Saketh R.Gudimella
Email: ******.*********@*****.***
M: 901-***-****
Objective:
> Seeking a Lead/Senior SAP Security/GRC Administrator position
Areas of Expertise
. Over 9 years experience as a Security Administrator in SAP R/3(ECC 6.0,
5.0, 4.7,4.6C, 4.0B), BW (BI 7.0, BW 3.5, 3.2, 3.0), BPC 7.0, HR, SRM
4.0, CRM, Solution manager 7.0, APO, PI/XI, VIRSA/GRC, Approva Biz
Rights.
. Upgrade experience from 4.6C to ECC 5.0, ECC 5.0 to ECC 6.0 and BW 3.5 to
BI 7.0.
. Security Experience with various modules like PP/MM/QM/IM/WM/PM/HR/FI-
CO/SD/TS/MDM etc.
. Set up CRM security for Marketing and Campaign Management, Business
Partner Security, E-commerce (Internet Sales) and Product Security.
. BI Security- Secured BI Info Areas, Info cubes, Queries, Info objects,
Hierarchy and Info objects. Successfully upgraded BW3.5 authorizations to
BI7.0 Analysis authorizations. Restricted Analysis Authorizations (Using
RSECADMIN Tool) at Characteristic Values, Attribute Values, Hierarchies
and Key Figure level. Extensively used new BI tools like Authorization
Monitoring and Legal Audit. Defined Authorization-Relevant
Characteristics and Attributes using InfoObject Maintenance (RSD1).
. BPC Security - Setup Users, Teams, Task profiles and Member access
profiles.
. HR Security - Designed and Developed HR Security in Personnel
administration and Payroll accounting, Benefits, Compensation, Time
Management, Travel, Payroll, Personnel Development and Org Management
modules. Implemented Structural Authorizations to Restrict PD Objects.
. Extensively worked on tools like GRC(5.3, 5.1), VIRSA'S VRAT 3.0,
Approva Biz Rights and PCI tools for Sarbanes-Oxley Compliance
. Configured GRC Compliance Calibrator (Risk Analysis and Remediation),
Fire Fighter (Superuser Privilege Management), Role Expert (Enterprise
Role Management), Access Enforcer (Compliant User Provisioning) and
Approva's BizRights tools.
. Preventative, mitigating and compensation controls to ensure the
appropriate level of protection and adherence to the goals of the overall
SAP security strategy
. Collaborate with other team members and business representatives to
ensure that security settings meet the requirements of the business and
align with the defined controls and standards
. Respond to requests and prepare SAP security reports based on management
and department needs.
. Excellent Computer Skills with particular emphasis on Microsoft Word,
Excel, Access, PowerPoint and Visio.
. Excellent problem solving skills, team player with good communication
skills
Professional Experience:
Miller Coors Nov 2009 - Present
Milwaukee WI
SAP BI and HCM Security Lead
Environment: ECC 6.0, BI 7.0, HCM, SRM, CUA, GRC 5.3
Responsibilities:
> Provided SAP Security design, configuration, and support for SAP
NetWeaver systems running BI/BW 7.0 (NetWeaver 2004s) and HCM (Personnel
administration and Payroll accounting, Benefits, Compensation, Time
Management, Travel, Payroll, personnel Development and Org Management
modules)
> Developed the global security plan defining security strategy in design,
development implementation and support
> Created template for the global rollout for the creation and maintenance
of security accesses, permissions and controls by job role requirements
> Designed and performed fully integrated tests of delivered solutions;
investigated, diagnosed and analyzed issues and recommend solutions
> Managed and tracked project schedule
> Extracted Structural authorizations from HCM system to BI using standard
SAP extractors
> Created Analysis Authorizations using the new RSECADMIN tool to restrict
BI reporting users.
> Restricted Roles based on Personnel Subarea, Cost Center, Employee
Subgroup and sensitive fields like 0SALARYGR, 0ANSALARY, ZHRLYPAY
> Assigned workbooks, queries to roles in the Business explorer.
