Job Description
Overview
The SAP Security Sustain Manager leads the day-to-day operation of SAP Security services across production and non-production environments. The role is responsible for access governance, compliance, audit support, service delivery, operational excellence, vendor management, and continuous improvement while ensuring business users maintain secure and compliant access to SAP systems.
The role balances security governance, business enablement, audit compliance, risk management, sustain support operations, and vendor management to ensure reliable and efficient SAP security services across the enterprise.
Responsibilities
Service Delivery Management
- Lead SAP Security sustain operations across global SAP landscapes
- Own service delivery performance, SLAs, KPIs, and operational metrics.
- Manage incident, request, and problem management processes.
- Ensure timely resolution of SAP security tickets and escalations.
- Drive continuous service improvements and operational efficiencies.
User Access Governance
- Oversee user provisioning, deprovisioning, and access modifications.
- Ensure compliance with access management policies and standards.
- Govern privileged access, Firefighter IDs, and emergency access processes.
- Review and approve high-risk access requests.
- Support identity lifecycle management activities.
Role & Authorization Management
- Govern SAP role design, maintenance, and optimization.
- Approve role changes and authorization enhancements.
- Ensure role-based access controls support business requirements.
- Maintain security authorization matrices and role documentation.
- Drive role simplification and standardization initiatives.
Governance, Risk & Compliance (GRC)
- Lead Segregation of Duties (SoD) risk management and remediation.
- Govern SAP GRC Access Control processes and rulesets.
- Conduct periodic access reviews and certifications.
- Monitor sensitive access and risk violations.
- Ensure compliance with SOX, ITGC, and corporate security standards.
Audit & Controls
- Serve as the primary SAP Security contact for internal and external audits.
- Coordinate audit evidence collection and control testing.
- Ensure execution of SAP security controls.
- Manage remediation plans for audit observations and compliance findings.
- Maintain security policies, procedures, and support documentation.
Vulnerability & Risk Management
- Oversee SAP vulnerability identification and remediation.
- Review SAP OSS security notes and patch recommendations.
- Ensure security risks are assessed before production deployment.
- Monitor compliance with enterprise cybersecurity standards.
- Drive closure of security findings and risk exceptions.
Change & Release Management
- Provide security approval for application enhancements and releases.
- Review security impacts of projects, upgrades, and system changes.
- Participate in testing, cutover, and hypercare support.
- Ensure security controls remain effective following deployments.
- Support transition of projects into sustain operations.
Vendor & Team Leadership
- Lead internal SAP Security analysts and external service providers.
- Manage vendor performance, contract deliverables, and resource planning.
- Conduct performance reviews and skill development activities.
- Establish operational governance with delivery partners.
- Drive knowledge management and cross-training initiatives.
Reporting & Stakeholder Management
- Provide regular operational reporting to leadership.
- Present security metrics, risk posture, audit status, and service health.
- Partner with Business, Controls, Audit, Cybersecurity, and SAP functional teams.
- Escalate critical security risks and operational issues appropriately.
- Support executive decision-making through security insights and recommendations.
Key Success Metrics
- SLA Compliance
- Ticket Backlog Reduction
- SoD Risk Reduction
- Audit Compliance Results
- Access Provisioning Turnaround Time
- Security Vulnerability Closure Rates
- User Satisfaction
- Operational Cost Optimization
- Control Effectiveness
- Vendor Performance Metrics
Compensation and Benefits:
- The expected compensation range for this position is between $110,700 - $185,250.
- Location, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. Your recruiter can share more about the specific salary range during the hiring process.
- Bonus based on performance and eligibility target payout is 12% of annual salary paid out annually.
- Paid time off subject to eligibility, including paid parental leave, vacation, sick, and bereavement.
- In addition to salary, PepsiCo offers a comprehensive benefits package to support our employees and their families, subject to elections and eligibility: Medical, Dental, Vision, Disability, Health, and Dependent Care Reimbursement Accounts, Employee Assistance Program (EAP), Insurance (Accident, Group Legal, Life), Defined Contribution Retirement Plan.
Qualifications
Required Qualifications
- Bachelor's degree in Information Technology, Information Systems, Cybersecurity, or related field.
- 8+ years of SAP Security experience.
- 3+ years of leadership or people management experience.
- Deep expertise in:
- SAP Security & Authorization Concepts
- SAP GRC Access Control
- Segregation of Duties (SoD)
- SAP S/4HANA Security
- SAP Fiori Security
- SAP BW, HCM, CRM, SCM Security
- Audit and Compliance Controls
- Experience leading global SAP security initiatives and project teams.
Preferred Qualifications
- SAP Security or SAP GRC certifications.
- Experience with cloud security models and SAP BTP.
- Knowledge of SOX, COBIT, NIST, and cybersecurity frameworks.
- Experience supporting multinational SAP landscapes and global deployments.
- Strong understanding of SAP integration and application controls.
Competencies
- Strategic Thinking
- Leadership & Team Development
- Stakeholder Management
- Risk Management
- Executive Communication
- Problem Solving
- Vendor Management
- Program & Project Management
- Cross-Functional Collaboration
- Results Orientation
Our Company will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the Fair Credit Reporting Act, and all other applicable laws, including but not limited to, San Francisco Police Code Sections 4901-4919, commonly referred to as the San Francisco Fair Chance Ordinance; and Chapter XVII, Article 9 of the Los Angeles Municipal Code, commonly referred to as the Fair Chance Initiative for Hiring Ordinance. All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status. PepsiCo is an Equal Opportunity Employer: Female / Minority / Disability / Protected Veteran / Sexual Orientation / Gender Identity / Age If you'd like more information about your EEO rights as an applicant under the law, please download the available EEO is the Law & EEO is the Law Supplement documents. View PepsiCo EEO Policy. Please view our Pay Transparency Statement.