Senior Application Security SAP Consultant

C5MI Insight
•$175,000 - $195,000•Onsite

About The Position

The Senior Application Security SAP Consultant is responsible for SAP application security and governance, risk, and compliance within an SAP S/4HANA environment, covering authorization design, role management, segregation of duties enforcement, and the access control evidence required to sustain system authorization and support financial audit, in support of a large-scale, greenfield SAP S/4HANA financial management modernization program for a Department of War (DoW) organization. As the senior SAP security authority on the program, the consultant owns the authorization concept and segregation of duties architecture, designs the governance, risk, and compliance control framework, and is accountable for access control evidence at audit and authorization milestones. This position operates at the Senior level of the C5MI job architecture and contributes to delivery across a five-gate milestone structure spanning pre-design approval, preliminary design review, critical design review, production readiness review, and closeout. Note: This position is contingent upon contract award.

Requirements

  • Bachelor’s degree in a related field or equivalent experience (Master’s degree or advanced certification a plus); 5-7 years of relevant experience with a Bachelor’s or Master’s degree, or 7-10 years of relevant experience without a Bachelor’s degree.
  • 5+ years of SAP Security and SAP governance, risk, and compliance experience, including authorization design ownership on at least one full lifecycle implementation.
  • Deep expertise in SAP S/4HANA authorization concept design, role architecture, and Fiori security.
  • Demonstrated experience designing and customizing a segregation of duties ruleset and a mitigating control framework with assigned ownership and monitoring.
  • Demonstrated experience designing SAP Access Control solutions across access risk analysis, access request management, business role management, and emergency access management.
  • Experience producing access control evidence for external financial audit or information system controls testing.
  • Must meet DoDM 8140.03 (formerly DoD 8570.01-M) IAT Level II baseline certification requirements (e.g., CompTIA Security+ CE) prior to being granted privileged access, and must obtain any computing environment certification required by the Government within six months of assignment.
  • Demonstrated ability to own workstreams and key solution components and to solve complex problems with minimal oversight.
  • Experience supporting multi-system SAP landscapes and enterprise-scale implementations.
  • Secret security clearance required: must hold an active Secret clearance or be able to obtain and maintain one prior to assignment (requires U.S. citizenship).

Nice To Haves

  • Active Secret security clearance at time of hire.
  • Experience supporting federal ERP modernization programs, Department of War (DoW) SAP environments, or other defense business systems acquired under DoDI 5000.75.
  • CISSP, CISA, or equivalent advanced security or audit certification.
  • Experience supporting risk management framework authorization activities, including access control family implementation and continuous monitoring evidence.
  • Experience with identity, credential, and access management integration, including federated authentication and hardware-based multifactor authentication.
  • Experience with SAP HANA database security and analytic privileges.
  • Industry or vendor certification relevant to the discipline; relevant certifications include SAP Certified Application Associate – SAP Access Control / SAP Security, CISSP, CISA, or an equivalent security or audit certification.
  • Experience customizing and uplifting a segregation of duties ruleset for an S/4HANA role redesign.
  • Experience owning the access control portion of an external financial audit or information system general controls examination.

Responsibilities

  • Owns the SAP authorization concept for the program, including the role architecture, naming standards, derivation strategy, and the governance process for role change.
  • Designs the segregation of duties framework, including ruleset design and customization, risk definitions, and the mitigating control catalog with assigned ownership and monitoring frequency.
  • Designs the governance, risk, and compliance solution architecture across access risk analysis, access request management, business role management, and emergency access management.
  • Designs preventive segregation of duties enforcement so that access risk is evaluated and resolved before provisioning rather than detected after the fact, including risk simulation within the request workflow.
  • Designs cross-system access risk analysis extending beyond the core platform to integrated applications within the program landscape.
  • Designs the user access review and recertification program, including campaign scope, frequency, reviewer assignment, and evidence retention.
  • Owns the mapping of access controls to applicable control frameworks, including access control family requirements under the risk management framework and information system general controls tested during financial audit.
  • Designs privileged access management for the SAP landscape, including privileged role restriction, emergency access governance, and logging sufficient to support audit and inspector general examination.
  • Solves complex problems spanning multiple variables, modules, and interfacing systems; owns a workstream or key solution component within the assigned process area.
  • Leads design for the assigned functional area, including options analysis, effort and risk assessment, and presentation of recommendations to the solution architecture function.
  • Serves as the recognized subject matter expert for the discipline, supporting milestone gate reviews, government working groups, and formal design review response.
  • Mentors and develops consultants at the III level, raising functional depth and design maturity across the team.
  • Supports authority to operate, cybersecurity, audit, and compliance activities associated with the program, including production of control evidence for assigned configuration.
  • Supports cutover, go-live, and post-deployment hypercare activities for assigned scope, and contributes to transition of the delivered capability into the sustainment organization.
  • Travels to client sites up to 50% to support workshops, design sessions, testing events, cutover, and go-live activities, varying based on client program schedules.
  • Adheres to all certified processes as part of our commitment to maintaining the highest standards of quality and information security, which includes actively participating in quality assurance activities and ensuring the protection of sensitive information in accordance with our security policies.
  • Performs other related tasks as assigned by direct supervisor.

Benefits

  • medical, dental, vision, life, and long-term disability coverage
  • a 401(k) plan
  • bonus opportunities
  • paid holidays
  • paid time off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service