> Created Portal Roles so that Users can access to Roles/Queries through
the Portal.
> HCM Security
. Gathered Requirements and Created Roles for HCM modules including
Personnel administration and Payroll accounting, Benefits,
Compensation, Time Management, Travel, Payroll, Personnel Development
and Org Management modules.
. Created Security Roles for ESS and MSS
. Restricted HCM Roles at various levels like Employee sub group,
personnel area, Info type and subtype.
. Implemented HR position based security
. Built HR context sensitive authorizations
. Setup HR Authorization switches as per the Requirement
. Created Role Vs Tcode and Role Vs Infotype Matrix.
. Created Test scripts for Unit test and Integration Test. Created Test
Id's and assigned the security roles based on the position based
security model.
. Provided support for Cutover, Go-live activities.
DTE Energy
Detroit
March 2005 - May 2007
August2007 - October 2009 Sr. SAP Security
Architect/Lead
Environment:
Wave I Phase - SAP R/3 4.7, BW 3.0, CRM 5.2, XI 3.0, EP 6.0 HR Security
administration, PCI sentinel for SOX remediation
Wave II Phase - ECC5.0, BI 7.0, SEM BPS and BCS, CRM 2007, HR, PI, Portal,
Solution manager 7.0, GRC 5.2 for SOX remediation
Performed the Upgrade project from ECC 5.0 to ECC 6.0, BW 3.5 to BI 7.0,
CRM 5.2 to CRM 2007
Lead the SAP Security Redesign project by reducing the number of Roles by
aligning the Roles to user's job positions, thereby reducing the Security
maintenance efforts.
Certified by DTE Energy for working above and beyond normal expectations
Responsibilities:
> Extensive experience in Requirement gathering, Design, Development, and
Maintenance of SAP applications security.
> Experienced in handling the security workshops and being the focal point
for major security issues.
> Defined Standard Work Instruction (SWI's) and Job Aid's for all security
related activities.
> Designed Project Deliverable template and gathered Security Role
requirements from Business team using Business Process Master List (BPML)
for SAP, BW, HR, CRM and SRM.
> Implemented Position based (Wave I) and Role-based (Wave II) security.
> Designed Security for various modules like PP/MM/QM/IM/WM/PM/HR/FI-
CO/SD/TS/TV/Tax/MDM etc.
> Configured and managed Central User Administration (CUA) environment.
Administer Users using SCUA, SCUL, SCUG and SCUM
> Successfully implemented a 3-Tier architecture which resulted in less
number of issues for Production support team
> Enforced Best Business Practices during all phases of Project life cycle.
> Designed Project Charter which includes Objectives, Scope, Strategy, Work
Plan, Constraints, Assumptions and Risks
> Involved in all aspects of SAP security from setting up naming
conventions for roles, profiles, Unit/Integration Test ids, custom
objects and user groups to interact and work closely with various
functional teams to collect role requirements, configuration of single
and composite roles, transportation of roles, deployment activities and
post implementation support
> Created and Executed several ECATT Scripts for User Administration.
> Successfully Implemented Single Sign On (SSO).
> Administered Enterprise Portal User Management Engine (UME).
> Integrated SAP with IBM Tivoli Identity Manager and LDAP
> CRM Security -
. Worked with functional analysts in developing CRM security in
accordance to CRM Business Role requirements and assigning PFCG roles
to business roles.
. Extensively used CRMD_UI_ROLE_PREPARE report to generate the necessary
UIU_COMP settings corresponding to the CRM business role.
. Worked on CRM Call Center project and secured cases, knowledge search
etc.
. Hands on experience with CRM ACE tool for maintaining dynamic
authorizations to CRM objects
. Secured Call Center information.
. Secured Sales and Marketing business scenarios
> HR Security -
. Design and Development of HR Security for various modules including
Personnel administration and Payroll accounting, Benefits,
Compensation, Time Management, Travel, Payroll, Personnel Development
and Org Management modules.
. Created Security Roles for ESS and MSS.
