|
We are Builders FirstSource, America's largest supplier of building materials, value-added components and building services to the professional market. You'll feel proud of the work you do here every day to transform the future of home building and help make the dream of home ownership more achievable. At BFS, we believe building a successful career is not solely defined by a degree. Your experience, skills, and passion are just as important, if not more so. As such, we are committed to creating a diverse and inclusive workplace that welcomes candidates from all backgrounds and experience levels. Under the direction of the Chief Information Security Officer, the Information Security team is comprised of experienced technology professionals and is responsible for overseeing or managing the following areas: administration of the Security Awareness/Education program, Web Content Filtering, Identity Management, Vulnerability Scanning, scoping Penetration Tests, Governance, Risk and Compliance (GRC) as well as the development and maintenance of corporate IT Security Policies, Standards & Procedures. The SAP Security Lead will provide strategic and operational support to ensure that SAP environments are secure, compliant, and resilient against emerging threats. The SAP Security Lead will prioritize risks, monitor trends, and identify vulnerabilities across SAP S/4HANA and related platforms, ensuring that threats are properly mitigated in collaboration with Information Technology (IT), Implementation Team, External Systems Integrator, Internal Controls, Organization Change Management, and other business units. The role will support and facilitate maturity assessments and operational reviews to demonstrate the efficacy of SAP-specific cybersecurity controls within the broader enterprise applications security program. This includes oversight of segregation of duties (SoD), role-based access controls, and audit readiness for SOX and other regulatory frameworks. The SAP Security Lead will be a key contributor to global business and technology initiatives, integrating security controls across hybrid environments-on-premise, cloud, and SaaS. The SAP Security Lead must have strong oral and written documentation and communication skills with the ability to work with management and auditors concerning IT business controls and procedures. This position should bring prior analytical problem-solving skills, sound judgement, knowledge and expertise in all areas related to SAP Security and GRC in order to provide security by design. In addition, demonstrate a technical background and knowledge of SAP system security processes, such as authentication practices, security administration and familiarity with SAP systems. ESSENTIAL DUTIES AND RESPONSIBILITIES
- Design, implement, and maintain SAP security roles, profiles, and authorizations across SAP modules (e.g., ECC, S/4HANA, BW, HANA, SuccessFactors, Ariba, GRC). Collaborate with business managers to refine or adjust SAP roles
- Lead role design using best practices (e.g., single-role or composite role strategy, least privilege).
- Serve as an SAP Security subject matter expert, providing technical guidance to team members and stakeholders.
- Define security considerations and stage gates for SDLC phases of system implementation (design, testing, implementation, data conversion, data transfer, cutover, post go-live) and monitor adherence with the requirements.
- Design, implement, and enforce API security controls to protect data in transit across internal and external systems.
- Design, implement, and enforce standards for the enterprise authentication architecture for applications, APIs, and services.
- Define and implement authentication standards aligned with Zero Trust and security-by-design principles.
- Troubleshoot user roles, security objects, and authorizations to resolve Segregation of Duties (SOD) conflicts and risks, applying mitigation controls, supervising sensitive access and elevated privileges
- Conduct regular system audits to detect deviations from established standards, procedures, role mappings, and unauthorized system activity. Identify gaps in security administration processes, procedures, and opportunities for improvement
- Configure and utilize a GRC tool to create and modify SAP Security Roles/Profiles. Leverage the GRC tool to validate user role assignments and profile modifications
- Assist the team in performing reviews and monitoring activities using the GRC tool
- Review security patches for SAP landscape applications and conduct security reviews of SAP systems. Resolve technical and complex security-related issues across the SAP landscape.
- Develop Application / ERP security standards, procedures, and checklists for future Mergers and Acquisitions (M&A) activities.
MINIMUM REQUIREMENTS To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required.
- Bachelor's degree in Information Systems, Computer Science, or related field (or equivalent experience).
- 8+ years of experience in analyzing, developing, and maintaining SAP Security including leadership or lead-level responsibility.
- Strong foundation on S/4HANA Security is a prerequisite. Should be able to identify and build portfolios in S/4HANA Security implementation and Conversion topics.
- Strong in Technology security fundamentals and hands on experience on SAP specific products and solutions like SAP GRC suite of products including Access Control, Process Control, Risk Management, Audit Management, Business Integrity Screening, SAP Single Sign-On, SAP Identity Management
- Technical knowledge and experience in SAP Business Technology Platform (BTP) and related solutions like Identity Authentication, Identity Access Governance, and Identity Provisioning is a must
- Expertise in designing and deploying comprehensive security solutions for large corporations using S/4 HANA, ECC, BI/BW, PI/PO, EWM, Solution Manager, and FIORI Gateway
- Strong understanding of IAM concepts, RBAC, least privilege principles, Segregation of Duties and Sarbanes-Oxley regulations related to application security.
- Excellent communication and stakeholder management skills.
- Experience using GRC Tools (SAP GRC, CPGRC, etc.)
- Understanding of UI Masking /Logging and related data privacy requirements including GDPR.
- Proficient project management skills and a collaborative, team-oriented approach.
- General familiarity with SAP modules, including FI, CO, SD, MM, PP, BW, EWM, Hybris, PI/PO, CPI, and portal landscape, is highly preferred.
- Expertise is developing and implementing security standards for system implementations, API management, and M&A activities.
COMPETENCIES
- Evaluates Problems: Evaluates and analyzes different types of information objectively to identify appropriate solutions; writes fluently, establishing the key facts clearly and interprets numerical data effectively.
- Technical Communication/ Presentation: Communicates with clarity and precision, presenting complex information in a concise format that is audience appropriate.
