Post Job Free
Sign in

Sap Security

Location:
8540
Posted:
September 16, 2010

Contact this candidate

Resume:

RAGHU KAGITA

609-***-****

Summary:

Mr.Raghu has over eight years of experience in SAP Security &

Authorizations. He is a Subject Matter Expert with solid working experience

and in-depth knowledge of SAP security administration and maintenance. Have

a lead experience working with a team of 6 people, architecting the role

design process and implementing CUA landscape at the client location.

Experienced in 5 SAP implementations/upgrades in various industries (hi-

tech, telecommunications, utilities, healthcare and services). Experience

in managing complex and long-term projects. SAP Skills include: design,

development and administration of user roles, authorizations and user

profiles, also managing the mass user/role maintenance using SAP provided

CATT/eCATT scripts. Maintaining SAP user accounts in production and non-

production systems. Experienced in analyzing the current configurations,

recommending and implementing necessary changes. Compliance with all

security standards, policies and audit guidelines by using SOD tools like

VIRSA and SAP GRC 5.3 access controller. Experience with backup management

of users and profiles. Installed and configured SAP R/3 components.

Experienced in developing JAQs and DCMs in compliance with the SOX act

certification. Implemented SAP R/3 Logical Security in compliance with

Sarbanes-Oxley (SOX) Sections 404 and 302. Experience in creating and

maintaining roles, worksets, pages in Enterprise Portal 5.5 and 6.0 SP2.

Involved in the day to day movement of Transport requests from Dev systems

to TST and PRD systems. Experience in different versions of SAP R/3 and its

sub modules like SD, PM, MM, FI/CO, RMCA, PP, WM, SAP Workflow, and other

SAP systems like BW, BI analysis authorization, SCM with APO, SRM, CRM with

ICWEB, XI/PI, Solution Manager and SAP HR Structural authorizations.

GRC/VIRSA Security (Sarbanes-Oxley) Summary:

. Experience with VIRSA, SAP GRC 5.3 Access controller component, a

SoD tool for continuously monitoring ERP applications, to warn both

potential and actual violations of internal controls.

. Experience in implementing/maintaining of SAP GRC Access Controller

and all its sub components Compliant User Provisioning (CUP),

Enterprise Role Management (ERM), Risk Analysis and Remediation

(RAR), and Super user Privilege Management (SPM).

. Developed JAQs and DCMs in compliance with the SOX act

certification.

. Implemented SAP R/3 Logical Security in compliance with Sarbanes-

Oxley (SOX) sections 404 and 302.

. Identified and analyzed the critical transactions that are involved

for resolving the Sarbanes Oxley act 404.

. Getting the requirements from the external auditors for identifying

the critical reports and streamlining the reports.

. Discussing with functional module experts to get the Segregation of

Duties matrix and making subsequent changes to the roles and users

based on the matrix.

. Identifying and classifying the reports to address the Delegation

of authority (DOA) and Segregation of Duties issues (SoD).

SAP R/3 Security Summary:

. Used SAP's Profile Generator (PG) to create, generate and assign

authorization profiles in PFCG.

. Installation/configuration/upgrade/maintenance of SAP R/3, BW

servers.

. Worked with user information system, creating and changing users

and assigning users to activity groups/roles using custom programs

or bulk uploading of users using CATT scripts.

. Generated and maintained authorizations and authorization profiles

based on existing activity groups, and mass maintenance of roles

using SAP eCATT scripts.

. Copying and Modifying SAP-Provided User Role Templates and also

created a set of custom user role templates which are specific to

the client requirements.

. Define & Implement SAP Security using Profile Generator for

individual job functions and modify workflow templates

. Performed ABAP trouble shooting and programming error

determination.

. Day to Day to Monitoring of SAP R/3 Systems using SM66, ST22 and

SM37 for failed batch jobs.

. Maintaining missing authorizations manually, from templates and

profiles/roles using PFCG.

. Troubleshooting the user authorization issues using SU53 and also

putting a through trace on the user ID using ST01 and analyzing the

trace file for finding the missing authorizations from the user

profiles and documenting the process for future purposes.

