RAGHU KAGITA
Summary:
Mr.Raghu has over eight years of experience in SAP Security &
Authorizations. He is a Subject Matter Expert with solid working experience
and in-depth knowledge of SAP security administration and maintenance. Have
a lead experience working with a team of 6 people, architecting the role
design process and implementing CUA landscape at the client location.
Experienced in 5 SAP implementations/upgrades in various industries (hi-
tech, telecommunications, utilities, healthcare and services). Experience
in managing complex and long-term projects. SAP Skills include: design,
development and administration of user roles, authorizations and user
profiles, also managing the mass user/role maintenance using SAP provided
CATT/eCATT scripts. Maintaining SAP user accounts in production and non-
production systems. Experienced in analyzing the current configurations,
recommending and implementing necessary changes. Compliance with all
security standards, policies and audit guidelines by using SOD tools like
VIRSA and SAP GRC 5.3 access controller. Experience with backup management
of users and profiles. Installed and configured SAP R/3 components.
Experienced in developing JAQs and DCMs in compliance with the SOX act
certification. Implemented SAP R/3 Logical Security in compliance with
Sarbanes-Oxley (SOX) Sections 404 and 302. Experience in creating and
maintaining roles, worksets, pages in Enterprise Portal 5.5 and 6.0 SP2.
Involved in the day to day movement of Transport requests from Dev systems
to TST and PRD systems. Experience in different versions of SAP R/3 and its
sub modules like SD, PM, MM, FI/CO, RMCA, PP, WM, SAP Workflow, and other
SAP systems like BW, BI analysis authorization, SCM with APO, SRM, CRM with
ICWEB, XI/PI, Solution Manager and SAP HR Structural authorizations.
GRC/VIRSA Security (Sarbanes-Oxley) Summary:
. Experience with VIRSA, SAP GRC 5.3 Access controller component, a
SoD tool for continuously monitoring ERP applications, to warn both
potential and actual violations of internal controls.
. Experience in implementing/maintaining of SAP GRC Access Controller
and all its sub components Compliant User Provisioning (CUP),
Enterprise Role Management (ERM), Risk Analysis and Remediation
(RAR), and Super user Privilege Management (SPM).
. Developed JAQs and DCMs in compliance with the SOX act
certification.
. Implemented SAP R/3 Logical Security in compliance with Sarbanes-
Oxley (SOX) sections 404 and 302.
. Identified and analyzed the critical transactions that are involved
for resolving the Sarbanes Oxley act 404.
. Getting the requirements from the external auditors for identifying
the critical reports and streamlining the reports.
. Discussing with functional module experts to get the Segregation of
Duties matrix and making subsequent changes to the roles and users
based on the matrix.
. Identifying and classifying the reports to address the Delegation
of authority (DOA) and Segregation of Duties issues (SoD).
SAP R/3 Security Summary:
. Used SAP's Profile Generator (PG) to create, generate and assign
authorization profiles in PFCG.
. Installation/configuration/upgrade/maintenance of SAP R/3, BW
servers.
. Worked with user information system, creating and changing users
and assigning users to activity groups/roles using custom programs
or bulk uploading of users using CATT scripts.
. Generated and maintained authorizations and authorization profiles
based on existing activity groups, and mass maintenance of roles
using SAP eCATT scripts.
. Copying and Modifying SAP-Provided User Role Templates and also
created a set of custom user role templates which are specific to
the client requirements.
. Define & Implement SAP Security using Profile Generator for
individual job functions and modify workflow templates
. Performed ABAP trouble shooting and programming error
determination.
. Day to Day to Monitoring of SAP R/3 Systems using SM66, ST22 and
SM37 for failed batch jobs.
. Maintaining missing authorizations manually, from templates and
profiles/roles using PFCG.
. Troubleshooting the user authorization issues using SU53 and also
putting a through trace on the user ID using ST01 and analyzing the
trace file for finding the missing authorizations from the user
profiles and documenting the process for future purposes.
. Responsible for the implementing/maintaining of CUA in a 3 ties
landscape system with all the systems in the client landscape like
R/3, BW, CRM and SCM systems and integrating them into the front
end portal to use SSO for global login.
