Logo for Information Commissioner's Office

SAP Security GRC Analyst

Role overview

Qualifications

  • Experience of SAP GRC Access Control, including ARA, ARM, BRM and EAM
  • Experience designing and maintaining SAP roles and authorisations
  • Strong knowledge of SAP Security and Authorisation concepts
  • Degree-level qualification or equivalent professional experience

Responsibilities

  • Designing, building and maintaining SAP roles, authorisations and access governance controls
  • Analysing requirements and recommending secure solutions aligned with least privilege and Segregation of Duties principles
  • Performing SAP access risk analysis and investigating Segregation of Duties conflicts, critical access risks and privileged access requirements
  • Supporting and maintaining SAP GRC Access Control, including ARA, ARM, BRM and EAM

Key facts

Hard skills

Other skills

  • Governance
  • Analytical Skills
  • Problem Solving
  • Communication
  • Relationship Building

About the company

Information Commissioner's Office logo

Information Commissioner's Office

Government Administration

The ICO is the UK's independent authority set up to uphold information rights in the public interest, promoting openness by public bodies and data privacy for individuals. We rule on eligible complaints, give guidance to individuals and organisations, and take appropriate action when the law is broken.

Company details

IndustryGovernment Administration
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Circa £60k, salary dependant on skills and experience

Permanent

Full-time, with flexibility for part-time

Hybrid role, working from Lincoln or Huntingdon

Anglian Water offers a flexible approach; this role provides you the flexibility to work from home and from an Anglian Water office. Your base location will be in either our Lincoln or Huntingdon office.

Are you an experienced SAP Security professional with strong knowledge of SAP GRC, access governance and risk management?

We’re looking for an SAP Security GRC Analyst to join our Information Services team and play an important role in protecting Anglian Water’s business-critical SAP platforms.

You’ll bring specialist expertise across SAP Security, SAP GRC Access Control and access governance, helping us ensure access is designed, provisioned and maintained in line with cyber security policies, regulatory requirements, internal controls and business needs.

What you’ll be doing

Working closely with our Cyber Security team, Enterprise Architecture, SAP teams, Business Role Owners, Business Risk Owners and delivery partners, you’ll help ensure our SAP environments remain secure, controlled and compliant.

Your key responsibilities will include:

  • Designing, building and maintaining SAP roles, authorisations and access governance controls
  • Analysing requirements and recommending secure solutions aligned with least privilege and Segregation of Duties principles
  • Performing SAP access risk analysis and investigating Segregation of Duties conflicts, critical access risks and privileged access requirements
  • Supporting and maintaining SAP GRC Access Control, including ARA, ARM, BRM and EAM
  • Supporting the configuration of GRC workflows, routing rules, access risk rulesets and mitigating controls
  • Supporting SAP user lifecycle processes, including joiners, movers and leavers
  • Reviewing access requests, role maintenance, provisioning and periodic access reviews
  • Supporting internal and external audits and providing evidence of SAP Security and GRC control operation
  • Executing and monitoring SAP IT General Controls (ITGCs) and access governance controls
  • Producing risk, compliance and management information for stakeholders and governance forums
  • Identifying opportunities to improve and automate SAP Security and GRC processes, reporting and controls
  • Supporting SAP transformation initiatives and security-related projects.

What does it take to be successful?

You’ll have demonstrable experience in SAP Security and Authorisations within SAP S/4HANA environments, alongside a strong understanding of security governance, access controls and risk management.

We’re looking for someone with:

  • Experience of SAP GRC Access Control, including ARA, ARM, BRM and EAM
  • Experience designing and maintaining SAP roles and authorisations
  • Strong knowledge of SAP Security and Authorisation concepts
  • Experience analysing and managing Segregation of Duties and critical access risks
  • Experience configuring and maintaining SAP GRC workflows, rulesets and governance controls
  • Experience supporting SAP user lifecycle management
  • Experience supporting SAP audit and compliance activities
  • An understanding of SAP Security governance frameworks, internal controls and risk management principles
  • Experience supporting SAP projects, enhancements and change
  • Strong analytical and problem-solving skills
  • The ability to communicate complex security and risk concepts clearly to both technical and non-technical audiences
  • The ability to build effective relationships across business and technology teams
  • Degree-level qualification or equivalent professional experience.

It would be advantageous if you also have experience or knowledge of:

  • SAP Security and/or SAP GRC certifications
  • SAP ECC Security
  • SAP Fiori Security
  • SAP BTP and SAP Cloud Security
  • IT General Controls
  • Working within a regulated industry
  • Agile delivery methodologies
  • SAP S/4HANA functional processes
  • SAP identity integration with enterprise IAM platforms
  • ABAP authorisation checks
  • Producing management information, risk and governance reporting.

.

As a valued employee, you’ll be entitled to:

  • Full private healthcare with no excess
  • 26 days leave, rising with service + Bank Holidays, with the option to swap Christmas and Easter holidays for those celebrated by your religion
  • A flexible working culture
  • Competitive pension scheme – we double-match your contributions up to 6%
  • Bonus Scheme

Why Anglian Water?

This is an opportunity to use your SAP Security and GRC expertise in a role covering both day-to-day security operations and the continued development of our SAP Security, Access Governance and GRC capabilities. You’ll work with stakeholders across Cyber Security, Enterprise Architecture, SAP delivery, audit, transformation programmes and the wider business.  You’ll have the opportunity to improve security processes, strengthen governance, support automation and contribute to wider SAP transformation activities.


If you’re an SAP Security professional who enjoys solving complex access and risk challenges while improving how security and governance work in practice, we’d love to hear from you.

Closing date: 6th October 2026

#loveeverydrop

#LI-ZP1

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

GRC Analyst Related jobs

Other jobs at Information Commissioner's Office

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.