In my previous role I owned EAM for SAP GRC across a 12,000-user landscape. I ran the Firefighter provisioning process end-to-end, enforcing a 4-eye approval and automated expiry so temporary access never stayed open. I set a KPI that 100% of Firefighter sessions be reviewed within 48 hours and built a 3-person rotation to hit that SLA. We automated log aggregation and alerts into our ticketing system so any critical activity generated a remediation ticket within 24 hours; lower-risk findings went into a weekly batch. Over six months the combination of automation and the rotation reduced open remediation items from 18 to 2 (89% drop) and audit exceptions to zero. Everything was recorded in Jira and our control repository and I routinely produced evidence packages for SOX and external auditors.
Get AI-powered feedback on your answer and improve your skills
Takes 5-10 minutes