CODY VANMETER
Email: ********.****@*****.*** Cell: 419-***-****
SAP SECURITY, CONTROLS, and COMPLIANCE
Cody has 10 years of experience in designing, configuring, and implementing SAP Security and Controls and Governance, Risk and Compliance (GRC) solutions. He has experience in requirement gathering, design, development, and maintenance of SAP application security, security redesign, SOD rule set design, analysis and remediation, continuous monitoring and applying mitigating controls to access and process violations. Areas of Expertise
PROFESSIONAL EXPERIENCE
Winterhawk Consulting April 2015 – Present
SAP Security and GRC Consultant
• GRC Administration tasks including:
o Performing Quarterly User Access Reviews
o Conducting all levels of training: Role Approver, Administration, Workflow, Simulation o Administration of Access Request Management, Emergency Access Administration, and Access Risk Analysis
o Developing custom notifications texts for ARM
• GRC updates to Risk ruleset, functional updates, test and transport though change management process.
• Configured SAP GRC Access Control modules (Risk Analysis, Business Role Management, Emergency Access Management) to support governance and compliance.
• Developing test scripts for GRC integration testing
• Expert in GRC Modules: Access Control, Risk Analysis, Role Management and Emergency Access Management
• Segregation of Duties (SOD) Remediation and Risk Rationalization
• Performed SAP Security role remediation.
• Built relationships with core users to ensure supporting and working effectively with all areas of the business.
• Led SOD role remediation efforts utilizing Risk analysis reports to perform user and role-based access changes.
• Worked closely with clients and their security team to develop a long-term strategy of sustaining a minimal amount of SOD violations.
• Gathered requirements and executed Role Redesign efforts as per SOX, SOD security requirements, and compliance.
• Generated periodic status reports and participated in frequent updates to management and team members.
• Worked with project managers and organizations to understand project requirements for SAP Role Redesign project-based work.
• Developed work breakdown structure for security tasks and project plans to meet deliverables. SAP GRC SAP S4 Application Security Access Risk Ruleset design Fiori Marketplace IDs BI Security
Continued on Page 2
Cody VanMeter Page 2 of 3
• Developed and implemented SAP security strategies, procedures, standards, and tools necessary to enable business functionality while securing sensitive data and otherwise supporting the Company’s internal controls and risk guidelines.
Winterhawk Consulting
SAP Security and Control Analyst
• Provided information security expertise and assistance in incorporating control measures into new and existing SAP security guidelines.
• Demonstrated ability to work effectively within a team, deliver high performance, and customer satisfaction.
• Created, documented, and presented the procedures for end user training regarding secure provisioning.
• Gathered requirements, designed, developed, and maintained SAP application security.
• Performed SAP user administration tasks such as creating, modifying, and deletion of users.
• Maintained user master records including user provisioning and de-provisioning.
• Designed and maintained single, composite, and derived roles using Profile Generator (PFCG).
• Designed and modified roles according to business requirement
• Managed the addition and removal of Transaction Codes, authorizations, and authorization objects by modifying existing roles based upon change request.
• Comprehensive use of Profile Generator to generate roles and assign roles to end users.
• Maintained authorization groups and secured table level technical data.
• Maintained and managed firefighter IDs to support users.
• Managed issues within SAP Security and Authorizations, including escalation and troubleshooting through resolution.
• Resolved Security related defects raised during Integration and User Acceptance Test cycles.
• Configured workflow using Business Rules Framework.
• Created and maintained users and roles in Fiori, BI, HCM, ECC, S4, and GTS systems.
• Opened clients and created marketplace IDs in SAP support portal.
• Built and maintained standard role-based security models across SAP S/4HANA, ECC, and Fiori, including catalog and group setup and space and page setup, task mapping, and user access conversion.
• Provided hands-on troubleshooting and resolution of complex authorization issues using SUIM, SU53, ST01, STAUTHTRACE and Fiori debugging tools.
• Supported audit readiness by partnering with internal and external audit teams to identify risks, document controls, and refine compliance procedures.
• Delivered post-go-live hyper-care support, resolving security issues and ensuring seamless user transitions.
• Mentored onshore and offshore teams on SAP Role Optimization projects, ensuring consistent delivery and knowledge transfer.
• Exposure to multicultural work environments and international teams, supporting global security initiatives.
• Supported implementing remediation strategies effectively.
• Compliance Frameworks: SOX, ITGC, Internal/External Audits
• Created naming conventions and led Unit Testing, UAT, and user conversion workshops.
• Upgraded and integrated multi-system Identity Management (IDM) landscapes across ECC, HCM, CRM, and other SAP platforms.
• Exposure to multicultural work environments and international teams, supporting global security initiatives.
• SAP S/4HANA, ECC, and Fiori, including catalog and group setup and space and page setup, task mapping, and user access conversion.
• Creating training documents to pass to team members. Cody VanMeter Page 3 of 3
EDUCATION OTHER
Franklin University - 2017
BA Business Management