Job Information
About the Position
Introduction
Werfen is a growing, family-owned, innovative company founded in 1966 in Barcelona, Spain. We are a worldwide leader in specialized diagnostics in the areas of Hemostasis, Acute Care Diagnostics, Transfusion, Autoimmunity, and Transplant. Through our Original Equipment Manufacturing (OEM) business line, we research, develop, and manufacture customized assays and biomaterials. We operate directly in 30 countries, and in more than 100 territories through distributors. Our Headquarters and Technology Centers are located in the US and Europe, and our workforce is more than 7,000 strong.
Overview
We seek an experienced and technically proficient Access Control Manager to oversee user access management and security controls for SAP systems and Microsoft Active Directory environments. This role is critical in ensuring secure and compliant access to enterprise systems, supporting internal audit requirements, and driving process improvements in identity and access governance.
Responsibilities
Key Accountabilities
- Lead and manage all aspects of user access control for SAP and Active Directory environments across the organization.
- Design, implement, and maintain role-based access control (RBAC) models aligned with business needs and segregation of duties (SoD) policies.
- Collaborate with IT, audit, HR, and business teams to manage user provisioning, deprovisioning, and access reviews.
- Monitor and ensure compliance with regulatory requirements such as SOX, GDPR, and internal IT security policies.
- Conduct regular audits of user roles and permissions in SAP and Active Directory; remediate access risks and violations.
- Develop and maintain access control documentation, including policies, standards, and procedures.
- Manage and support access management tools and integrations (e.g., SAP GRC, Azure AD, IAM solutions).
- Provide expertise and technical support during system upgrades, migrations, and security incident investigations.
- Train and mentor junior staff in access control best practices and procedures.
Minimum Knowledge & Experience required for the position:
- Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field.
- Minimum 5 years of experience managing user access and security in SAP and Microsoft Active Directory environments.
- In-depth technical knowledge of SAP security concepts (SAP GRC, SU01, PFCG, role creation) and Active Directory group policy management.
- Strong understanding of identity and access management (IAM) principles and SoD frameworks.
- Experience with compliance frameworks (e.g., SOX, GDPR, ISO 27001).
- Hands-on experience with tools such as SAP GRC, Azure Active Directory, Microsoft Identity Manager, or similar.
- Excellent analytical, problem-solving, and communication skills.
- Industry certifications such as CISSP, CISM, SAP Certified Technology Associate – System Security, or Microsoft Certified: Identity and Access Administrator Associate are a plus.
Qualifications
Minimum Knowledge & Experience required for the position:
- Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field.
- Minimum 5 years of experience managing user access and security in SAP and Microsoft Active Directory environments.
- In-depth technical knowledge of SAP security concepts (SAP GRC, SU01, PFCG, role creation) and Active Directory group policy management.
- Strong understanding of identity and access management (IAM) principles and SoD frameworks.
- Experience with compliance frameworks (e.g., SOX, GDPR, ISO 27001).
- Hands-on experience with tools such as SAP GRC, Azure Active Directory, Microsoft Identity Manager, or similar.
- Excellent analytical, problem-solving, and communication skills.
- Industry certifications such as CISSP, CISM, SAP Certified Technology Associate – System Security, or Microsoft Certified: Identity and Access Administrator Associate are a plus.
Skills & Capabilities:
- Knowledge of single sign-on (SSO), multi-factor authentication (MFA), and federation technologies (SAML, OAuth).
- Experience with automation and scripting for access management (e.g., PowerShell, Python).
- Exposure to cloud platforms (e.g., Microsoft Azure, AWS) access control methodologies.
Travel requirements:
N/A
If you are interested in constantly learning and being challenged on a daily basis, we encourage you to submit your resume or CV.
Werfen appreciates and values diversity. We are an Equal Opportunity/Affirmative Action Employer M/F/D/V.
www.werfen.com