Pam Leung
Senior SAP Security and IT Governance/Compliance Analyst
- Role
- SAP Security Architect and IT Governance Compliance Lead at Weyerhauser Co
- Location
- Renton, WA, US
- LinkedIn followers
- 500 followers
About Pam Leung
Accomplished SAP Security Architect and IT Governance, Risk, and Compliance (GRC) Lead with a proven track record of driving S4/HANA transformation projects and optimizing complex business processes. Expertise in developing and executing comprehensive programs in security control design, vulnerability management, control frameworks, and policy/standards management. Demonstrated success in global enterprise Audit and Risk Management, SOX IT General Controls, Audit Readiness, and GRC for Fortune 100 companies and the Federal government. In-depth knowledge of industry regulations, including SOX, PCI, SOC, NIST, FedRAMP, CIS, and CMMC, with a strong focus on ensuring data security and achieving full compliance with regulatory standards.
Experience
SAP Security Architect and IT Governance Compliance Lead
Mar 2023 — Present
Engineered and implemented comprehensive security frameworks for SAP and non-SAP applications, focusing on Segregation of Duties (SOD) risk mitigation through detailed role design and the establishment of strategic control frameworks tailored for global enterprise environments- Designed, automated, and standardized security controls across the SAP Product portfolio (GRC, IAG, CIS [IAS & IPS], BTP, SAC, C4C, and Solman ChaRM), incorporating both preventive and detective measures to manage access control and reduce vulnerability exposure proactively- Developed and implemented risk mitigation strategies for SAP ChaRM personas, embedding security controls within change request flows, and ensuring proper Segregation of Duties (SOD) for secure and compliant change management processes. Optimizing the security infrastructure using SAP Cloud Transport Management Service (CTMS), C4C, and S4 Transport Management, while maintaining secure manual processes for change requests- Architected and deployed SOX IT General Controls (ITGC) for SAP S/4 HANA on Azure and SAP cloud applications, designing solutions that ensured secure and compliant infrastructure with a focus on mitigating risks identified during audit reviews. The successful deployment led to the project being nominated for SAP Insider 2025- Led the design, implementation, and continuous improvement of security policies and controls for SAP and non-SAP applications, ensuring the architecture evolved in line with emerging security threats and compliance requirements. Established a framework for periodic reviews, enhancing security responsiveness- Conducted comprehensive security assessments and risk evaluations, identifying vulnerabilities within existing security models and implementing robust solutions to fortify systems. Led rigorous testing, including Mock Testing and ITGC testing, ensuring the architecture maintained integrity and security.
Education
CrossBeam Systems Certification
CrossBeam Specialist
2009 — 2009
Sun MicroSystems Certification
Sun Solaris Administration for Solaris 7
2001 — 2001
State University of New York at Buffalo
BS, Chemical Engineering
1993 — 1997
HP Certification
HP-UX Security Administration
2003 — 2003
ISACA
Certified Information Systems Auditor (CISA)
2007 — 2007
Polytechnic University
MS, Information Systems
2004 — 2005
DB2 Certification
DB2 9 Database Administration for UNIX
2007 — 2007
Skills
- Security
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.