avantor

Principal Saviynt IAM Architect (Government Systems & SAP Security Integration) Serves as the enterprise design authority for Identity Governance & Administration (IGA), identity lifecycle automation, and regulated access architecture supporting NuSil's U.S. Government operations. This role is primarily responsible for architecting and leading Avantor's identity governance strategy within highly regulated environments, including the implementation and integration of Saviynt with SAP S/4HANA and other enterprise platforms. Team CMMC (Cybersecurity Maturity Model Certification) requirements Controlled Unclassified Information (CUI) handling mandates ITAR / Export Administration Regulations (EAR) restrictions Controlled materials and proprietary formulation protections SOX IT General Controls What We're Looking For Education : Bachelor's degree and/or equivalent experience, education and training Experience 12+ years of Identity & Access Management experience 5+ years of enterprise IGA architecture experience Deep expertise with Saviynt architecture, workflows, and governance models Strong understanding of identity lifecycle management, entitlement modeling, automated provisioning, access certification, and role governance Experience integrating IDM solutions with SAP S/4HANA and enterprise applications Experience designing IAM controls in regulated environments subject to CMMC, CUI, ITAR, or SOX Expert understanding of SAP authorization concepts and SAP role structures Experience designing identity-driven access controls for enterprise ERP environments Demonstrated ability to operate independently as enterprise architectural authority Preferred Qualifications Saviynt certifications or implementation experience Experience with SAP GRC Access Control Experience supporting U.S. Government or defense-regulated environments Familiarity with Zero-Trust and ABAC security models Experience with data masking or privileged access governance solutions CISSP, CIAM, or related security certifications Primary Responsibilities Identity Governance & Administration (IGA) Architecture Serve as the architectural authority for SAP implementation and identity governance strategy Design enterprise identity governance frameworks supporting regulated environments Architect identity lifecycle processes including Joiner/Mover/Leaver automation Define enterprise entitlement models and role governance structures Design automated provisioning and de-provisioning workflows across SAP and integrated platforms Architect access certification, attestation, and role review processes Define identity governance controls supporting audit, compliance, and regulatory requirements Engineer scalable identity governance models supporting growth of U.S. Government operations Define API integration strategies, connectors, and identity synchronization mechanisms Saviynt Platform Architecture & Integration Lead architecture and integration of Saviynt with SAP S/4HANA and other enterprise systems Define entitlement mapping strategies between SAP roles and Saviynt access models Architect birthright access, dynamic role assignment, and conditional access frameworks Configure and optimize provisioning workflows, approval chains, and governance processes Prevent over-provisioning and privilege escalation through identity-centric control design Design scalable identity governance processes for regulated manufacturing environments Partner with enterprise IAM teams on roadmap, standards, and platform optimization CMMC, CUI & ITAR-Aligned Access Architecture Architect identity-driven access controls aligned to CMMC access control domains Engineer segregation and governance of CUI within enterprise systems Design controls ensuring ITAR-restricted data is accessible only to authorized U.S. persons Define identity governance models supporting controlled manufacturing and export-sensitive processes Implement auditable and traceable identity governance controls for regulated environments Partner with Information Security and Compliance teams to support evolving regulatory requirements SAP Security Integration Provide architectural oversight for SAP S/4HANA and Fiori security integration into Saviynt Support SAP role governance, entitlement mapping, and Segregation of Duties alignment Partner with SAP Security teams on SAP GRC integration, access certification alignment, provisioning workflows, and SoD remediation strategies Ensure SAP authorization structures align with enterprise IAM governance models Support secure integration of SAP identities, RFC/service accounts, and privileged access workflows Data Protection & Sensitive Access Controls Support governance of sensitive and regulated data access within SAP and integrated platforms Architect identity-centric controls supporting data masking, sensitive data segmentation, and privileged access governance Partner with Security and SAP teams on Zero-Trust and least‑privilege initiatives Ensure regulated data access is controlled through sustainable identity governance processes Regulatory & Audit Technical Leadership Serve as IAM technical authority during CMMC readiness reviews and audits Support audit evidence generation related to identity governance and access certification Design defensible access governance processes aligned to SOX and regulatory expectations Lead remediation efforts related to identity governance findings and access control deficiencies Partner with Internal Audit, Compliance, and Security teams on preventive control design Leadership & Cross-Functional Influence Act as principal-level technical authority for identity governance architecture Influence enterprise IAM and access governance strategy decisions Partner cross‑functionally with SAP teams, Information Security, Infrastructure, Compliance, Internal Audit, and Enterprise IAM teams Mentor IAM engineers and analysts Reduce dependency on external consultants by institutionalizing identity governance expertise Complexity & Regulatory Impact Multi‑regulatory exposure (CMMC, CUI, ITAR, SOX) Defense‑customer audit scrutiny Enterprise identity governance across regulated manufacturing systems Complex entitlement and provisioning architecture across SAP and integrated platforms Direct impact on government contract eligibility and audit readiness Enterprise‑level IAM design authority Cross‑platform integration complexity spanning Saviynt, SAP, security tooling, and enterprise identity infrastructure Remote Position #LI-Remote Disclaimer The above statements are intended to describe the general nature and level of work being performed by employees assigned to this classification. They are not intended to be construed as an exhaustive list of all responsibilities, duties and skills required of employees assigned to this position. Avantor is proud to be an equal opportunity employer. Pay Transparency The expected pre‑tax pay for this position is Actual pay may differ depending on relevant factors such as prior experience and geographic location. EEO Statement We are an Equal Employment / Affaffirmative Action employer and VEVRAA Federal Contractor. We do not discriminate in hiring on the basis of sex, gender identity, sexual orientation, race, color, religious creed, national origin, physical or mental disability, protected Veteran status, or any other characteristic protected by federal, state/province, or local law. Contact For reasonable accommodation requests, email View email address on click.appcast.io. Benefits Avantor offers a comprehensive benefits package including medical, dental, and vision coverage, wellness programs, health savings and flexible spending accounts, a 401(k) plan with company match, and an employee stock purchase program. Employees also receive 11 paid holidays, accrue 18 PTO days annually, are eligible for volunteer time off and 6 weeks of 100% paid parental leave (except in states that offer paid family leave). These benefits may not apply to employees covered by a collective bargaining agreement or those subject to other eligibility rules. #J-18808-Ljbffr Avantor

Vacancy posted more than 2 months ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal SAP Security Architect (S/4HANA & Government Systems). Be the first to apply!