CronJobs

security jobs

Senior Application Security SAP Consultant

C5miinsightllc · Remote - United States

remotesenior$175,000–$195,000Posted Sep 28, 2026SAP S/4HANASAP authorizationsegregation of dutiesprivileged access managementrole managementaccess control

Apply on the employer site

About this role

**C5MI — Senior Application Security SAP Consultant** C5MI is not your typical consulting firm. We’re a high-performance team of SAP and supply chain experts who solve complex, mission-critical challenges for organizations that cannot afford failure. We hire consultants who thrive in complexity, move fast, take ownership, and deliver under pressure. You’ll be hands-on, client-facing, and directly influencing outcomes that matter. **Position Summary** The **Senior Application Security SAP Consultant** is responsible for **SAP application security and governance, risk, and compliance** within an **SAP S/4HANA** environment. This includes: - Authorization design and **role management** - **Segregation of duties** enforcement - Producing and maintaining **access control evidence** to sustain authorization and support financial audit This role supports a **large-scale, greenfield SAP S/4HANA financial management modernization program** for a **Department of War (DoW)** organization. As the senior SAP security authority on the program, you will own the **authorization concept** and **segregation of duties architecture**, design the **GRC control framework**, and be accountable for **access control evidence** at audit and authorization milestones. This position operates at the **Senior** level of the C5MI job architecture and contributes to delivery across a **five-gate milestone structure**: 1. Pre-design approval 2. Preliminary design review 3. Critical design review 4. Production readiness review 5. Closeout > **Note:** This position is contingent upon contract award. **Essential Functions & Responsibilities** - Own the SAP authorization concept for the program, including **role architecture**, **naming standards**, **derivation strategy**, and the **governance process for role change**. - Design the **segregation of duties** framework (ruleset design/customization, risk definitions, and a mitigating control catalog with ownership and monitoring frequency). - Design the **governance, risk, and compliance** solution architecture across: - Access risk analysis - Access request management - Business role management - Emergency access management - Design **preventive segregation of duties enforcement** so access risk is evaluated and resolved **before provisioning** (including risk simulation within the request workflow). - Design **cross-system access risk analysis** beyond the core platform to integrated applications in the program landscape. - Design the **user access review and recertification** program (campaign scope, frequency, reviewer assignment, and evidence retention). - Own the mapping of access controls to applicable control frameworks, including: - Access control family requirements under the risk management framework - Information system general controls tested during financial audit - Design **privileged access management** for the SAP landscape, including privileged role restriction, emergency access governance, and **logging** sufficient to support audit and inspector general examination. *(The provided description appears truncated after the final bullet above.)*

Listing freshness

CronJobs last confirmed this listing 13h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord