- Location
- Barcelona (Head Office), Spain
- Type
- Full-time
- Seniority
- Senior
- Source
- Workday
Description
About the Role
As Senior Manager Access Governance, you will join the internal IT Compliance & Risk Management Team at Fresenius Kabi and help ensure that access across business-critical applications, identity systems, and SAP environments is secure, compliant, and fully auditable.
The role brings together enterprise access governance and SAP authorization governance in a regulated environment. Working closely with IT, information security, risk, compliance, and business functions, you will support a consistent, risk-based approach that balances operational needs with internal policies, audit expectations, and applicable regulatory requirements, including GxP where relevant.
Your Responsibilities
- In this role, you will play an important part in developing and maintaining our enterprise access governance framework across business-critical applications, IT platforms, identity systems, and SAP environments. Your work will cover the relevant policies, standards, role design principles, approval rules, and access lifecycle controls.
- One of your core responsibilities will be to ensure that access is managed consistently throughout its full lifecycle. This includes access requests, approvals, provisioning, user lifecycle management, recertification, privileged and emergency access, segregation of duties (SoD), mitigation controls, and remediation tracking.
- SAP authorization governance will be a central part of your role. You will work across SAP ECC, SAP S/4HANA, and related SAP landscapes and oversee SAP role and authorization concepts as well as the relevant SAP GRC access control processes, including access risk analysis, access request & emergency access management, business bole management, and SoD risk management.
- When complex or high-risk access situations arise, you will assess them carefully against the principles of least privilege, need-to-know, traceability, auditability, and segregation of duties. You will also coordinate periodic user access, role, privileged access, and mitigation control reviews and ensure that findings and corrective actions are followed through.
- Your expertise will support internal and external audits through clear governance documentation, reliable evidence, and well-founded explanations of access controls. At the same time, you will provide practical guidance and training to role owners, application owners, access approvers, business process owners, and other stakeholders involved in access governance.
- Close collaboration will be essential to your work. You will coordinate with teams across identity and access management, information security, IT operations, SAP, risk, controls, audit, validation, quality, legal, privacy, and compliance, as well as with relevant business stakeholders and external service partners.
- You will also help make access governance more efficient and transparent by improving and automating recurring activities. This work should lead to more consistent role design, higher-quality access requests and approvals, fewer SoD risks and high-risk access violations, and faster remediation of findings. Clear reporting on access risks, compliance metrics, control effectiveness, remediation progress, and audit readiness will create transparency for management.
What You Bring
- You hold a Master’s degree or an equivalent qualification in IT/CS, BA etc.
- You bring several years of relevant experience in identity and access management, access governance, IT compliance or audit, internal controls, SAP Security, SAP authorization governance, or SAP GRC. This includes practical experience in regulated enterprise environments and in preparing audit-ready evidence for internal or external audits.
- Your expertise covers role-based access control, identity and user lifecycle management, privileged access, segregation of duties, critical and emergency access, access reviews, and role design.
- Strong knowledge of SAP authorization concepts, SAP ECC, SAP S/4HANA, complex SAP landscapes, and SAP GRC Access Control is essential for this role.
- You understand IT general controls, information security, internal control frameworks, and risk and compliance management. This enables you to assess complex access risks and translate governance or regulatory requirements into practical controls.
- You communicate and present complex topics clearly and work confidently with technical, business, and assurance stakeholders. You can provide functional leadership, influence decisions, and document recommendations accurately. Sound judgment, analytical thinking, and a high level of ownership are important parts of how you work.
Additional Experience We Value
- Relevant certifications such as CISA, CISM, CISSP, CRISC, SAP, or identity governance certifications.
- Experience in regulated industries (e.g., life sciences, pharma, healthcare, medical devices) with knowledge of GxP, data integrity, computerized system validation, FDA 21 CFR Part 11, EU GMP Annex 11, SOX-like controls, or GDPR.
- Experience with identity governance, privileged access, and workflow tools (e.g., SailPoint, Microsoft Entra ID, Saviynt, ServiceNow, CyberArk) and SAP security solutions (e.g., SAP Fiori, SAP HANA authorizations, SAP Cloud IAG).
Why join our team?
At Fresenius Kabi, compliance and quality are the foundation of our mission to improve patient care worldwide. In this role, you will have a direct impact on the security and reliability of critical IT systems that support our global operations. You will work closely with international teams and contribute to the continuous development of a strong, future oriented compliance landscape.
Ready to join us?
Apply now via our online portal.
#futurefresenius