Martin User
@martinuser9
SAP GRC security consultant specializing in IAM, SoD remediation, and audit-ready compliance for regulated enterprises.
What I'm looking for
I’m a results-driven SAP GRC Security Consultant with 8+ years of progressive experience spanning SAP GRC Access Control, IAM, IT risk and compliance, and cybersecurity governance. I design and enforce SAP security roles in S/4HANA and ECC environments, remediate Segregation of Duties (SoD) conflicts, and deliver audit-ready compliance postures aligned with SOX, HIPAA, PCI-DSS, FISMA, and NIST frameworks.
I also bring a strong hands-on lens to the work: I lead SoD analysis using SAP GRC 12.0 ARA, configure and upgrade SAP GRC 12.0 modules (ARM, ARA, BRM), run quarterly user access reviews (UAR), and use SAP Solution Manager (SolMan) to strengthen change management and audit trail integrity. Across regulated public sector and financial/healthcare contexts, I bridge technical controls with business risk language to engage auditors, stakeholders, and executive leadership—supporting evidence packages and sustained compliance readiness.
Experience
Work history, roles, and key accomplishments
SAP GRC Security Consultant
Infotech Risks Security LLC (IRSL Consulting)
Jan 2020 - Present (6 years 6 months)
Architected and maintained SAP security across S/4HANA and ECC6, managing end-to-end user provisioning, role design, and access governance. Led SAP GRC 12.0 ARA SoD analysis and remediation, automated access request workflows, and delivered audit evidence for SOX ITGC audits with zero critical findings over three consecutive cycles.
Cyber GRC & DLP Analyst
Infolock Technologies
Sep 2020 - Feb 2022 (1 year 5 months)
Performed enterprise technical risk assessments and vulnerability remediation aligned with NIST 800-53 and ISO 27001. Monitored Data Loss Prevention (DLP) alerts, led incident response for HIPAA/PCI-DSS/SOX-related data events, and built risk registers and compliance dashboards.
IT GRC Professional
Freddie Mac
Oct 2018 - Sep 2020 (1 year 11 months)
Monitored and tracked IT control deficiencies and guided control owners through remediation plans for gaps found during SOX and FFIEC examinations. Supported DR/BCP exercises, advised on control design and testing, and escalated emerging risks to senior leadership.
Security Compliance Analyst
Tangible Security
Apr 2016 - Oct 2018 (2 years 6 months)
Coordinated evidence collection and stakeholder interviews for HIPAA, SOC 2, ISO 27001, and FISCAM audits to ensure complete and timely submissions. Tracked vendor and third-party risk remediation across a portfolio of 50+ vendors and authored security documentation including System Security Plans (SSPs) and contingency test reports.
FedRAMP Cloud Assessor (Junior)
Autonomic Resources
Feb 2015 - Mar 2016 (1 year 1 month)
Assisted FedRAMP readiness assessments by reviewing Authorization to Operate (ATO) packages for cloud service providers seeking federal authorization. Implemented and validated NIST 800-53 controls and produced threat/vulnerability assessment reports with remediation recommendations across IaaS, PaaS, and SaaS environments.
Education
Degrees, certifications, and relevant coursework
Barclay College
Business Administration
Studied Business Administration at Barclay College in 2015.
Guilford College
Computer Information Systems
Studied Computer Information Systems at Guilford College in 2013.
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Martin?
You can contact Martin and 90k+ other talented remote workers on Himalayas.
Message MartinGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
