SAP Access Management Lead

Function:  Technology
Location: 

LND, GB

Work Arrangement:  Hybrid

Position Title: SAP Access Management Lead

Location:  Wimbledon (Hybrid)

Reports to: ERP Platform Lead

 

 

ABOUT THE WELLA COMPANY

 

Together, WE enable individuals to look, feel, and be their true selves.

 

Wella Company is one of the world’s leading beauty companies, comprised of a family of iconic brands such as Wella Professionals, Clairol, OPI, Nioxin and ghd. With 6,000 employees globally, presence in over 100 countries, Wella Company and its brands enable consumers to look, feel, and be their true selves. As innovators in the hair and nail industry, Wella Company empowers its people to delight consumers, inspire beauty professionals, engage communities, and deliver sustainable growth to its stakeholders. For additional information about the Wella Company please visit www.wellacompany.com.

 

 

THE ROLE

 

The SAP Access Management & Governance Lead is accountable for defining, governing, and continuously improving SAP access management, security governance, and compliance across Wella's global SAP landscape.

This role owns the end-to-end operating model for SAP access management, ensuring that the right individuals have the right access at the right time while maintaining compliance with regulatory and audit requirements. The role is responsible for Segregation of Duties (SoD), access governance, approval workflows, role ownership, audit readiness, risk management, and the overall maturity of SAP security processes.

Working closely with Business Owners, Internal Audit, Cybersecurity, Enterprise Architecture, SAP Basis, and strategic service partners, the SAP Access Management & Governance Lead will establish sustainable governance processes, drive security transformation initiatives, and ensure Wella maintains a secure, scalable, and audit-ready SAP environment.

The role combines strategic leadership, governance ownership, and operational oversight and will play a key role in shaping the future SAP security and identity governance landscape at Wella.

 

KEY RESPONSIBILITIES

1. Governance & Strategy

  • Define and own Wella's SAP Access Management operating model.
  • Establish and govern SAP access management policies, standards, and controls.
  • Drive the long-term SAP access governance strategy and roadmap.
  • Act as the design authority for SAP access governance during major transformation programmes and SAP implementations.
  • Define ownership models for SAP roles, business processes, mitigating controls, and approval authorities.
  • Govern access management across Wella's SAP ecosystem including ECC, S/4HANA, SAP BTP, Datasphere, SAC, Ariba, SuccessFactors, Concur, Emarsys, and future SAP platforms.

2. Segregation of Duties (SoD) & Risk Management

  • Own and maintain the global SAP SoD framework.
  • Define governance processes for identifying, approving, mitigating, and monitoring access risks.
  • Partner with business stakeholders to ensure risk acceptance and mitigation processes are effective and documented.
  • Perform regular risk assessments of SAP roles and access models.
  • Drive reduction of access risks and toxic combinations across the SAP landscape.
  • Oversee management of privileged and emergency access, including Firefighter access controls and reviews.

3. Audit, Compliance & Controls

  • Own SAP access-related controls supporting SOX, GDPR, ISO27001 and other regulatory requirements.
  • Act as the primary point of contact for internal and external auditors.
  • Lead remediation of audit findings and compliance gaps.
  • Establish sustainable, audit-ready processes and evidence repositories.
  • Ensure audit evidence can be produced efficiently and consistently.
  • Monitor control effectiveness and drive continuous improvement activities.
  • Prevent repeat audit findings through robust governance and process enhancement.

 
4. Access Request Management & Provisioning

  • Own the design and governance of SAP access request and approval processes.
  • Define approval authorities, role ownership responsibilities, and escalation paths.
  • Ensure end-to-end traceability and auditability of all access requests.
  • Govern Joiner, Mover, Leaver (JML) processes across SAP applications.
  • Oversee provisioning and de-provisioning activities delivered by support partners.
  • Drive automation and simplification of access management processes through workflow and identity governance tools.
  • Ensure timely and accurate access provisioning aligned with agreed service levels.


5. Access Certifications & Role Management

  • Own periodic user access reviews and certifications.
  • Ensure role reviews are performed regularly by designated business owners.
  • Establish governance around role design, naming standards, documentation, and approval processes.
  • Reduce role complexity and promote role standardisation across SAP systems.
  • Ensure clear ownership exists for all SAP roles and access profiles. 