. Maintaining the CUA parameters from SCUM, and checking the SCUL
logs frequently for any IDOC that are waiting in Central system to
be processed and also trouble shoot the failed IDOCS and
reprocessing them manually.
. Responsible for unhooking and re hooking of CUA system with every
migration, release, and application of support packs and major
upgrades to SAP systems.
. Experience in major SAP upgrades to perform security role
remediation using SU25 to check the authorization/transaction
changes and maintaining the customer roles.
. Global activating or deactivating of authorization checks from
SU24.
. Worked extensively with SUIM reports for users last logon dates,
checking the history on user's access, role modification history,
users by the authorization group they are assigned to and more.
. Define and manage Operation Modes, CCMS monitors & Background Jobs
. Mass maintenance of users using SU01, SU10 and also generating the
user specific reports like, user history, last logon dates, and
profiles addition/deletion from their IDs from SUIM.
. Working with SQVI queries to generate custom reports based on the
requirements.
. Experience in HR business process and in the areas of Portal,
Employee Self Service (ESS), Manager Self Service (MSS), Benefits
Administration (BA), Enterprise Compensation Management (ECM),
Organization Management (OM), Personal Administration (PA) and
Personnel Development (PA-PD).
SAP CRM Security Summary:
. Worked on designing/configuring and developing security roles in CRM
4.0, CRM 5.0 and CRM2007 systems
. Implemented CRM 2007/CRM 2005 security using business transaction
types/Authorization Keys/Status Profiles/Business Partner
Authorizations etc
. Worked on designing CRM business roles by working with Process Team
and Controls Team
. Documentation of CRM business Roles and Simple Role structure which
dictates SAP Security Design document for Trade
. Maintained security roles for CRM call center management/ Service
order
. Enhanced CRM business roles which contain navigation bar definition by
process team.
. Experience in creating organizational structure in CRM system,
assigning the ABAP profiles to the organizational profiles.
. Creating business partners for the CRM WebUI users and assigning them
different positions in the organizational structure, so that they will
only be limited to the ABAP profiles and screens that are supposed to
get.
. Creating the portal aliases for the CRM systems, iviews for the ICWeb
connectivity from the backend system using SAP ITS.
. Worked in creating the portal roles for all the CRM transactions and
ICWeb agent for the end users to come from SSO portal to access the
backend SAP systems.
. Worked on upgrading the CRM 4.0 system to CRM 2007, analyzing all the
new transactions and authorizations that new system is bringing in and
making the necessary modifications to the roles where needed.
. Drive the identification of Roles in the new CRM 2007 UI roles and
building those roles in the most efficient and effective manner.
. Unhooking the CRM systems form CUA and assisting Basis team in locking
the end users while performing the CRM upgrading tasks and putting
back the CRM Systems back into CUA.
. Troubleshooting the issues with the upgrade, searching for the OSS
notes and opening SAP messages for the issues that need SAP attention.
. Working on Production support issues in resolving the ICWeb access for
the end users and making necessary changes.
SAP BW Security Summary:
. Worked on upgrading the BW environments from BW 3.x to SAP BI 7.0
. Experience in migrating the existing authorization concept in BW
3.x systems to BI analysis authorizations using the security tool
RSEC_MIGRATION.
. Maintaining the info object for authorization relevant
characteristics and attributes from RSD1.
. Worked with management of analysis authorizations using the newest
tool RSECADMIN.
. Authorizing the characteristic values, attribute values and
hierarchies using the newest analysis authorization in BI and
assigning them directly to the users and roles.
. Redesigning the role and authorization structure at the client
location to overcome the authorization failures occurred with the
migration to BI analysis authorization.
. Worked with the BI web templates to add them to the role menu and
also creating an iviews from the portal side to add the template to
the portal roles as well.
. Set up security by INFOAREA, INFOCUBE, ODS, PSA, INFOOBJECT, QUERY
and WORKBOOKS used by the users.
. Configured roles and authorization objects to secure reporting
users.
. Limiting the query access within the BEx Analyzer.
. Implemented InfoObject Security (field-level security) for
Reporting Users and also created custom reporting authorization
objects in BW 3.x systems.