. Implemented Security using Structural and General authorization
. Knowledge of various HR Infotypes in the system and the interaction of
general and structural authorizations
. Designed custom Function modules (to reduce the Structural Profile
Count) and used in Structural authorizations to meet the Business
Requirements.
. Designed and implemented New Authority Check statements in the HR custom
Transactions and Programs.
. Generated authorizations for users in organizational plan using
RHPROFL0 report
. Extensively used RHBAUS reports to improve the performance while using
Structural authorizations.
> BW3.5/BI 7.0 Security
. Created Analysis Authorizations (RSECADMIN / RSECAUTH) to restrict BI
reporting users.
. Optimized the authorization relevant checks on InfoObjects in BI.
. Define Authorization-Relevant Characteristics and Attributes using
InfoObject Maintenance (RSD1)
. Restricted Analysis Authorizations (Using RSECADMIN Tcode) at
Characteristic Values, Attribute Values, Hierarchies and Key Figure
level.
. Designed and developed a BW workgroups concept for the reporting power
users to share queries within their business groups including
development, Operations and Production support, Change Management,
Security design and methodology, project planning and project
management.
. Worked with BW Technical Team to design security, identify InfoAreas,
InfoCubes, and created custom objects.
. Upgraded BW from BW 3.5 to BI7.0. Migrated BW 3.5 Authorizations to BI
7.0 Authorizations using SAP's Migration Tool (program
RSEC_MIGRATION). Restricted Authorizations at various levels such as
Query, Query View, Web Template, Web Item and Workbook.
. BPC Security - Setup Users, Teams, Task profiles and Member access
profiles.
> GRC
. Coordinated with Internal Audit and Functional Teams to develop
solutions for SOD conflicts, control issues, Alert management and
Emergency access monitoring.
. Worked on External Audit remediation efforts.
. Initiated changes in the Role Design and deployed process
controls to tackle SOX/SOD issues.
. Performed the implementation for SAP Best Practice
configurations for GRC.
. Implemented and configured the entire GRC tool set - Compliance
Calibrator (Risk Analysis and Remediation), Fire Fighter (Superuser
Privilege Management), Role Expert (Enterprise Role Management),
Access Enforcer (Compliant User Provisioning)
. Worked with Audit and Business Teams to create the RAR Rule Set,
Mitigation controls and Firefighter access procedures.
. Configured Compliant User Provisioning for User Access request
process.
. Responsible for the planning and implementation of the entire GRC
Suite including Compliance Calibrator (Risk Analysis and Remediation),
Fire Fighter (Superuser Privilege Management), Role Expert (Enterprise
Role Management), Access Enforcer (Compliant User Provisioning).
. Created Mitigation Controls, Mitigation Owners and Alerts in
Compliance Calibrator to monitor critical transaction usage
LTD Commodities
Chicago June 2007 - August 2007
SAP Security Lead
Environment:
SAP ECC 6.0, BI 7.0, SEM BPS and BCS, CRM, HR, APO, GTS, PI, Approva
BizRights 4.1
Responsibilities:
> Designed Project Deliverable template and gathered Security Role
requirements from Business team using Business Process Master List
(BPML).
> Extensively used Automatic Profile Generator (PFCG) to create
roles/profiles for various systems such as ECC 6.0, BI 7.0, SEM BPS and
BCS, CRM, HR.
> Created, generated profiles, Authorizations, object classes, objects, and
roles and assigned to user master.
> Worked on SAP Check Indicator Defaults and Field values, reduced the
scope of Authorization checks using transaction SU24 and maintained check
indicators for Transaction codes.
> Troubleshoot security/authorization related problems using SU53, ST01,
RSSM(for BW)and
SUIM
> Work with profile generator (PFCG) in creating roles, profiles, composite
roles, derived roles, and global roles.
> APO Authorizations - Worked on APO authorizations for SDP Functions,
Macros, Master Data and Planning Area, Book like C_APO_FUN, C_APO_MAC,
C_APO_LOC, C_AP0_PB
> HR Security -
. Designed and Implemented structural authorizations to cover HR
requirements
. Possesses good understanding of the various HR Infotypes in the system
and the interaction of general and structural authorizations
. Set up general authorization checks for PA, PD, Payroll modules
. Created Structural authorization profiles as per the Requirements.
