C5MI Insight logo

Senior Application Security SAP Consultant

Salary
$175K–$195K
USD per year
Hiring from
United States
Work type
Remote
Posted
Sep 28, 2026
Is this job info correct?

C5MI is not your typical consulting firm. We are a high-performance team of SAP and supply chain experts who solve complex, mission critical challenges for organizations that cannot afford failure. We hire consultants who thrive in complexity, move fast, take ownership, and deliver under pressure. At C5MI, you will not be siloed or stuck in theory. You will be hands on, client facing, and directly influencing outcomes that matter. Our culture rewards initiative, accountability, and continuous growth. This is a place where your expertise is valued, your work is meaningful, and your performance truly matters. If you’re energized by learning through real-world challenges, collaborating with top-tier talent, and expanding your capabilities every day, C5MI is where strong consultants level up. Position Summary: The Senior Application Security SAP Consultant is responsible for SAP application security and governance, risk, and compliance within an SAP S/4HANA environment, covering authorization design, role management, segregation of duties enforcement, and the access control evidence required to sustain system authorization and support financial audit, in support of a large-scale, greenfield SAP S/4HANA financial management modernization program for a Department of War (DoW) organization. As the senior SAP security authority on the program, the consultant owns the authorization concept and segregation of duties architecture, designs the governance, risk, and compliance control framework, and is accountable for access control evidence at audit and authorization milestones. This position operates at the Senior level of the C5MI job architecture and contributes to delivery across a five-gate milestone structure spanning pre-design approval, preliminary design review, critical design review, production readiness review, and closeout. Note: This position is contingent upon contract award. Essential Functions and Responsibilities: Owns the SAP authorization concept for the program, including the role architecture, naming standards, derivation strategy, and the governance process for role change. Designs the segregation of duties framework, including ruleset design and customization, risk definitions, and the mitigating control catalog with assigned ownership and monitoring frequency. Designs the governance, risk, and compliance solution architecture across access risk analysis, access request management, business role management, and emergency access management. Designs preventive segregation of duties enforcement so that access risk is evaluated and resolved before provisioning rather than detected after the fact, including risk simulation within the request workflow. Designs cross-system access risk analysis extending beyond the core platform to integrated applications within the program landscape. Designs the user access review and recertification program, including campaign scope, frequency, reviewer assignment, and evidence retention. Owns the mapping of access controls to applicable control frameworks, including access control family requirements under the risk management framework and information system general controls tested during financial audit. Designs privileged access management for the SAP landscape, including privileged role restriction, emergency access governance, and logging sufficient to support audit and inspector general examination. Solves complex problems spanning multiple variables, modules, and interfacing systems; owns a workstream or key solution component within the assigned process area. Leads design for the assigned functional area, including options analysis, effort and risk assessment, and presentation of recommendations to the solution architecture function. Serves as the recognized subject matter expert for the discipline, supporting milestone gate reviews, government working groups, and formal design review response. Mentors and develops consultants at the III level, raising functional depth and design maturity across the team. Supports authority to operate, cybersecurity, audit, and compliance activities associated with the program, including production of control evidence for assigned configuration. Supports cutover, go-live, and post-deployment hypercare activities for assigned scope, and contributes to transition of the delivered capability into the sustainment organization. Travels to client sites up to 50% to support workshops, design sessions, testing events, cutover, and go-live activities, varying based on client program schedules. Adheres to all certified processes as part of our commitment to maintaining the highest standards of quality and information security, which includes actively participating in quality assurance activities and ensuring the protection of sensitive information in accordance with our security policies. Performs other related tasks as assigned by direct supervisor. C5MI Expectations of all Employees: Adheres to all C5MI Policies and Procedures. Always conducts self in a manner consistent with C5MIs’ Core Values. Maintains a positive and respectful attitude with all contacts. Consistently reports to work on time and prepared to perform the duties of the position. Meets productivity standards and performs duties as workload necessitates. Maintains the privacy of all company proprietary information. Treats vendors, customers, and team members with respect and dignity. Able to safely perform the essential functions of the job with or without reasonable accommodation. Minimum Qualifications: Bachelor’s degree in a related field or equivalent experience (Master’s degree or advanced certification a plus); 5-7 years of relevant experience with a Bachelor’s or Master’s degree, or 7-10 years of relevant experience without a Bachelor’s degree. 