. Securing the data presented in queries by hierarchy node.
. Maintaining authorizations for Hierarchies.
. Tracing the SAP-provided objects and custom reporting authorization
object to debug an authorization error.
. Building security for Administrative users using SAP provided
templates
. Involved in the implementation of structural authorizations for the
HR module
. Interacting with functional and technical consultants for problem
diagnosis.
Project: 1 ( Employer : Radiant Systems, Inc)
Duration: 11/009 - Present
Client: PEPSICO, Chicago.
Platform & Skills: ECC 6.0, R3 HR, BI 7.0, CRM 6.0, PI 7.0, CRM 2007,
XI/PI, Solution Manager 7.0, SRM 5.0 and Enterprise Portal 5.5 & 6.0 SP2.
Role: SAP Security Administrator
Duties & Responsibilities:
. Experience with VIRSA, SAP GRC 5.3 Access controller component, a
SoD tool for continuously monitoring ERP applications, to warn both
potential and actual violations of internal controls.
. Experience in implementing/maintaining of SAP GRC Access Controller
and all its sub components Compliant User Provisioning (CUP),
Enterprise Role Management (ERM), Risk Analysis and Remediation
(RAR), and Super user Privilege Management (SPM).
. Developed JAQs and DCMs in compliance with the SOX act
certification.
. Implemented SAP R/3 Logical Security in compliance with Sarbanes-
Oxley (SOX) sections 404 and 302.
. Identified and analyzed the critical transactions that are involved
for resolving the Sarbanes Oxley act 404.
. Getting the requirements from the external auditors for identifying
the critical reports and streamlining the reports.
. Experience with role base and userID base firefighter setup in
VIRSA Firefighter and GRC SPM
. Working with Functional and process teams in identifying the
functions and creating the risks in SAP GRC using Rule Architect
(RAR)
. Configuring the CUP and the workflow for userID requests and
integrating the backend SAP systems for completely automating the
userID creation process in production systems
. Discussing with functional module experts to get the Segregation of
Duties matrix and making subsequent changes to the roles and users
based on the matrix.
. Identifying and classifying the reports to address the Delegation
of authority (DOA) and Segregation of Duties issues (SoD).
. In depth knowledge of BI 7.1 authorization tools like RSECADMIN for
creating and maintaining the analysis authorizations and directly
assigning them to the users, groups and roles.
. Authorization monitoring by checking authorizations by running the
query as a specific user from RSECADMIN tool, also testing the
reports and analyzing authorization check logs.
. Extensive knowledge in analyzing the issues, and working on
prototyping the issue to come up with a solution that will be
acceptable to both Business and the controls team.
. Introduced the concept of enabler roles in BI system for the
business users who are working on different plant locations with
the base role having the reporting authorization and the enabler
roles are restricted by different plant values
. Automated the process of getting the hierarchy nodes from CRM
system and generating the analysis authorization and assigning it
directly to the users in production by the control-M job that is
run on a daily basis. This reduces the manual maintenance of
hierarchies which will be changing on a daily basis.
. Maintaining the views, roles and work sets in Enterprise portals
and responsible for creation and modification of users there.
. Involved in Enterprise portal upgrade from EP 5.5 to EP 6.0 SP2.
. Worked with PCD inspector tool to replicate all the iviews, roles
and work sets for configuring the frontend portal to different
clients in backend SAP systems.
. Defined a strategic design for maintaining the portal iviews and
using work sets that are common to every role and assigning them as
delta links in portal, also responsible for client configuration in
the portal side to different clients in the backend SAP Systems in
DEV and QA.
. Configuring the UME in portal and authenticating the portal users
using LDAP.
. Responsible for maintaining SRM security authorizations and
exporting the authorization into flat file to upload into portal.
Project: 2 ( Employer : Radiant Systems, Inc)
Duration: 05/06 - 11/09
Client: AT&T, Morristown NJ.
Platform & Skills: R/3 Enterprise 4.7 EE, ECC 6.0, R3 HR, BW 3.0 B, BW 3.5
and BI, CRM 4.0 and
CRM 2007, XI/PI, Solution Manager, SRM and Enterprise Portal 5.5 & 6.0 SP2.