. Responsible for the implementing/maintaining of CUA in a 3 ties

landscape system with all the systems in the client landscape like

R/3, BW, CRM and SCM systems and integrating them into the front

end portal to use SSO for global login.

. Maintaining the CUA parameters from SCUM, and checking the SCUL

logs frequently for any IDOC that are waiting in Central system to

be processed and also trouble shoot the failed IDOCS and

reprocessing them manually.

. Responsible for unhooking and re hooking of CUA system with every

migration, release, and application of support packs and major

upgrades to SAP systems.

. Experience in major SAP upgrades to perform security role

remediation using SU25 to check the authorization/transaction

changes and maintaining the customer roles.

. Global activating or deactivating of authorization checks from

SU24.

. Worked extensively with SUIM reports for users last logon dates,

checking the history on user's access, role modification history,

users by the authorization group they are assigned to and more.

. Define and manage Operation Modes, CCMS monitors & Background Jobs

. Mass maintenance of users using SU01, SU10 and also generating the

user specific reports like, user history, last logon dates, and

profiles addition/deletion from their IDs from SUIM.

. Working with SQVI queries to generate custom reports based on the

requirements.

. Experience in HR business process and in the areas of Portal,

Employee Self Service (ESS), Manager Self Service (MSS), Benefits

Administration (BA), Enterprise Compensation Management (ECM),

Organization Management (OM), Personal Administration (PA) and

Personnel Development (PA-PD).

SAP CRM Security Summary:

. Worked on designing/configuring and developing security roles in CRM

4.0, CRM 5.0 and CRM2007 systems

. Implemented CRM 2007/CRM 2005 security using business transaction

types/Authorization Keys/Status Profiles/Business Partner

Authorizations etc

. Worked on designing CRM business roles by working with Process Team

and Controls Team

. Documentation of CRM business Roles and Simple Role structure which

dictates SAP Security Design document for Trade

. Maintained security roles for CRM call center management/ Service

order

. Enhanced CRM business roles which contain navigation bar definition by

process team.

. Experience in creating organizational structure in CRM system,

assigning the ABAP profiles to the organizational profiles.

. Creating business partners for the CRM WebUI users and assigning them

different positions in the organizational structure, so that they will

only be limited to the ABAP profiles and screens that are supposed to

get.

. Creating the portal aliases for the CRM systems, iviews for the ICWeb

connectivity from the backend system using SAP ITS.

. Worked in creating the portal roles for all the CRM transactions and

ICWeb agent for the end users to come from SSO portal to access the

backend SAP systems.

. Worked on upgrading the CRM 4.0 system to CRM 2007, analyzing all the

new transactions and authorizations that new system is bringing in and

making the necessary modifications to the roles where needed.

. Drive the identification of Roles in the new CRM 2007 UI roles and

building those roles in the most efficient and effective manner.

. Unhooking the CRM systems form CUA and assisting Basis team in locking

the end users while performing the CRM upgrading tasks and putting

back the CRM Systems back into CUA.

. Troubleshooting the issues with the upgrade, searching for the OSS

notes and opening SAP messages for the issues that need SAP attention.

. Working on Production support issues in resolving the ICWeb access for

the end users and making necessary changes.

SAP BW Security Summary:

. Worked on upgrading the BW environments from BW 3.x to SAP BI 7.0

. Experience in migrating the existing authorization concept in BW

3.x systems to BI analysis authorizations using the security tool

RSEC_MIGRATION.

. Maintaining the info object for authorization relevant

characteristics and attributes from RSD1.

. Worked with management of analysis authorizations using the newest

tool RSECADMIN.

. Authorizing the characteristic values, attribute values and

hierarchies using the newest analysis authorization in BI and

assigning them directly to the users and roles.

. Redesigning the role and authorization structure at the client

location to overcome the authorization failures occurred with the

migration to BI analysis authorization.

. Worked with the BI web templates to add them to the role menu and

also creating an iviews from the portal side to add the template to

the portal roles as well.

. Set up security by INFOAREA, INFOCUBE, ODS, PSA, INFOOBJECT, QUERY

and WORKBOOKS used by the users.

. Configured roles and authorization objects to secure reporting

users.

. Limiting the query access within the BEx Analyzer.

