Consulting practices
Building and running SAP security and GRC delivery: team design, utilization, solution and pricing models for managed-services bids, and the capability development that keeps a practice sellable.
SAP security and access governance. CISM, CISSP.
Thirty years in SAP security and access governance, from three sides of the table: inside the enterprise, inside four global integrators, and inside two GRC software vendors.
I have spent thirty years on segregation of duties, role design, and access governance in SAP. First owning it inside an enterprise, then building and running delivery organizations at EDS, HP, HPE and DXC, then leading professional services at two GRC software vendors.
That path means I have designed the access model, priced the engagement to fix it, and sat on the buying side deciding whether the proposal was worth it. Most people in this field have done one of those three.
I am currently consulting independently on S/4HANA security, SoD remediation, and GRC Access Control for Fortune 500 and Fortune 1000 manufacturers, and measuring what LLM tooling does to the effort curve on that work.
Building and running SAP security and GRC delivery: team design, utilization, solution and pricing models for managed-services bids, and the capability development that keeps a practice sellable.
Professional services that support the license motion: implementation velocity, expansion inside existing accounts, escalation recovery, and market credibility alongside delivery.
Owning access governance in house: SoD remediation, S/4HANA security workstreams, audit readiness, and knowing what the integrators and vendors quoting you are actually charging for.
Post-S/4HANA migration. Redesigned 1,000+ roles and remediated segregation-of-duties conflicts across the new landscape.
S/4HANA transition. Migrated 600+ roles, including Fiori catalog and space design for the new authorization model.
SAP GRC Access Control optimization across emergency access, risk analysis, and provisioning.
I write about SAP security and access governance on LinkedIn.
devinmcl903@gmail.com linkedin.com/in/devinmclaughlin
Longview, Texas. Open to remote and travel.
Certified Information Security Manager (CISM) and Certified Information Systems Security Professional (CISSP). BBA in Accounting, Texas Tech University.