Role: SAP Security Administrator
Duties & Responsibilities:
. Configured the CUA system to integrate all the SAP environments,
and responsible for the designing of CUA structure as which one
should be the Central system and how many CUA's do we need (like
one for DEV, one for PFX to separate it from PRD, and one for PRD.)
. Implemented CRM 2007/CRM 2005 security using business transaction
types/Authorization Keys/Status Profiles/Business Partner
Authorizations etc
. Worked on designing CRM business roles by working with Process Team
and Controls Team
. Documentation of CRM business Roles and Simple Role structure which
dictates SAP Security Design document for Trade
. Maintained security roles for CRM call center management/ Service
order
. Enhanced CRM business roles which contain navigation bar definition
by process team.
. Worked on creating the CUA communication users, defining and
assigning the logical systems, creating the RFC destinations and
assigning them to the logical systems and finally creating the
distribution model for CUA.
. Responsible for the maintenance of CUA system and its parameters,
clearing the SCUL logs and unhooking and re hooking the CUA child
systems with the migrations and upgrades to SAP systems
. Searching and applying of OSS notes to fix SUIM, SU10 to fix CUA
related issues.
. Daily maintenance of production users using custom program to
create/modify users profile and update their roles.
. Experience in creating organizational structure in CRM system,
assigning the ABAP profiles to the organizational profiles.
. Creating business partners for the CRM WebUI users and assigning
them different positions in the organizational structure, so that
they will only be limited to the ABAP profiles and screens that are
supposed to get.
. Creating the portal aliases for the CRM systems, iviews for the
ICWeb connectivity from the backend system using SAP ITS.
. Worked in creating the portal roles for all the CRM transactions
and ICWeb agent for the end users to come from SSO portal to access
the backend SAP systems.
. Worked on upgrading the CRM 4.0 system to CRM 2007, analyzing all
the new transactions and authorizations that new system is bringing
in and making the necessary modifications to the roles where
needed.
. Drive the identification of Roles in the new CRM 2007 UI roles and
building those roles in the most efficient and effective manner.
. Unhooking the CRM systems form CUA and assisting Basis team in
locking the end users while performing the CRM upgrading tasks and
putting back the CRM Systems back into CUA.
. Troubleshooting the issues with the upgrade, searching for the OSS
notes and opening SAP messages for the issues that need SAP
attention.
. Working on Production support issues in resolving the ICWeb access
for the end users and making necessary changes.
. Worked with the ABAP team for creating the technical requirements
for the ZUSER program and also responsible for testing the program
and enhancements to the program.
. Provided the security support for the data and account migration
into the CFM system from legacy systems over the weekends.
. Mass lockout of users from mass maintenance transaction SU10, and
also checking the user login information from AL08, knocking off
the users who already logged into the system during the migration
weekend and support for the migrating IT users and their access
issues.
. Performing the pre and post migration installation tasks for
Security.
. Responsible for the security tasks in the upgrade of BW 3.5 to BI.
. Worked extensively in migrating the old authorization object
concept in BW 3.5 to the newest analysis authorizations introduced
by BI 7.0
. In depth knowledge of BI 7 authorization tools like RSECADMIN for
creating and maintaining the analysis authorizations and directly
assigning them to the users, groups and roles.
. Authorization monitoring by checking authorizations by running the
query as a specific user from RSECADMIN tool, also testing the
reports and analyzing authorization check logs.
. Managed the security team of 3 people and responsible for the
security upgrade of BW, R3 and CRM systems.
. Upgraded R3 system from 4.7 EE to ECC 6.0 which involved
synchronization of roles from SU25 and critically analyzed the new
authorizations that have been brought in by the upgrade.
. experience as a SAP HR structural authorization consultant,
specialized in HR business process and in the areas of Portal,
Employee Self Service (ESS), Manager Self Service (MSS), Benefits
Administration (BA), Enterprise Compensation Management (ECM),
Organization Management (OM), Personal Administration (PA) and
Personnel Development (PA-PD)
. Worked with the IT partners and business leads to maintain the new
authorization in updating the roles and making aware of the
business leads about the new functionality from the upgrade.