. Possess a solid understanding of the evaluation paths and assisted in
determining the responsibility period for HR applications
. Schedule Background processing using central scheduling tools
> CRM Authorizations -
. Creation and maintenance of an Employee in the CRM system with
transaction BP
. Maintained the Organizational Model with transaction PPOMA_CRM.
. Set up security for Marketing and Campaign Management, Business
Partner Security, E-commerce (Internet Sales) and Product Security.
. Restrictions made based on person responsible, Authorization Group,
Campaign Type. Also Set Restrictions for assigning Attribute Sets and
Attributes
> BI 7.0 Authorizations
. Designed and Developed BI 7.0 Analysis authorizations using RSECADMIN.
. Restricted Analysis Authorizations (Using RSECADMIN Tcode) at
Characteristic Values, Attribute Values, Hierarchies and Key Figure
level.
. Restricted Authorizations at various levels such as Query, Query View,
Web Template,Web Item and Workbook.
. Grouped authorizations into hierarchies and assigned to users (using
Infoobject 0TCTAUTH).
Becton Dickinson
Franklin Lakes, NJ Jan 2004 - March 2005
Sr. SAP Security Consultant
Worked as a Sr. SAP Security Consultant in SAP R/3 4.6C, BW 3.0, HR, CRM
and APO for SOX remediation project, VIRSA VRAT 3.0
R/3 Security Administration:
> Designed Project Deliverable template and utilized the security analysts
efficiently.
> Extensively used Automatic Profile Generator (PFCG) to create
roles/profiles for various modules such as HR, MM, FM, GL, CO, AP, AR
etc.
> Created, generated profiles, Authorizations, object classes, objects, and
roles and assigned to user master.
> Worked on SAP Check Indicator Defaults and Field values, reduced the
scope of Authorization checks using transaction SU24 and maintained check
indicators for Transaction codes.
> Troubleshoot security/authorization related problems using SU53, ST01,
RSSM(for BW)and
SUIM
> Work with profile generator (PFCG) in creating roles, profiles, composite
roles, derived roles, and global roles.
> HR Security - Designed Implemented structural authorizations to cover HR
requirements
> Set up the general authorization checks for PA, PD, Learn Management and
Payroll modules.
> BW Security- BW Info cubes, Info objects, Hierarchy, Variables, Update
and transfer rules, Info Areas, Info object catalog, ODS (Operational
Data Store).
> Created and maintained BW reporting objects for a variety of custom
authorization and reporting objects that are required in the
implementation.
> Worked as part of remediation team and assist in elimination of
Segregation of Duties (SOD) conflicts inherent within the SAP security
model using VIRSA VRAT tool.
> Work with Business specialists to help them understand what SAP
authorization objects are causing the conflicts and what all options
exist for mitigating the conflicts.
> Manually modifying profiles and roles to remove the SOD conflicts present
in the roles.
> Knowledge transfer to team members provided ongoing security related
support for all security milestones during different phases.
> Have a close interaction with Internal and External Auditors
> Managed Task assignment of reporting security analysts.
Delphi Corporation, Troy, MI
Senior SAP Security Administrator Aug2003 - December 2003
Environment: SAP R/3 4.6C, BW 2.0
As a SAP Security Administrator, I provided complete SAP Security support
Security Responsibilities:
> Defining and implementing security policies and procedures.
> SAP Security Administration across all the SAP modules - HR, MM, FM, GL,
CO, AP, AR etc
> Used Profile Generator for creation, modifying roles, composite roles,
global roles, derived roles.
> Manual generation and modification of profiles.
> Generated authorizations using Profile Generator and assigned to
authorization profiles and assigned to activity groups. Activity groups
are assigned to user master.
> Setting up SAP system for auto log-out, password length and expiration
and specifying impermissible passwords
> User Administration for nearly 6,000+ users. Used Central User
Administration(CUA) for user administration
> Created users and maintained user master and established security
policies and procedures.
