Base Career helps you apply smarter for this job.
Key skills for this role
The Security Engineer IV is responsible for SAP Security, Identity & Access Management (IAM), and Governance, Risk & Compliance (GRC) operations in support of the Retail Spine transformation, a business led, IT enabled modernization initiative aimed at strengthening long term competitiveness, improving operational efficiency, and establishing future state enterprise capabilities.
Ahold Delhaize USA, a division of global food retailer Ahold Delhaize, is part of the U.S. family of brands, which also includes five leading omnichannel grocery brands – Food Lion, Giant Food, The GIANT Company, Hannaford and Stop & Shop. Ahold Delhaize USA associates support the brands with a wide range of services, including Finance, Legal, Sustainability, Commercial, Digital and E-commerce, Technology and more.
The Security Engineer IV is responsible for SAP Security, Identity & Access Management (IAM), and Governance, Risk & Compliance (GRC) operations in support of the Retail Spine transformation, a business led, IT enabled modernization initiative aimed at strengthening long term competitiveness, improving operational efficiency, and establishing future state enterprise capabilities.
This engineer is responsible for role design, access controls, compliance, and audit readiness across all SAP S/4HANA and integrated systems. The Engineer partners closely with the SAP Functional teams, business process owners, Audit, InfoSec, Systems Integrator, and third party technology providers to ensure secure, compliant, and scalable SAP operations that enable Retail Spine program success.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Quincy, USA
Carlisle, USA
Quincy, USA
Scarborough, USA
Quincy, USA
Salisbury, USA
Salisbury, USA
Salisbury, USA
Salisbury, USA
Govern the security obligations and deliverables of the SI and vendor partners, ensuring secure solution design, adherence to established standards, quality of security-related work products, and timely risk escalation and remediation.
Define and govern identity and access management integration standards, including SSO, MFA, and Azure AD/Entra ID federation, in partnership with Enterprise Security and SI architects ensuring secure, scalable identity patterns are established and enforced across the SAP landscape.
Ensure security is embedded across the full release lifecycle covering transport reviews, role change impact assessments, interface security validations, and landscape change controls operating consistently across agile, hybrid, and waterfall delivery models.
Own the SAP role design standard, including role catalog governance, authorization concept, segregation of duties (SoD) frameworks, mitigation controls, and access request workflows ensuring designs are clean core aligned and sustainable across the programme lifecycle.
Partner with SAP Technology leadership and Solution Architects to define and maintain secure solution patterns, hardening standards, and security architecture aligned to the RISE with SAP shared responsibility model and Retail Spine future state architecture.
Provide strategic and operational support across SAP Security and GRC functions, ensuring a secure, compliant, and well-governed technical landscape spanning S/4HANA, BTP, Fiori, and all integrated systems within the RISE with SAP environment.
Support SAP GRC platform operations covering Access Control (AEM, ARM, BRM, EAM), Firefighter and Emergency Access Management processes, periodic access reviews, SoD conflict analysis, and continuous controls monitoring maintaining audit-ready posture at all times.
Own SOX, PCI, GDPR, and internal and external audit readiness for the SAP landscape, including access control evidence management, risk logs, mitigation plans, and remediation tracking in close partnership with Internal Audit, External Audit, and Enterprise InfoSec.
Establish and maintain KPIs and operational metrics for SAP Security and GRC functions including role change cycle time, access request SLA adherence, SoD remediation velocity, and audit finding closure rates and drive continuous improvement through automation and process optimization across IAM and GRC workflows.
Provide security support during go-lives, cutovers, system refreshes, environment provisioning, and major Retail Spine transformation waves ensuring security controls are validated, access is appropriately provisioned, and risk is formally accepted or mitigated prior to each milestone.
Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field. Master's degree in Cybersecurity, Technology Management, or related discipline.