. Implemented InfoObject Security (field-level security) for

Reporting Users and also created custom reporting authorization

objects in BW 3.x systems.

. Securing the data presented in queries by hierarchy node.

. Maintaining authorizations for Hierarchies.

. Tracing the SAP-provided objects and custom reporting authorization

object to debug an authorization error.

. Building security for Administrative users using SAP provided

templates

. Involved in the implementation of structural authorizations for the

HR module

. Interacting with functional and technical consultants for problem

diagnosis.

Project: 1 ( Employer : Radiant Systems, Inc)

Duration: 11/009 - Present

Client: PEPSICO, Chicago.

Platform & Skills: ECC 6.0, R3 HR, BI 7.0, CRM 6.0, PI 7.0, CRM 2007,

XI/PI, Solution Manager 7.0, SRM 5.0 and Enterprise Portal 5.5 & 6.0 SP2.

Role: SAP Security Administrator

Duties & Responsibilities:

. Experience with VIRSA, SAP GRC 5.3 Access controller component, a

SoD tool for continuously monitoring ERP applications, to warn both

potential and actual violations of internal controls.

. Experience in implementing/maintaining of SAP GRC Access Controller

and all its sub components Compliant User Provisioning (CUP),

Enterprise Role Management (ERM), Risk Analysis and Remediation

(RAR), and Super user Privilege Management (SPM).

. Developed JAQs and DCMs in compliance with the SOX act

certification.

. Implemented SAP R/3 Logical Security in compliance with Sarbanes-

Oxley (SOX) sections 404 and 302.

. Identified and analyzed the critical transactions that are involved

for resolving the Sarbanes Oxley act 404.

. Getting the requirements from the external auditors for identifying

the critical reports and streamlining the reports.

. Experience with role base and userID base firefighter setup in

VIRSA Firefighter and GRC SPM

. Working with Functional and process teams in identifying the

functions and creating the risks in SAP GRC using Rule Architect

(RAR)

. Configuring the CUP and the workflow for userID requests and

integrating the backend SAP systems for completely automating the

userID creation process in production systems

. Discussing with functional module experts to get the Segregation of

Duties matrix and making subsequent changes to the roles and users

based on the matrix.

. Identifying and classifying the reports to address the Delegation

of authority (DOA) and Segregation of Duties issues (SoD).

. In depth knowledge of BI 7.1 authorization tools like RSECADMIN for

creating and maintaining the analysis authorizations and directly

assigning them to the users, groups and roles.

. Authorization monitoring by checking authorizations by running the

query as a specific user from RSECADMIN tool, also testing the

reports and analyzing authorization check logs.

. Extensive knowledge in analyzing the issues, and working on

prototyping the issue to come up with a solution that will be

acceptable to both Business and the controls team.

. Introduced the concept of enabler roles in BI system for the

business users who are working on different plant locations with

the base role having the reporting authorization and the enabler

roles are restricted by different plant values

. Automated the process of getting the hierarchy nodes from CRM

system and generating the analysis authorization and assigning it

directly to the users in production by the control-M job that is

run on a daily basis. This reduces the manual maintenance of

hierarchies which will be changing on a daily basis.

. Maintaining the views, roles and work sets in Enterprise portals

and responsible for creation and modification of users there.

. Involved in Enterprise portal upgrade from EP 5.5 to EP 6.0 SP2.

. Worked with PCD inspector tool to replicate all the iviews, roles

and work sets for configuring the frontend portal to different

clients in backend SAP systems.

. Defined a strategic design for maintaining the portal iviews and

using work sets that are common to every role and assigning them as

delta links in portal, also responsible for client configuration in

the portal side to different clients in the backend SAP Systems in

DEV and QA.

. Configuring the UME in portal and authenticating the portal users

using LDAP.

. Responsible for maintaining SRM security authorizations and

exporting the authorization into flat file to upload into portal.

Project: 2 ( Employer : Radiant Systems, Inc)

Duration: 05/06 - 11/09

Client: AT&T, Morristown NJ.

Platform & Skills: R/3 Enterprise 4.7 EE, ECC 6.0, R3 HR, BW 3.0 B, BW 3.5

and BI, CRM 4.0 and

CRM 2007, XI/PI, Solution Manager, SRM and Enterprise Portal 5.5 & 6.0 SP2.