- Adjusting and Driving Change: Takes a positive approach to tackling work and embraces change; invites feedback relating to performance and deals constructively with criticism. Identifies the need for and drives change when required to achieve objectives.
- Focuses on Customers: Understands and anticipates customer needs and takes action to provide high-quality products and services to exceed expectations.
- Demonstrates Business Acumen: Demonstrates working knowledge of market, economic, legal and regulatory environments and how they impact the business.
- Agile Best Practices: Understands how agility is leveraged in IT ways of working. Adopts agile best practices as appropriate throughout the assigned work lifecycle. Responds to feedback quickly based on comments of internal and external customers and needs of the market.
- Bias for Action: Takes initiative and identifies what needs to be done and acts without waiting to be asked. Executes work in a timely manner. Suggests improvements to current ways of working.
BFS COMPETENCIES
- Business and Financial Acumen
- Demonstrates depth of understanding for the P&L and financial analysis
- Teaches business and financial acumen to others.
- Understands KPIs and how BFS makes money.
- Knows the different business segments and how they relate to one another.
- Understands customer sales and engagement.
- Demonstrates functional and/or technical expertise.
- Understands complex issues and demonstrates problem solving skills.
- Understands how to maximize business results regardless of industry cycle.
- Results Driven
- Holds self and others accountable.
- Communicates and sets clear goals with plans to deliver.
- Manages competing priorities effectively.
- Demonstrates appropriate urgency.
- Drives to exceed expectations in alignment with our BFS SPICE values.
- Embraces and follows best practices.
- Demonstrates self-starter, can-do attitude.
- Strategic Thinking and Decision Making
- Leverages resources and teams around them to solve problems and create mutually beneficial outcomes.
- Demonstrates willingness and courage to make tough decisions in a timely manner.
- Balances short-and-long term priorities
- Demonstrates proactive versus reactive thinking.
- Asks questions to identify root cause and analyze situations more accurately.
- Servant Leadership
- Demonstrates humility by putting others first.
- Builds trust-based relationships.
- Leads by example with kindness and respect.
- Collaborates well across all areas of the business.
- Advocates for others
- Actively listens to understand the meaning and intent of what the other person is communicating.
- Demonstrates authenticity and encourages others to do the same.
- Emotional Intelligence
- Demonstrates situational awareness - knows when and how to adjust leadership style in different situations.
- Demonstrates self-awareness - understands strengths and weaknesses.
- Demonstrates empathy - puts themselves in other's shoes.
- Assumes positive intent.
- Develops and Leads Others
- Drives alignment through clear communication of vision, goals, and expectations.
- Invests time on a regular basis in performance feedback and developmental conversations.
- Fosters a respectful and inclusive environment.
- Empowers, motivates, and inspires others.
- Coaches and mentor others for their development.
- Guides and persuades others to deliver positive outcomes.
- Growth Mindset
- Demonstrates a growth mindset; takes appropriate risks, fails fast and forward, learns from mistakes.
- Perseveres and champions growth, even in the face of resistance, ambiguity, or possible failure.
- Thinks like an owner with an entrepreneurial spirit.
- Demonstrates and encourages intellectual curiosity.
- Continuous learner; seeks opportunities and knowledge for personal and professional growth.
- Sees possibilities over problems - actively seeks solutions.
- Innovation
- Encourages out-of-the box thinking to create new ways of doing things.
- Continuously seeks to improve and simplify pain points in the business.
- Anticipates, embraces, and leads change.
- Develops and executes breakthrough strategies.
- Integrity
- Does the right thing even under challenging circumstances?
- Communicates with honesty.
- Consistently treats others fairly and equitably.
- Demonstrates reliability and does what they say they will do.
- Conducts tough conversations and delivers difficult messages with kindness and respect.
WORK ENVIRONMENT / PHYSICAL ACTIVITY The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- Subject to both typical office environment and outside locations with temperature and weather variations.
- Must be able to lift and carry up to 25 pounds.
- Occasional travel may be required.
This position was posted on 5/14/2026 and we anticipate it will be open for a minimum of five days, though it may be open for a longer period. We encourage your prompt application. Successful, innovative, and fulfilling careers are built here, and your professional development is a high priority. We invest in your future through the latest training, tools, and technologies. Highly collaborative, we work together to solve problems and find better ways to continually grow our business and careers every day. You'll be empowered to try new things, gain new experiences, and build a career with unlimited horizons. The scale and depth of resources that being the #1 building materials distributor in the nation provides a variety of opportunities for you to explore - all in a friendly, people-first environment. Join us to be more, do more, and build more, together at BFS. In addition to the base wage listed, this position is also eligible to earn an annual bonus subject to changes in plan design and documents and in accordance with applicable law. Eligibility and the amount of the bonus varies based on overall company success, thresholds met and other terms and conditions of the Company's active bonus policy for the respective year. At Builders FirstSource, we offer competitive, affordable benefits designed to make life better for you and the people you love. Our goal is simple - provide great plans that help you and your family to live happier, healthier and more secure lives. To view all our benefit offerings click here www.bldrbenefits.com. Builders FirstSource is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, protected veteran status or status as an individual with a disability. In compliance with the ADA Amendments Act (ADAAA), if you have a disability and would like to request an accommodation in order to apply for a position with Builders FirstSource, please call (214) 765-3990 or email: ADA.Accommodation@bldr.com. Please do not send resumes to this email address - it is intended only to be used to request an accommodation in submitting an application for a job opening. If there's legally required pay transparency information missing from our job posting, it's not intentional and we'd like to know. To let us know, please email the job title and location to JobPostings@bldr.com. Please do not send resumes to this email address - it is intended only be used to provide a notice of non-compliance. Please note that due to the volume of applications received, we are unable to respond to individual inquiries about the status of your application.
|