Summary
Overview
Work History
Education
Skills
Accomplishments
Current Company Start Date
Additional Information
Current Company End Date
Industry Exposure
Sap Applications
Tools And O S
Projects History
Current Company
Personal Information
Timeline
Generic

Surbhi Mishra

Pune,MH

Summary

IT professional with 13+ years of experience developing and implementing security solutions in fast-paced environments. Skilled in SAP Security and GRC with proven history of delivering exceptional risk management support.

Overview

14
14
years of professional experience

Work History

SAP Security and GRC Lead

Barclays Global Service Centre
03.2013 - Current
  • Is SAP Consultant - ERP currently working with Barclays Technology Centre India & has completed total 13+ years in SAP Security & GRC AC
  • Having vast experience in managing and supporting SAP R/3, HR, SRM, BI, and Portal Security along with SAP GRC Access Control (12) in various SAP landscapes.
  • Streamlined user access administration through automation of SAP security processes.
  • Conducted thorough risk assessments to identify gaps in existing SAP security strategies and proposed actionable solutions for improvement.
  • Provided expert guidance on SAP Security, advising management on proper protocols and measures to protect sensitive data.
  • Liaised closely with auditors during annual reviews, providing necessary documentation as evidence of adherence to established security practices.
  • Fostered culture of continuous improvement in realm of information security through ongoing professional development opportunities such as workshops, conferences, and certification programs.
  • Assisted in successful migration of legacy systems to new SAP environments while maintaining strict security standards.
  • Enhanced system security by implementing SAP role-based access controls and user provisioning.
  • Ensured compliance with industry regulations by staying up-to-date on latest SAP security best practices.
  • Acted as primary point of contact for all SAP security-related inquiries, providing prompt and reliable support to internal stakeholders.
  • Collaborated with cross-functional teams to develop comprehensive security policies and procedures.
  • Reduced risk of data breaches with regular security audits and vulnerability assessments.
  • Developed customized training programs for end-users, promoting awareness of information security issues within organization.
  • Managed access rights for various user groups in complex organizational hierarchy, ensuring appropriate levels of authorization were granted while minimizing risk of unauthorized data access.
  • Established robust identity management process to streamline user provisioning and de-provisioning workflows effectively.
  • Performed risk analyses to identify appropriate security countermeasures.

SAP Consultant - ERP

IBM India Pvt. Ltd
01.2010 - 02.2013
  • Security profile maintenance across SAP system landscape based on business rules.
  • User maintenance across all SAP landscape via SU01 and SU10.
  • Creating roles and position via PFCG for providing authorization to user within their scope.
  • Updating transactions via SU24 for maintaining standard values of authorization object.
  • Utilizing system trace (ST01) and SU53 to analyze and fix Problems related to authorization.
  • Transport Management using TMS worklist for Dev to QA to PRD, Also doing Transport Production Build – Weekly as well as Monthly which includes Non-Routine Transport Requests.
  • Running PFUD for updating User Master Records on daily basis in all Systems.
  • Providing Temporary Access, Emergency Access & Configuration of ID's based on Requests.
  • Closed coordination with functional team related to role based transaction authorization verification.
  • Coordination with Business lead for the business critical requests, approvals.
  • Queue manager (New Scale) allocating Tasks in offshore team members, Mentoring team members and organizing.
  • Training within the team member to upscale the performance.

Education

Bachelor of Engineering (Hons.) - Computer Science

University of Rajasthan
2009

Skills

  • Business process understanding
  • Incident Response Handling
  • Role Design Expertise
  • Identity Management Integration
  • ITIL Framework Familiarity
  • Segregation of Duties Analysis
  • SAP Fiori Security
  • GRC Access Control
  • SAP Authorization Management
  • SAP Security Architecture
  • Application Security Best Practices
  • Security Audit Compliance

Accomplishments

  • Received 10K award money for Top performer award.
  • Received Spot award for saving 20k+ funds in license renewal.
  • Received Excellence award and 5K prize money as recognition.
  • Received 'Best of IBM' Award for exceptional performance in IBM.
  • ITIL Foundation Certified.