10+ years of experience in SAP Security and SAP GRC Access Control. Strong hands on experience with SAP role design, SoD, Firefighter, GRC Access Control, and audit/compliance frameworks. Experience partnering with System Integrators and managing multi vendor delivery models. Experience supporting large scale SAP transformations, including S/4HANA migrations or RISE with SAP models. Background in retail, consumer goods, or other high volume transaction environments.
Working knowledge of SAP S/4HANA, HANA, Fiori, SAP BTP, and integrated security architecture. Strong understanding of SOX, PCI, GDPR, and enterprise security standards. Knowledge of identity governance (IGA), privileged access management (PAM), and cloud security patterns.
SAP or security certifications (e.g., SAP Security, SAP GRC, CISM, CISSP, CISA).
Excellent communication, stakeholder engagement, and leadership skills.
Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field.
10+ years of experience in SAP Security and SAP GRC Access Control.
Strong hands on experience with SAP role design, SoD, Firefighter, GRC Access Control, and audit/compliance frameworks.
Working knowledge of SAP S/4HANA, HANA, Fiori, SAP BTP, and integrated security architecture.
Experience partnering with System Integrators and managing multi vendor delivery models.
Strong understanding of SOX, PCI, GDPR, and enterprise security standards.
Master's degree in Cybersecurity, Technology Management, or related discipline.
Experience supporting large scale SAP transformations, including S/4HANA migrations or RISE with SAP models.
Knowledge of identity governance (IGA), privileged access management (PAM), and cloud security patterns.
Background in retail, consumer goods, or other high volume transaction environments.
Ahold Delhaize USA, a division of global food retailer Ahold Delhaize, is part of the U.S. family of brands, which also includes five leading omnichannel grocery brands – Food Lion, Giant Food, The GIANT Company, Hannaford and Stop & Shop. Ahold Delhaize USA associates support the brands with a wide range of services, including Finance, Legal, Sustainability, Commercial, Digital and E-commerce, Technology and more. Join our Talent Community to stay updated on opportunities with Ahold Delhaize USA. You’ll be the first to know about new positions that match your career aspirations. To join, click here: Talent Community - Ahold Delhaize USA (careerswithus.com) .
At Ahold Delhaize USA, we provide services to one of the largest portfolios of grocery companies in the nation, and we're actively seeking top talent.
Our team shares a common motivation to drive change, take ownership and enable our brands to better care for their customers. We thrive on supporting great local grocery brands and their strategies. Our associates are the heartbeat of our organization. We are committed to offering a welcoming work environment where all associates can succeed and thrive. Guided by our values of courage, care, teamwork, integrity (and even a little humor), we are dedicated to being a great place to work. We believe in collaboration, curiosity, and continuous learning in all that we think, create and do. While building a culture where personal and professional growth are just as important as business growth, we invest in our people, empowering them to learn, grow and deliver at all levels of the business. Learn More About Our Benefits - Click Here
Ahold Delhaize USA is an equal opportunity employer.
Under the Federal Transparency in Coverage rule, group health plans are required to make publicly available machine-readable files that include in-network rates and out-of-network allowed amounts and billed charges. Click here to view the in-network rates and out-of-network allowed amounts and billed charges for health benefits offered by Ahold Delhaize USA.
Our employees and prospective employees are treated with respect and dignity. As an equal opportunity employer, we comply with all applicable federal, state and local laws. Qualified applicants are considered without regard to sex, race, color, ancestry, national origin, citizenship status, religion, age, marital status (including civil unions), military service, veteran status, pregnancy (including childbirth and related medical conditions), genetic information, sexual orientation, gender identity, legally recognized disability, domestic violence victim status or any other characteristic protected by law.
We provide reasonable accommodations to applicants and employees with disabilities. If you have a disability and require assistance in the application process, please contact our Talent Acquisition Department at tad@adusa.com.
The U.S. service division for a global grocery retailer.
Visit company websiteJobs and hiring trendsFull-time
Senior · 10+ years experience
Onsite
Apply faster on company sites with our extension.