> Used Derived activity groups to create new activity groups and to
transfer transaction codes from old ones to new ones.
> Extensively worked on Authorization objects, fields, authorizations,
authorization profiles.
> Performed transports and mass transports of roles.
> Perform reconciliation of user master record and roles using PFUD and
SUPC
> Used workflow and transport proposal extensively.
> Customized every Authorization object in the FI-CO, SD, MM and BW
modules.
> BW security - Worked with BEx analyzer, BEx explorer and BW
administration workbench(RSA1)
> Created and maintained BW reporting objects for a variety of custom
authorization and reporting objects that are required in the
implementation. Worked closely with Finance and BW teams to design a
scalable, flexible security model.
> Designed the workbook structure for the BW implementation team and
modified the roles as new reports and analytical areas were added.
Boston Scientific
Security Administrator Sep 2001 - August 2003
Environment: SAP R/3 4.6C, 4.0, BW 2.0
As a SAP Security Administrator, I provided complete SAP Security support
for nearly 20+ production servers.
Security Responsibilities:
> Provide direct support to the business and I.T. staff for security
related issues and requests.
> Defining and implementing security policies and procedures.
> SAP Security Administration across all the SAP modules - HR, MM, FM, GL,
CO, AP, AR etc
> Used Profile Generator for creation, modifying roles, composite roles,
global roles, derived roles.
> Manual generation and modification of profiles.
> Generated authorizations using Profile Generator and assigned to
authorization profiles and assigned to activity groups. Activity groups
are assigned to user master.
> Setting up SAP system for auto log-out, password length and expiration
and specifying impermissible passwords
> User Administration for nearly 6,000+ users. Used Central User
Administration(CUA) for user administration
> Created Transaction codes for the programs and ran the transactions.
> Created users and maintained user master and established security
policies and procedures.
> Used Derived activity groups to create new activity groups and to
transfer transaction codes from old ones to new ones.
> Extensively worked on Authorization objects, fields, authorizations,
authorization profiles.
> Performed transports and mass transports of roles.
> Used CATT scripts for mass users and assigning roles.
> Perform reconciliation of user master record and roles using PFUD and
SUPC
> Used workflow and transport proposal extensively.
> Customized every Authorization object in the FI-CO, SD, MM and BW
modules.
> Worked with BEx analyzer, BEx explorer and BW administration
workbench(RSA1)
> Created and maintained BW reporting objects for a variety of custom
authorization and reporting objects that are required in the
implementation. Worked closely with Finance and BW teams to design a
scalable, flexible security model.
> Designed the workbook structure for the BW implementation team and
modified the roles as new reports and analytical areas were added.
SC Johnson
Milwaukee, WI April 2000 - Aug
2001
Security Administrator
Environment: SAP R/3 4.0
As a SAP Security Administrator, I provided complete support of the SAP
security landscape of International paper.
Security Responsibilities:
> Designed and implemented methodology for controlling end user access to
plants, fund centers, etc.
> Created nearly 200 customized end user roles and menus, plus hundreds of
"mini-roles" to allow for low-level modular access control.
> Set up roles and user accounts for over 5000 End Users for primary Go
Live.
> Set up roles and user accounts for three follow-on projects, including
Business Warehouse
> Developed methodology and programs/scripts for continuous reconciliation
of End User Database and R/3 system.
> Continuously improved security configuration to reflect best practices
and to prepare for system audits.
> Configured Profile Generator and transported settings to all clients,
setup security for the developers,
> Used CATT scripts for mass users and assigning roles.
> Automated daily tasks and mundane procedures.
> Worked closely with the Technical Leads to create and maintain security
roles, discuss status reports, policies related to the SAP R/3 system,
project timeliness and deliverables.
> Providing on-call support on a rotational basis and as needed.
Education:
> Bachelor of Technology in Computer Science & Engineering
Jawaharlal Nehru Technological University, India
> MS in Computer Science
University Of Memphis, Memphis, TN
References:
Available on request