Current Company Start Date

03/2013

Additional Information

13+ years

Current Company End Date

Present

Industry Exposure

  • Banking
  • FMCG

Sap Applications

  • SAP ECC
  • GRC 12, 10.0 & 5.3
  • SAP HR
  • SRM 7
  • BW 3.5
  • BI 7.3
  • SAP EP

Tools And O S

  • GRC AC 12.0, 10, 5.3 (ARA, EAM)
  • MS Office (Excel, Word, PowerPoint)
  • MS Visio
  • MS Project
  • Windows 2000 / XP / 7 / 8

Projects History

  • SAP Security and GRC and Sox audit management, 04/2021, Present

Configured several GRC configurations connectors for ARA and EAM functionality including SAP S4Hana and BW4/HANA system. Configured Fiori rule sets in accordance with auditors recommendations. Performed several clean-up activities in alignment with business for security re-design. Worked on configuring GRC access workflow request for secret data roles in S4 Hana. Worked on SAC security for role implementation. Worked with IAM teams to sync SAP request workflow for seven production environments with Request portal (Barclays tool), Worked on BRID migration project where 2k+ user login account were migrated from windows login name to BRIDs. SPOC for RFT level SOx audits (auditor: KPMG, BDO IT), worked with Central team for approvals and scope for audit, coordinated with several teams across Finance tower to work on controls and gather evidences, relevancy of controls, worked on inefficiencies and escalations for end-to-end closure. Presented audit data to management and kept numbers within threshold.

  • SAP GRC Support and License Management, 07/2017, 03/2021

Experienced in post implementation configurations and Support of SAP GRC Access Control 10.0 module -Access Risk Analysis (ARA), Emergency Access Management (EAM). Experience in ARA (GRC 10.0) tool for SOD Analysis, Experience in EAM (GRC 10.0) tool for Emergency access management with Firefighter owner/controller configuration and firefighter id assignment. Hands-on experience on GRC Rule set creation/modification/upload/download and SOD clean up. Have a good planning experience working with the compliance team, SOX group for implementing business Mitigating Controls., Firsthand experience with Coupa (procurement tool for Barclays). Worked on raising requisitions and handling all approvals. Communicating PO to vendors and working with vendors for invoice review. Managed end to end software license renewal for group RFT including 60+ application renewals. Negotiated with vendors for better deals for renewals and handling budget allocated to RTB for renewals. Saved 20K+ pound over a period of 6 months.

  • SAP HR & SRM Support, 03/2014, 06/2017

Providing L2 technical support for SAP HR, SRM, BI & SAP EP security. Managing end to end UAM toolset. (An Automation tool developed by client to maintain complete user management in HR system). Completed major HR remediation project and achieved 0 Critical violations. Implemented FF concept and created various documents for functional team for using FF tool. Involved in daily and weekly projects with project managers and client leads. Working on internal system audits and health checks, to comply with the audit standards of PwC. Involved in various country specific roll-outs for HR and SRM 7 security & authorization work. Creating various manuals and housekeeping security tasks.

  • ECC Support, 01/2010, 02/2013

Security profile maintenance across SAP system landscape based on business rules. User maintenance across all SAP landscape via SU01 and SU10. Creating roles and position via PFCG for providing authorization to user within their scope. Updating transactions via SU24 for maintaining standard values of authorization object. Utilizing system trace (ST01) and SU53 to analyze and fix Problems related to authorization. Transport Management using TMS worklist for Dev to QA to PRD, Also doing Transport Production Build - Weekly as well as Monthly which includes Non-Routine Transport Requests. Running PFUD for updating User Master Records on daily basis in all Systems. Providing Temporary Access, Emergency Access & Configuration of ID's based on Requests. Closed coordination with functional team related to role based transaction authorization verification. Coordination with Business lead for the business critical requests, approvals. Queue manager (New Scale) allocating Tasks in offshore team members, Mentoring team members and organizing Training within the team member to upscale the performance.

Current Company

Barclays Technology Centre India

Personal Information

Date of Birth: 11/24/1986

Timeline

SAP Security and GRC Lead

Barclays Global Service Centre
03.2013 - Current

SAP Consultant - ERP

IBM India Pvt. Ltd
01.2010 - 02.2013

Bachelor of Engineering (Hons.) - Computer Science

University of Rajasthan
Surbhi Mishra