Role: SAP Security Administrator

Duties & Responsibilities:

. Configured the CUA system to integrate all the SAP environments,

and responsible for the designing of CUA structure as which one

should be the Central system and how many CUA's do we need (like

one for DEV, one for PFX to separate it from PRD, and one for PRD.)

. Implemented CRM 2007/CRM 2005 security using business transaction

types/Authorization Keys/Status Profiles/Business Partner

Authorizations etc

. Worked on designing CRM business roles by working with Process Team

and Controls Team

. Documentation of CRM business Roles and Simple Role structure which

dictates SAP Security Design document for Trade

. Maintained security roles for CRM call center management/ Service

order

. Enhanced CRM business roles which contain navigation bar definition

by process team.

. Worked on creating the CUA communication users, defining and

assigning the logical systems, creating the RFC destinations and

assigning them to the logical systems and finally creating the

distribution model for CUA.

. Responsible for the maintenance of CUA system and its parameters,

clearing the SCUL logs and unhooking and re hooking the CUA child

systems with the migrations and upgrades to SAP systems

. Searching and applying of OSS notes to fix SUIM, SU10 to fix CUA

related issues.

. Daily maintenance of production users using custom program to

create/modify users profile and update their roles.

. Experience in creating organizational structure in CRM system,

assigning the ABAP profiles to the organizational profiles.

. Creating business partners for the CRM WebUI users and assigning

them different positions in the organizational structure, so that

they will only be limited to the ABAP profiles and screens that are

supposed to get.

. Creating the portal aliases for the CRM systems, iviews for the

ICWeb connectivity from the backend system using SAP ITS.

. Worked in creating the portal roles for all the CRM transactions

and ICWeb agent for the end users to come from SSO portal to access

the backend SAP systems.

. Worked on upgrading the CRM 4.0 system to CRM 2007, analyzing all

the new transactions and authorizations that new system is bringing

in and making the necessary modifications to the roles where

needed.

. Drive the identification of Roles in the new CRM 2007 UI roles and

building those roles in the most efficient and effective manner.

. Unhooking the CRM systems form CUA and assisting Basis team in

locking the end users while performing the CRM upgrading tasks and

putting back the CRM Systems back into CUA.

. Troubleshooting the issues with the upgrade, searching for the OSS

notes and opening SAP messages for the issues that need SAP

attention.

. Working on Production support issues in resolving the ICWeb access

for the end users and making necessary changes.

. Worked with the ABAP team for creating the technical requirements

for the ZUSER program and also responsible for testing the program

and enhancements to the program.

. Provided the security support for the data and account migration

into the CFM system from legacy systems over the weekends.

. Mass lockout of users from mass maintenance transaction SU10, and

also checking the user login information from AL08, knocking off

the users who already logged into the system during the migration

weekend and support for the migrating IT users and their access

issues.

. Performing the pre and post migration installation tasks for

Security.

. Responsible for the security tasks in the upgrade of BW 3.5 to BI.

. Worked extensively in migrating the old authorization object

concept in BW 3.5 to the newest analysis authorizations introduced

by BI 7.0

. In depth knowledge of BI 7 authorization tools like RSECADMIN for

creating and maintaining the analysis authorizations and directly

assigning them to the users, groups and roles.

. Authorization monitoring by checking authorizations by running the

query as a specific user from RSECADMIN tool, also testing the

reports and analyzing authorization check logs.

. Managed the security team of 3 people and responsible for the

security upgrade of BW, R3 and CRM systems.

. Upgraded R3 system from 4.7 EE to ECC 6.0 which involved

synchronization of roles from SU25 and critically analyzed the new

authorizations that have been brought in by the upgrade.

. experience as a SAP HR structural authorization consultant,

specialized in HR business process and in the areas of Portal,

Employee Self Service (ESS), Manager Self Service (MSS), Benefits

Administration (BA), Enterprise Compensation Management (ECM),

Organization Management (OM), Personal Administration (PA) and

Personnel Development (PA-PD)

. Worked with the IT partners and business leads to maintain the new

authorization in updating the roles and making aware of the

business leads about the new functionality from the upgrade.