6. Vendor Governance & Service Management

  • Act as service owner for third-party SAP access management and security services.
  • Govern managed service providers, ensuring delivery against SLAs, KPIs, compliance obligations, and contractual commitments.
  • Drive continuous service improvements with strategic partners.
  • Ensure retention of knowledge, process documentation, and governance controls during supplier transitions.
  • Establish clear accountability models between Wella, business stakeholders, and service providers.


7. Security Transformation & Continuous Improvement

  • Lead SAP Identity Governance and Access Management initiatives.
  • Define future-state capabilities leveraging SAP GRC, SAP IAG, SailPoint and related governance technologies.
  • Partner with Cybersecurity and Enterprise Architecture to ensure secure-by-design principles are embedded within SAP programmes.
  • Drive maturity improvements across access governance, compliance, automation, and reporting.
  • Build sustainable operating procedures and governance frameworks that scale with business growth.

8. Leadership & Stakeholder Management

  • Provide leadership and subject matter expertise across all SAP access management activities.
  • Build strong relationships with Business Process Owners, Audit, Cybersecurity, Compliance, HR, and Technology teams.
  • Communicate risks, audit findings, compliance issues, and remediation plans to leadership.
  • Translate technical security concepts into business-focused recommendations.
  • Champion a culture of accountability, governance, and compliance across the organisation.

 

 

ESSENTIAL SKILLS, EXPERIENCE & QUALIFICATIONS

 

Education:

  • Bachelor's Degree in Information Systems, Computer Science, Cyber Security, or related discipline.
  • SAP Security, SAP GRC, SAP IAG, CISSP, CISA, CRISC or equivalent certifications desirable.

Experience:

  • 10+ years' experience in SAP Security, Access Management, Identity Governance, or Risk & Compliance.
  • Proven experience building or transforming SAP access management capabilities within large global organisations.
  • Experience acting as the primary interface for external and internal audits.
  • Proven experience implementing and operating SoD frameworks and access governance controls.
  • Strong understanding of SAP ECC and S/4HANA security concepts.
  • Experience governing outsourced or managed security service providers.
  • Experience supporting SAP transformation programmes, migrations, or cloud adoption initiatives.
  • Experience establishing and driving access management operating models and governance frameworks.

 

 

WHAT WE OFFER

 

  • 25 days holiday + additional day off for your birthday (not including bank holidays)
  • 3 days’ personal leave for your own signification life events
  • 2 paid days off for volunteering/charity work
  • Optional Wella Pension Scheme (8% employer contribution, 3% employee contribution)
  • Optional Family Private Medical Insurance Cover
  • Income Protection
  • Life Insurance (8x base salary up to 2 million payable in the event of your death in service of Wella)
  • Staff Discount (80% of all hair products, 40% OPI, 1 x 50% ghd)
  • EAP (Employee Assistance Program)
  • Enhanced maternity, paternity, and adoption leave
  • Gym Benefits
  • Eye Tests
  • WOW Program (Bonus following exit from KKR, eligible after successful probation. For permanent employees only)
  • Workplace/Nursery Benefits
  • 4 weeks working remotely abroad
  • Early Friday Finish during Summer

 

 

 

EEO OPPORTUNITIES

 

The Wella Company wants to meet the aims and commitments set out in its equality policy. This includes not discriminating under the Equality Act 2010 and building an accurate picture of the make-up of the workforce in encouraging equality and diversity.

We offer equal employment opportunity to qualified individuals without regard to race, religion or belief, color, national origin, age, gender, disability, sexual orientation, gender identity, gender expression, marital or civil partnership, pregnancy and maternity, veteran status, or any other characteristic protected by law. Wella Company with federal and state disability laws and makes reasonable accommodations for applicants and employees with disabilities. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact us at: https://www.wellacompany.com/consumer-affairs

We strongly believe that cultivating a diverse workplace gives a company strength. The combination of unique skills, abilities, experiences and backgrounds creates an environment that produces extraordinary results. EOE Minorities/Females/Protected Veterans/Disabled.

English - Please click on this link to review the Notification of Equal Opportunity Rights poster