
Head Governance Risk
2 days ago
Direct message the job poster from Gatronova
Position Summary:
We are seeking an experienced and visionary Head of Governance, Risk, and Compliance (GRC) to lead and strengthen the organization's SAP GRC framework and enterprise risk posture. This role is responsible for overseeing access control governance, segregation of duties (SoD), role design, SAP licensing compliance, user provisioning, and audit coordination. The incumbent will manage a dedicated GRC team, collaborate cross-functionally with business units, and ensure that all SAP access governance activities align with internal controls, data privacy regulations, and strategic business goals.
Key Responsibilities:
a) SAP GRC Governance
- Lead the enterprise-wide SAP GRC Access Control strategy, including ARA, ARM, BRM, and EAM modules.
- Oversee configuration, maintenance, and ongoing support of GRC tools.
- Ensure consistent GRC practices across the SAP ecosystem.
b) Access Risk Management
- Identify and mitigate Segregation of Duties (SoD) and critical access risks.
- Execute SoD risk assessments for new and existing roles.
- Provide remediation plans and support integration of risk management into broader business controls.
c) Role Design & Governance
- Guide the design and maintenance of SAP roles in compliance with internal policies.
- Work with functional/technical teams to ensure compliant and efficient role structures in S/4HANA, BW, etc.
d) Access Provisioning
- Review and approve SAP user access requests via ARM.
- Ensure effective management of automated workflows for provisioning and deprovisioning.
e) Limit of Authority Matrix (LOAM)
- Develop and manage LOAM for all business units.
- Ensure LOAM is reflected in SAP controls and workflows, enabling delegated authority tracking and enforcement.
f) SAP License Monitoring
- Monitor SAP license consumption and ensure adherence to license quotas.
- Lead optimization strategies for license usage.
g) SAP ID Usage
- Regularly analyze user activity and deactivate unused or low-utilization IDs.
- Implement measures to optimize license usage across the business.
h) UI Masking
- Oversee the implementation of UI Masking in SAP to protect sensitive data and enhance compliance with data privacy regulations.
i) Audit Compliance
- Act as the key liaison with internal and external auditors for all SAP access-related audits.
- Provide required evidence and oversee closure of audit findings.
j) User Access Reviews
- Manage periodic user access reviews, emergency access audits, and recertification exercises with full audit trails.
k) Cross-Functional Collaboration
- Partner with Finance, Operations, Manufacturing, IT, and Compliance to ensure business access needs are balanced with security and risk requirements.
- Investigate and resolve SAP access-related security incidents in collaboration with stakeholders.
- Lead and develop a high-performing GRC team.
- Promote a culture of accountability, transparency, and continuous improvement.
- Develop and deliver training programs for end users, role owners, and approvers on GRC tools and access policies.
o) Reporting
- Deliver executive-level dashboards and risk reports to senior leadership and the Chief Internal Auditor.
p) Talent Management
- Support team development through talent acquisition, training, performance management, and succession planning.
Qualifications & Experience:
- Education: Bachelor's or Master's degree in Information Systems, IT Security, Risk Management, or a related field. Relevant certifications are highly preferred.
- Experience:
- Minimum 10 years of progressive experience in IT governance, risk management, compliance, and SAP security/GRC.
- At least 3–5 years in a leadership or managerial capacity with enterprise-wide SAP GRC responsibility.
- Technical Proficiency:
- Strong hands-on expertise in SAP GRC Access Control modules (ARA, ARM, BRM, EAM), S/4HANA, BW/4HANA.
- Solid understanding of LOAM, UI Masking, SAP licensing, and access risk reporting.
- Leadership Skills:
- Proven ability to lead cross-functional teams, manage change, and align IT controls with business priorities.
- Strong decision-making, stakeholder engagement, and incident response capabilities.
- Seniority levelMid-Senior level
- Employment typeFull-time
- Job functionManufacturing, Management, and Consulting
- IndustriesManufacturing, IT Services and IT Consulting, and Human Resources Services
Referrals increase your chances of interviewing at Gatronova by 2x
Get notified about new Head Risk Compliance jobs in Karachi Division, Sindh, Pakistan.