. Implemented SAP GRC access controller and all its components to for

continuously monitoring ERP applications, to warn both potential

and actual violations of internal controls.

. Configured Firefighter access and IDs and defined control for the

owner to assign the Firefighter access to the users and setup to

email the log to the owners.

. Generated different reports for internal and external auditors and

successfully completed a clean audit report.

. Maintaining the CFM system with 15,000 users and 5000 active users

anytime during the active business day.

. Maintaining the views, roles and work sets in Enterprise portals

and responsible for creation and modification of users there.

. Involved in Enterprise portal upgrade from EP 5.5 to EP 6.0 SP2.

. Worked with PCD inspector tool to replicate all the iviews, roles

and work sets for configuring the frontend portal to different

clients in backend SAP systems.

. Defined a strategic design for maintaining the portal iviews and

using work sets that are common to every role and assigning them as

delta links in portal, also responsible for client configuration in

the portal side to different clients in the backend SAP Systems in

DEV and QA.

. Configuring the UME in portal and authenticating the portal users

using LDAP.

. Responsible for maintaining SRM security authorizations and

exporting the authorization into flat file to upload into portal.

Project: 3 (Employer : Delphi Systems, Inc)

Duration: 03/05 - 04/06

Client: Deluxe Corp, St. Paul MN.

Platform & Skills: R/3 Enterprise, SAP R/3 4.6C, BW 3.0B and BW 3.5, CRM

4.0, Enterprise Portal 5.5 & 6.0

Role: SAP Security Administrator

Duties & Responsibilities:

. User Administration and Password management

. Setting up Transport Layers and Transport Routes

. TMS Configuration and Quality Assurance

. Transports using TMS

. Working with CTS Tools viz., Workbench, Customizing and Transport

Organizer

. SAP DBA functions

. Performing Transports and Controlling imports using tp

. Working with ABAP workbench tools - ABAP Editor, Object Browser,

function builder etc.

. Closely worked with the Corporate Internal Audit (CIA) team to

assess the adequacy of the company's internal controls

. Involved in Developing JAQs and DCMs for compliance with SOX act

certification.

. Implemented SAP R/3 Logical Security in compliance with Sarbanes-

Oxley (SOX) Sections 404 and 302.

. Installed BizRights for continuously monitoring our ERP

applications, to warn both potential and actual violations of

internal controls.

. Involved in creation of Rules, Rulebooks, Templates for VIRSA which

enables rapid customization to reflect risks specific to our

organization.

. Continuous monitoring of user roles, profiles, and access to

sensitive transactions.

. SAP User Administration of 5000 plus users

. Member of a team of 6 S&A team members and 2 Print Support members

. Creating and Assigning Profiles to Users using Profile Generator

. Involved in upgrading profiles used in 4.5 environment to 4.7 Roles

. Converting Manual Profiles to Profile Generator Profiles

. Trouble-shooting authorization problems using Repository

Information System and tracing authorizations using SU53 and ST01.

. Working with CTS Tools viz., Workbench, Customizing and Transport

Organizer

. Performing Transports and Controlling imports using tp

. Creating and maintaining of roles, worksets, and pages in

Enterprise Portal 5.5

. Assigning roles to the users for the top level navigation, detailed

level navigation

. Novell LDAP synchronization, NT authentication, IIS authentication,

and SSO

Project: 4 ( Employer : Insoft Solutions, Inc)

Duration: 03/03 - 02/05

Client: Bristol Myers Squibb Co., Princeton NJ.

Platform & Skills: SAP R/3 4.6C, SAP HR, SAP SCM/APO 4.0, SAP R/3 4.5B, and

BW 3.0B.

Role: SAP Security Coordinator

Duties & Responsibilities:

. Identified and analyzed the critical transactions that are involved

for resolving the Sarbanes Oxley act 404.

. Getting the requirements from the external auditors for identifying

the critical reports and streamlining the reports.

. Monitoring the customized programs and tables on periodic basis.

. Classifying the reports to be analyzed based upon the criticality

and deciding the frequency to run reports.

. Organizing the reports in a structured format and uploaded into the

shared drive, which can be accessed easily based upon naming

conventions.

. Involved in analyzing the requests coming to the Security mailbox,

validating the users, and initializing the change management

tickets.