. Implemented SAP GRC access controller and all its components to for
continuously monitoring ERP applications, to warn both potential
and actual violations of internal controls.
. Configured Firefighter access and IDs and defined control for the
owner to assign the Firefighter access to the users and setup to
email the log to the owners.
. Generated different reports for internal and external auditors and
successfully completed a clean audit report.
. Maintaining the CFM system with 15,000 users and 5000 active users
anytime during the active business day.
. Maintaining the views, roles and work sets in Enterprise portals
and responsible for creation and modification of users there.
. Involved in Enterprise portal upgrade from EP 5.5 to EP 6.0 SP2.
. Worked with PCD inspector tool to replicate all the iviews, roles
and work sets for configuring the frontend portal to different
clients in backend SAP systems.
. Defined a strategic design for maintaining the portal iviews and
using work sets that are common to every role and assigning them as
delta links in portal, also responsible for client configuration in
the portal side to different clients in the backend SAP Systems in
DEV and QA.
. Configuring the UME in portal and authenticating the portal users
using LDAP.
. Responsible for maintaining SRM security authorizations and
exporting the authorization into flat file to upload into portal.
Project: 3 (Employer : Delphi Systems, Inc)
Duration: 03/05 - 04/06
Client: Deluxe Corp, St. Paul MN.
Platform & Skills: R/3 Enterprise, SAP R/3 4.6C, BW 3.0B and BW 3.5, CRM
4.0, Enterprise Portal 5.5 & 6.0
Role: SAP Security Administrator
Duties & Responsibilities:
. User Administration and Password management
. Setting up Transport Layers and Transport Routes
. TMS Configuration and Quality Assurance
. Transports using TMS
. Working with CTS Tools viz., Workbench, Customizing and Transport
Organizer
. SAP DBA functions
. Performing Transports and Controlling imports using tp
. Working with ABAP workbench tools - ABAP Editor, Object Browser,
function builder etc.
. Closely worked with the Corporate Internal Audit (CIA) team to
assess the adequacy of the company's internal controls
. Involved in Developing JAQs and DCMs for compliance with SOX act
certification.
. Implemented SAP R/3 Logical Security in compliance with Sarbanes-
Oxley (SOX) Sections 404 and 302.
. Installed BizRights for continuously monitoring our ERP
applications, to warn both potential and actual violations of
internal controls.
. Involved in creation of Rules, Rulebooks, Templates for VIRSA which
enables rapid customization to reflect risks specific to our
organization.
. Continuous monitoring of user roles, profiles, and access to
sensitive transactions.
. SAP User Administration of 5000 plus users
. Member of a team of 6 S&A team members and 2 Print Support members
. Creating and Assigning Profiles to Users using Profile Generator
. Involved in upgrading profiles used in 4.5 environment to 4.7 Roles
. Converting Manual Profiles to Profile Generator Profiles
. Trouble-shooting authorization problems using Repository
Information System and tracing authorizations using SU53 and ST01.
. Working with CTS Tools viz., Workbench, Customizing and Transport
Organizer
. Performing Transports and Controlling imports using tp
. Creating and maintaining of roles, worksets, and pages in
Enterprise Portal 5.5
. Assigning roles to the users for the top level navigation, detailed
level navigation
. Novell LDAP synchronization, NT authentication, IIS authentication,
and SSO
Project: 4 ( Employer : Insoft Solutions, Inc)
Duration: 03/03 - 02/05
Client: Bristol Myers Squibb Co., Princeton NJ.
Platform & Skills: SAP R/3 4.6C, SAP HR, SAP SCM/APO 4.0, SAP R/3 4.5B, and
BW 3.0B.
Role: SAP Security Coordinator
Duties & Responsibilities:
. Identified and analyzed the critical transactions that are involved
for resolving the Sarbanes Oxley act 404.
. Getting the requirements from the external auditors for identifying
the critical reports and streamlining the reports.
. Monitoring the customized programs and tables on periodic basis.
. Classifying the reports to be analyzed based upon the criticality
and deciding the frequency to run reports.
. Organizing the reports in a structured format and uploaded into the
shared drive, which can be accessed easily based upon naming
conventions.
. Involved in analyzing the requests coming to the Security mailbox,
validating the users, and initializing the change management
tickets.
