Costco
Security Engineer - SAP GRC
Issaquah, WA
Dec 28, 2024
Full-time
Full Job Description

Costco IT is responsible for the technical future of Costco Wholesale, the third largest retailer in the world with wholesale operations in fourteen countries. Despite our size and explosive international expansion, we continue to provide a family, employee centric atmosphere in which our employees thrive and succeed. As proof, Costco ranks eighth in Forbes “World’s Best Employers”.

This is an environment unlike anything in the high-tech world and the secret of Costco’s success is its culture. The value Costco puts on its employees is well documented in articles from a variety of publishers including Bloomberg and Forbes. Our employees and our members come FIRST. Costco is well known for its generosity and community service and has won many awards for its philanthropy. The company joins with its employees to take an active role in volunteering by sponsoring many opportunities to help others.

Come join the Costco Wholesale IT family. Costco IT is a dynamic, fast-paced environment, working through exciting transformation efforts. We are building the next generation retail environment where you will be surrounded by dedicated and highly professional employees.

SAP GRC Engineer supports the values and business goals as they relate to legal, ethical, and regulatory obligations; protect privacy; and maintain a secure technology environment. SAP GRC Engineers develop and execute security controls, defenses, and countermeasures to intercept and prevent internal/external attacks, infiltration of company data, and compromising of systems and accounts. SAP GRC Engineers research attempted/successful efforts to compromise systems security; design countermeasures; implement and maintain physical, technical, and administrative security controls; and provide information to management regarding the negative impact to the business.

The SAP GRC Engineers are responsible for the creation and maintenance of General IT control objectives in the area of SAP GRC. This position will be responsible for ensuring that all SAP GRC IT control objectives are in compliance and running to full efficiency. In addition, this role will assist with the daily and monthly reporting of SOD (Segregation of Duties) activities from SAP GRC in support of meeting applicable compliance objectives. This is a cross-functional role, working closely with the SAP Security team and other functional teams to ensure security requirements and solutions meet compliance objectives.

If you want to be a part of one of the worldwide BEST companies “to work for”, simply apply and let your career be reimagined.

ROLE

● Provides GRC, security, and technical expertise to support the development of GRC objects to satisfy business requirements.

● Analyzes and administers GRC policies to control physical and virtual system access.

● Identifies and investigates GRC issues and develops solutions that address compliance requirements that

can/do impact GRC and security.

● Identifies, develops, and implements mechanisms to detect incidents in order to enhance compliance and support of the standards and procedures.

● Assesses business role requirements, reviews authorization roles, and supports authorizations.

● Demonstrates a comprehensive skill set with testing authorizations for multiple environments and coordinates testing with business/technical users.

● Validates system configurations to ensure the safety of information systems assets and protects information systems from intentional or inadvertent access or destruction.

● Implements best practice when applying knowledge of information systems security standards/practices (e.g. access control and system hardening, system audit and log file monitoring, security policies, and incident handling).

● Identifies GRC gaps that expose Costco to potential exploit and develop short- and long-term prioritized remediation to address those gaps.

● Determines strategy and protocol for network behavior, analysis techniques, and tool implementation.

● Creates dashboards, configures alerts, implements and supports security software platforms, and monitors tools/apps.

● Identifies opportunities for streamlining and increasing effectiveness through continuous process improvement.

● Implements practices, processes, and procedures consistent with Costco's information security policy and IT standards.

● Develops and documents GRC events and incident handling procedures into Playbooks.

● Ensures that incident documentation is comprehensive, accurate, and complete.

● Triages, prioritizes, investigates, and coordinates security events and incident handling activities.

● Creates and/or remediates GITC (General IT Controls) in support of meeting audit objectives for all SAP modules and their supporting Databases, within the Costco SAP landscape (i.e. Finance, Retail, Warehouse Management, Payroll, HANA, etc.).

● Designs IT testing procedures to identify and evaluate risk exposures and determine the effectiveness and efficiency of controls.

● Assists with the creation of effective remediation solutions and/or exception documentation where applicable.

● Serves as the subject matter expert and point of contact to Internal and External Auditors.

● Assists project teams with creation and implementation of IT controls objectives and integration into SAP-GRC.

● Assists with the successful completion of the quarterly UAR (User Access Review) audit process.

● Collaborates with Internal Audit in developing, testing, and devising solutions to effectively meet applicable IT control objectives.

● Takes responsibility for continued personal growth in the areas of technology, business knowledge, Costco policies, and platforms.