EVP, Head of Process Governance & Operational Risk (Mashreq Digital Bank Pakistan)Karachi Division, Sindh, Pakistan 6 hours ago
Karachi Division, Sindh, Pakistan 4 months ago
We're unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-Ljbffr-
IT Governance Risk Manager
2 days ago
Karachi, Sindh, Pakistan beBee Careers Full timeAs a key member of the organization's leadership team, you will play a pivotal role in overseeing the development and implementation of the SAP GRC framework. This critical position requires an individual with extensive experience in IT governance, risk management, and compliance.Job Description
-
IT Governance and Risk Analyst
2 weeks ago
Karachi, Sindh, Pakistan beBee Careers Full timeSeeking a skilled professional to support the implementation and management of Business Continuity Management Systems (BCMS) in line with ISO 22301 standards.Key Responsibilities:Implement and review ISO 22301-based BCMS.Support BIA and risk assessment exercises.Document business continuity and disaster recovery plans.Participate in testing and simulation...
-
Karachi, Sindh, Pakistan Standard Chartered Full timePress Tab to Move to Skip to Content LinkChief Compliance Officer, Head Conduct Financial Crime Risk Governance, PakistanArea of interest: Governance, Risk Management & ComplianceManaging the Compliance, Financial Crime and Conduct Risk (CFCR) function in Pakistan. This includes oversight of Conduct, Financial Crime and Compliance related matters in...
-
Head- Risk Management
3 weeks ago
Karachi, Sindh, Pakistan Asaan Ghar Finance Ltd Full timeHead - Risk Management Department (HRMD) is responsible for analysing and assessing the risks associated with mortgage lending activities, ensuring the lender's financial stability by mitigating potential losses. They evaluate the creditworthiness of borrowers, monitor portfolio performance, and implement strategies to manage credit risk, including credit...
-
Governance and Control Expert
2 weeks ago
Karachi, Sindh, Pakistan beBee Careers Full timeSenior Manager - Governance and ControlThe Senior Manager - Governance and Control will be responsible for ensuring that all operational processes comply with bank's risk and compliance procedures. This role requires a thorough understanding of governance frameworks, control environments, and the ability to develop and implement effective risk management...
-
IT Governance Manager
1 week ago
Karachi, Sindh, Pakistan beBee Careers Full timeJob Title: IT Governance ManagerWe are seeking a skilled and experienced IT Governance Manager to support our organization in performing risk management, internal controls, and governance of Information Technology systems and business applications.This role is responsible for supporting senior management in developing, managing, and executing the audit plan...
-
Head of Risk and Compliance Unit
2 weeks ago
Karachi, Sindh, Pakistan beBee Careers Full timeHead of Risk and Compliance UnitWe are seeking a highly skilled professional to lead our risk and compliance unit, ensuring effective management of risks and adherence to regulatory requirements.ResponsibilitiesThe successful candidate will be responsible for:Leading the development, implementation, and management of the University's risk management and...
-
Cybersecurity and IT Governance Specialist
2 weeks ago
Karachi, Sindh, Pakistan beBee Careers Full timeWe are looking for an experienced IT Professional with expertise in IT Governance, Risk, and Compliance (IT GRC). The ideal candidate will have a proven track record of developing and implementing IT governance frameworks based on COBIT, NIST, and other best practices. Key responsibilities include conducting IT risk assessments, defining risk treatment...
-
IAM Governance Manager
2 weeks ago
Karachi, Sindh, Pakistan beBee Careers Full timeIAM Governance RoleThe ideal candidate will have 3-5 years of hands-on experience in IAM Governance, focusing on governance, risk management, and compliance.
-
IAM Governance Manager
1 week ago
Karachi, Sindh, Pakistan Mashreq Full timeIAM Governance Manager (Mashreq Global Network Pakistan)IAM Governance Manager (Mashreq Global Network Pakistan)Get AI-powered advice on this job and more exclusive features.Direct message the job poster from MashreqTalent Acquisition | Diversity and Inclusion | HR Generalist | Technical Recruitment | Executive SearchJob Description:We are seeking a detail...