5+ years of SAP Security and SAP governance, risk, and compliance experience, including authorization design ownership on at least one full lifecycle implementation. Deep expertise in SAP S/4HANA authorization concept design, role architecture, and Fiori security. Demonstrated experience designing and customizing a segregation of duties ruleset and a mitigating control framework with assigned ownership and monitoring. Demonstrated experience designing SAP Access Control solutions across access risk analysis, access request management, business role management, and emergency access management. Experience producing access control evidence for external financial audit or information system controls testing. Must meet DoDM 8140.03 (formerly DoD 8570.01-M) IAT Level II baseline certification requirements (e.g., CompTIA Security+ CE) prior to being granted privileged access, and must obtain any computing environment certification required by the Government within six months of assignment. Demonstrated ability to own workstreams and key solution components and to solve complex problems with minimal oversight. Experience supporting multi-system SAP landscapes and enterprise-scale implementations. Secret security clearance required: must hold an active Secret clearance or be able to obtain and maintain one prior to assignment (requires U.S. citizenship). Nice to Have: Active Secret security clearance at time of hire. Experience supporting federal ERP modernization programs, Department of War (DoW) SAP environments, or other defense business systems acquired under DoDI 5000.75. CISSP, CISA, or equivalent advanced security or audit certification. Experience supporting risk management framework authorization activities, including access control family implementation and continuous monitoring evidence. Experience with identity, credential, and access management integration, including federated authentication and hardware-based multifactor authentication. Experience with SAP HANA database security and analytic privileges. Industry or vendor certification relevant to the discipline; relevant certifications include SAP Certified Application Associate – SAP Access Control / SAP Security, CISSP, CISA, or an equivalent security or audit certification. Experience customizing and uplifting a segregation of duties ruleset for an S/4HANA role redesign. Experience owning the access control portion of an external financial audit or information system general controls examination. Compensation: In accordance with pay transparency law, the expected salary range for this position is $175,000 – $195,000 annually. The actual compensation offered will be determined based on factors such as the candidate’s experience, qualifications, skills, and location. We are committed to fair and equitable compensation practices. This posted range reflects our good faith estimate of the compensation we reasonably expect to offer for this role at the time of posting. Application Deadline: We anticipate this job posting will be posted until 12/01/2026. Benefits: C5MI offers a market competitive suite of benefits including medical, dental, vision, life, and long-term disability coverage, a 401(k) plan, bonus opportunities, paid holidays, and paid time off. See more information on our benefits here: C5MI Benefits Our employees are key to our success, so we strive to be more than just a team; we’re a community built upon a set of Core Values that guide our every action: Challenge – We believe in challenging the present – it’s the only way to shape the future. We must be exceptional communicators and collaborators while always learning. We also understand that speaking your mind requires equal parts brain (what to say), thoughtfulness (when to say it), and caring (how it’s said). Incremental won’t win. Have Fun – We are on a journey, together. Take care of your family, take care of yourself, and take care of each other. Live your happiness. Stay human, take care of each other and invest in your community. Life isn’t all about work. Live your happiness. Be healthy. All In – You can’t fake passion – show your energy. Own it – take charge and lead. Our team is made up of top quartile talent and we never accept second best. Accountability, trust, and integrity create an environment to realize the team’s true potential. Never Forget the Customer – We have walked a mile in your shoes. Experience matters. We drive innovation to generate business value. Be true – no BS. GSD (Get Stuff Done) – We take initiative and never make excuses. We act with urgency, and we delivery high quality outcomes with extreme velocity. We embrace process discipline, drive continuous improvement, and stay audit ready. We relentlessly execute and plan for tomorrow by creating sustainable outcomes. That is how we win! Empower – Our people are the foundation for our success. We recognize their value, and support them by fostering a culture of collaboration and innovation. We recognize individual strengths, build confidence through action, and invest in personal development. How to Apply: To apply for this position, use the application link provided in this job posting and complete the application and submit a resume. If the position requires a specific certification, please be sure to upload a copy of your certification when you apply. If you would like to be considered for employment opportunities with C5MI and have accommodation needs such as for a disability or religious observance, please call us toll free at 1 (904) 431-7922 or send us an email here or speak with your recruiter. C5MI is an Equal Opportunity Employer that does not discriminate on the basis of actual or perceived race, color, creed, religion, national origin, ancestry, citizenship status, age, sex or gender (including pregnancy, childbirth, pregnancy-related conditions, and lactation), gender identity or expression (including transgender status), sexual orientation, marital status, military service and veteran status, physical or mental disability, genetic information, or any other characteristic protected by applicable federal, state, or local laws and ordinances.

Similar jobs

Apply for this job