● Participates in team activities and team planning in regards to improving team skills, awareness, and quality of work.

REQUIRED

● Minimum of 12 years’ of experience of SAP GRC Access 10.0 and or 12.0 with expertise using the following modules: Account Request Management (ARM), Access Risk Analysis (ARA), Emergency Access Management (EAM), User Access Review (UAR), Process Control (PC), SAP ETD.

● Minimum of 7 years’ work experience in IT Risk Management, SOX compliance, and/or auditing with a strong background in IT controls.

● Minimum of 7 years’ of experience with SAP Security across various applications, including but not limited to, S/4 HANA, ECC, BW, MDG, Fiori, PI/PO, eWM, and Solution Manager.

● Minimum of 7 years’ experience with SOD conflict resolution.

● Direct “hands-on” experience in IT audits and functional experience using SAP GRC.

● Understanding of SAP cloud security.

● Strong understanding of Sarbanes-Oxley (SOX) and other compliance requirements that may impact controls.

● Expertise in working with internal and external auditors.

● Experience developing SAP GRC solutions that address Sarbanes-Oxley requirements.

● Effective communication and technical leadership; ability to fluently speak both technical and business language interchangeably.

● Ability to effectively mentor other team members on SAP compliance.

● Experience in successful project implementation and follow-up; strong time management skills.

● Strong conceptual, analytical, problem-solving, troubleshooting, and resolution skills.

● Ability to monitor and manage the progress of tasks and work independently.

● Ability to design, develop, and maintain SAP user management and security architecture across SAP environments, including hands-on role design and build across a number of complex SAP applications and databases.

● Scheduling flexibility to meet the needs of the business, including 24x7 on call rotational support.

Recommended

● Bachelor’s degree in Accounting, Business, Information Technology, or Computer Science preferred.

● Documentation and presentation skills catered to a diverse technical and business audience.

● Technical knowledge of SAP landscapes and roadmaps.

● Proficient in Google Workspace applications, including Sheets, Docs, Slides, and Gmail.

Required Documents

● Cover Letter

● Resume

California applicants, please click here to review the Costco Applicant Privacy Notice.

Pay Range:

Level Sr - $150,000 - $190,000, Bonus and Restricted Stock Unit (RSU) eligible

We offer a comprehensive package of benefits including paid time off, health benefits - medical/dental/vision/hearing aid/pharmacy/behavioral health/employee assistance, health care reimbursement account, dependent care assistance plan, short-term disability and long-term disability insurance, AD&D insurance, life insurance, 401(k), stock purchase plan to eligible employees.

Costco is committed to a diverse and inclusive workplace. Costco is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or any other legally protected status. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to IT-Recruiting@costco.com

If hired, you will be required to provide proof of authorization to work in the United States.

PDN-9dd46718-3118-4d44-9387-19c0e3242516
Job Information
Job Category:
Engineering
Spotlight Employer
Related jobs
Copy Editor
Lee Enterprises Inc
Night-Weekend EditorThe award-winning Omaha World-Herald is seeking a motivated and exacting editor to ensure high-quality content standards are met through the evening and on weekends. This position...
Dec 28, 2024
Omaha, NE
250 odell school rd, Concord, NC, 28027 What's the Job? Ready to accelerate your career while helping our customers move forward? As a Technician at Penske, you'll do exactly that. Here, you'll do pre...
Dec 28, 2024
CONCORD, NC
1326 w craighead rd charlotte, NC, 28206 Shift diff: 2.50 and 3.50 Position Summary: A Penske Refrigeration Technician will diagnose, overhaul, adjust, and repair all series of motor truck and trailer...
Dec 28, 2024
CHARLOTTE, NC
©2024 Latinx in Tech.
Powered by TalentAlly.
Apply for this job
Security Engineer - SAP GRC
Costco
Issaquah, WA
Dec 28, 2024
Full-time
Your Information
First Name *
Last Name *
Email Address *
Zip Code *
Password *
Confirm Password *
Create your Profile from your Resume
By clicking the Apply button, you agree to the terms of use and privacy policy.
Continue to Apply

Costco would like you to finish the application on their website.

Ace your interview with
AI-powered interview practice

Get comfortable talking to hiring managers, receive personalized feedback on areas for improvement, sharpen your ability to answer the most common questions, and build confidence in formulating strong responses on the spot. Click the button below to begin your three free virtual interviews!