Job Description
Reporting to the Vice President, Risk & Compliance (R&C), the Director / Senior Director, R&C is responsible for the design, oversight, and continuous improvement of technology-enabled risk management and internal controls across SAP S/4 HANA (S/4) and associated financial boundary systems....While having the ground floor opportunity of bridging a multi-year S/4 finance transformation implementation with a post go-live compliance and advisory function, this role provides leadership in all aspects of Security, Risk, and Controls (SRC), which includes assessing job-based security roles, segregation of duties (SoD), and process-level risks and developing / maintaining a company-wide Risk & Control Matrix (RCM)....The Director / Senior Director partners closely with the S/4 project team, Global Controllership across Global Financial Operations (GFO), Corporate, and Business Units; Operations & Technology (O&T); and various compliance groups to ensure risks are identified, mitigated, and appropriately controlled within an evolving financial systems landscape....Responsibilities:
Security & Access Controls and SoD Governance for S/4 and associated boundary systems
• Govern and work closely with Project Teams, GPOs, and O&T to develop and maintain the ongoing global access control strategy and role design standards
• Help design and implement new roles that align with NBCU users' job responsibilities
• Design post-go-live approval workflows and set policy for access provisioning, role and transaction code changes, SoD risk mitigation, and periodic access and SoD rule set reviews
• Act as the final design authority for critical and cross-functional / high-risk roles and help ensure SAP security design aligns with financial close, PTP, OTC, RTR control objectives, SOX compliance, and cyber, internal audit and external audit expectations
• Identify, analyze, and remediate SoD risks / rule sets
• Assess inherent and residual risks, with a focus on system-enabled risks and SoD exposures, and work directly with corporate / business units an