. Responsible for customizing and maintaining of SAP APO 4.0 system.
. Analyzed the SAP provided standard iPPE user profiles defined in
APO system and copying them to the custom roles and modifying the
roles/profiles as per the requirements.
. Defined the model definitions between the objects that are
displayed in the navigation area in APO system
. Worked on the reports for the profile in the iPPE Workbench
professional which is defined in the APO system.
. Also worked on integration of SAP APO and SAP R/3 system.
. Involved in the BW foundation project, developing the security
strategy, implementing the naming conventions.
. Handling the security request for four landscapes of the
Organization. (Enterprise R/3, HR/Payroll System, Corporate BW/SEM
system, APO system).
. Monitoring the Emergency access - temporary access to ABAP
Development and debug, documenting the process.
. Monitoring the crucial transactions and tables that should be
accessed by only Basis and Security Administration.
. Monitoring the users who are inactive for 90 days in the system and
initiating the process to lock the users in the system and eventual
deletion of the users after 120 days.
. Daily monitoring of the super user ID's (SAP*, DDIC, ITSECURITY).
. Communicating with the Security Coordinators, Line of Business
(LOB) people for organizing and analyzing the security requests and
documenting the details for future reference.
. Frequent monitoring of users having access to financial related
data.
. Maintaining the USR40 (password table) table and streamlining the
guidelines for the password restrictions.
. Worked in configuration HR structural authorizations and possesses
a thorough understanding of all aspects of the Human Resources
business process, comprising the life cycle of an employee
including recruiting, hiring, employee maintenance, payroll and
benefits.
. Created Functional Specs, Conceptual design and detail design
documents for ESS/MSS based on the business requirements.
. Created various custom iviews for both ESS and MSS
. Involved in the day to day movement of SAP transport requests from
development systems to quality and subsequently to preproduction
and Production systems.
. Well acquainted with Remedy software for Change management and Help
Desk Issues.
. Configuring/maintaining transport system and coordinating with
various ongoing projects to see that their Config/object changes
made it to the PRD system without any overlaps.
. Documented Daily, Weekly, Monthly Remedy tickets processed based
on different projects and part of 24/7 On-call team.
Project: 5 ( Employer : Insoft Solutions, Inc) Duration:
05/02 - 02/03
Client: PSE&G, Newark NJ.
Platform & Skills: SAP R/3 3.0F, 4.0B, HP UX 11.0, Oracle 8.0.6
Scope: Installed SAP R/3 3.0F, upgrade to 4.0B and SAP BW software.
Role: Basis/Security consultant
Duties & Responsibilities:
. SAP Installation of Release 3.1G
. Installation of SAPGUI/SAP help
. Performed installations, Setup Development projects, Developed
Client system strategy document, helped procuring hardware (servers
and disk storage) for SAP implementation
. Configure Change and Transport System(CTS) Transport Management
Systems (TMS) & Change Transport Organizer (CTO)
. Setting up the TP program.
. Determine the Transport Strategy, QA approval procedure
. performing and monitoring transports
. User Administration using Profile Generator
. OSS notes download and solving end user problems
. Client copy functions and Client Maintenance.
. Profile Maintenance from CCMS
. Designing strategy for backup and recovery of database.
. User Distribution: Logon Load Balancing and the SAP logon Utility
. Involved in the creation of roles based on BW Reporting
Functionality with a very high granularity.
. Implemented Hierarchy Security for BW Queries in multiple ways.
. Developed custom Authorization Objects for queries developed by the
users.
. Worked with both the authorization classes in BW
. Set up security by INFOAREA, INFOCUBE, ODS, PSA, INFOOBJECT, QUERY
and WORKBOOKS
. Implemented Central User Administration (CUA) which consists of 3
landscapes
. Involved in the implementation of structural authorizations for the
HR module
. Creating and Assigning Profiles to Users using Profile Generator
. Formulation of Transport Strategy in the CTS
. Converting Manual Profiles to Profile Generator Profiles
Education:
M.S in Electrical Engineering, University of Nebraska, Lincoln,
Nebraska.
B.Tech in Electrical Engineering, JNT University, Hyderabad, India.