. Responsible for customizing and maintaining of SAP APO 4.0 system.

. Analyzed the SAP provided standard iPPE user profiles defined in

APO system and copying them to the custom roles and modifying the

roles/profiles as per the requirements.

. Defined the model definitions between the objects that are

displayed in the navigation area in APO system

. Worked on the reports for the profile in the iPPE Workbench

professional which is defined in the APO system.

. Also worked on integration of SAP APO and SAP R/3 system.

. Involved in the BW foundation project, developing the security

strategy, implementing the naming conventions.

. Handling the security request for four landscapes of the

Organization. (Enterprise R/3, HR/Payroll System, Corporate BW/SEM

system, APO system).

. Monitoring the Emergency access - temporary access to ABAP

Development and debug, documenting the process.

. Monitoring the crucial transactions and tables that should be

accessed by only Basis and Security Administration.

. Monitoring the users who are inactive for 90 days in the system and

initiating the process to lock the users in the system and eventual

deletion of the users after 120 days.

. Daily monitoring of the super user ID's (SAP*, DDIC, ITSECURITY).

. Communicating with the Security Coordinators, Line of Business

(LOB) people for organizing and analyzing the security requests and

documenting the details for future reference.

. Frequent monitoring of users having access to financial related

data.

. Maintaining the USR40 (password table) table and streamlining the

guidelines for the password restrictions.

. Worked in configuration HR structural authorizations and possesses

a thorough understanding of all aspects of the Human Resources

business process, comprising the life cycle of an employee

including recruiting, hiring, employee maintenance, payroll and

benefits.

. Created Functional Specs, Conceptual design and detail design

documents for ESS/MSS based on the business requirements.

. Created various custom iviews for both ESS and MSS

. Involved in the day to day movement of SAP transport requests from

development systems to quality and subsequently to preproduction

and Production systems.

. Well acquainted with Remedy software for Change management and Help

Desk Issues.

. Configuring/maintaining transport system and coordinating with

various ongoing projects to see that their Config/object changes

made it to the PRD system without any overlaps.

. Documented Daily, Weekly, Monthly Remedy tickets processed based

on different projects and part of 24/7 On-call team.

Project: 5 ( Employer : Insoft Solutions, Inc) Duration:

05/02 - 02/03

Client: PSE&G, Newark NJ.

Platform & Skills: SAP R/3 3.0F, 4.0B, HP UX 11.0, Oracle 8.0.6

Scope: Installed SAP R/3 3.0F, upgrade to 4.0B and SAP BW software.

Role: Basis/Security consultant

Duties & Responsibilities:

. SAP Installation of Release 3.1G

. Installation of SAPGUI/SAP help

. Performed installations, Setup Development projects, Developed

Client system strategy document, helped procuring hardware (servers

and disk storage) for SAP implementation

. Configure Change and Transport System(CTS) Transport Management

Systems (TMS) & Change Transport Organizer (CTO)

. Setting up the TP program.

. Determine the Transport Strategy, QA approval procedure

. performing and monitoring transports

. User Administration using Profile Generator

. OSS notes download and solving end user problems

. Client copy functions and Client Maintenance.

. Profile Maintenance from CCMS

. Designing strategy for backup and recovery of database.

. User Distribution: Logon Load Balancing and the SAP logon Utility

. Involved in the creation of roles based on BW Reporting

Functionality with a very high granularity.

. Implemented Hierarchy Security for BW Queries in multiple ways.

. Developed custom Authorization Objects for queries developed by the

users.

. Worked with both the authorization classes in BW

. Set up security by INFOAREA, INFOCUBE, ODS, PSA, INFOOBJECT, QUERY

and WORKBOOKS

. Implemented Central User Administration (CUA) which consists of 3

landscapes

. Involved in the implementation of structural authorizations for the

HR module

. Creating and Assigning Profiles to Users using Profile Generator

. Formulation of Transport Strategy in the CTS

. Converting Manual Profiles to Profile Generator Profiles

Education:

M.S in Electrical Engineering, University of Nebraska, Lincoln,

Nebraska.

B.Tech in Electrical Engineering, JNT University, Hyderabad, India.



Contact this candidate