C5MI Insight
Senior Application Security SAP Consultant
Remote - United States
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →hirly's read of this role
- Role family
- Supply chain
- Seniority
- Senior
- Country
- US
- Work mode
- Remote-friendly
- First seen by hirly
- 28 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
C5MI is not your typical consulting firm. We are a high-performance team of SAP and supply chain experts who solve complex, mission critical challenges for organizations that cannot afford failure.
We hire consultants who thrive in complexity, move fast, take ownership, and deliver under pressure. At C5MI, you will not be siloed or stuck in theory. You will be hands on, client facing, and directly influencing outcomes that matter.
Our culture rewards initiative, accountability, and continuous growth. This is a place where your expertise is valued, your work is meaningful, and your performance truly matters. If you’re energized by learning through real-world challenges, collaborating with top-tier talent, and expanding your capabilities every day, C5MI is where strong consultants level up.
Position Summary:
The Senior Application Security SAP Consultant is responsible for SAP application security and governance, risk, and compliance within an SAP S/4HANA environment, covering authorization design, role management, segregation of duties enforcement, and the access control evidence required to sustain system authorization and support financial audit, in support of a large-scale, greenfield SAP S/4HANA financial management modernization program for a Department of War (DoW) organization. As the senior SAP security authority on the program, the consultant owns the authorization concept and segregation of duties architecture, designs the governance, risk, and compliance control framework, and is accountable for access control evidence at audit and authorization milestones. This position operates at the Senior level of the C5MI job architecture and contributes to delivery across a five-gate milestone structure spanning pre-design approval, preliminary design review, critical design review, production readiness review, and closeout.
Note: This position is contingent upon contract award.
Essential Functions and Responsibilities:
Owns the SAP authorization concept for the program, including the role architecture, naming standards, derivation strategy, and the governance process for role change.
Designs the segregation of duties framework, including ruleset design and customization, risk definitions, and the mitigating control catalog with assigned ownership and monitoring frequency.
Designs the governance, risk, and compliance solution architecture across access risk analysis, access request management, business role management, and emergency access management.
Designs preventive segregation of duties enforcement so that access risk is evaluated and resolved before provisioning rather than detected after the fact, including risk simulation within the request workflow.
Designs cross-system access risk analysis extending beyond the core platform to integrated applications within the program landscape.
Designs the user access review and recertification program, including campaign scope, frequency, reviewer assignment, and evidence retention.
Owns the mapping of access controls to applicable control frameworks, including access control family requirements under the risk management framework and information system general controls tested during financial audit.
Designs privileged access management for the SAP landscape, including privileged role restriction, emergency access governance, and logging sufficient to support audit and inspector general examination.
Solves complex problems spanning multiple variables, modules, and interfacing systems; owns a workstream or key solution component within the assigned process area.
Leads design for the assigned functional area, including options analysis, effort and risk assessment, and presentation of recommendations to the solution architecture function.
Serves as the recognized subject matter expert for the discipline, supporting milestone gate reviews, government working groups, and formal design review response.
Mentors and develops consultants at the III level, raising functional depth and design maturity across the team.
Supports authority to operate, cybersecurity, audit, and compliance activities associated with the program, including production of control evidence for assigned configuration.
Supports cutover, go-live, and post-deployment hypercare activities for assigned scope, and contributes to transition of the delivered capability into the sustainment organization.
Travels to client sites up to 50% to support workshops, design sessions, testing events, cutover, and go-live activities, varying based on client program schedules.
Adheres to all certified processes as part of our commitment to maintaining the highest standards of quality and information security, which includes actively participating in quality assurance activities and ensuring the protection of sensitive information in accordance with our security policies.
Performs other related tasks as assigned by direct supervisor.
C5MI Expectations of all Employees:
Adheres to all C5MI Policies and Procedures.
Always conducts self in a manner consistent with C5MIs’ Core Values.
Maintains a positive and respectful attitude with all contacts.
Consistently reports to work on time and prepared to perform the duties of the position.
Meets productivity standards and performs duties as workload necessitates.
Maintains the privacy of all company proprietary information.
Treats vendors, customers, and team members with respect and dignity.
Able to safely perform the essential functions of the job with or without reasonable accommodation.
Minimum Qualifications:
Bachelor’s degree in a related field or equivalent experience (Master’s degree or advanced certification a plus); 5-7 years of relevant experience with a Bachelor’s or Master’s degree, or 7-10 years of relevant experience without a Bachelor’s degree.
5+ years of SAP Security and SAP governance, risk, and compliance experience, including authorization design ownership on at least one full lifecycle implementation.
Deep expertise in SAP S/4HANA authorization concept design, role architecture, and Fiori security.
Demonstrated experience designing and customizing a segregation of duties ruleset and a mitigating control framework with assigned ownership and monitoring.
Demonstrated experience designing SAP Access Control solutions across access risk analysis, access request management, business role management, and emergency access management.
Experience producing access control evidence for external financial audit or information system controls testing.
Must meet DoDM 8140.03 (formerly DoD 8570.01-M) IAT Level II baseline certification requirements (e.g., CompTIA Security+ CE) prior to being granted privileged access, and must obtain any computing environment certification required by the Government within six months of assignment.
Demonstrated ability to own workstreams and key solution components and to solve complex problems with minimal oversight.
Experience supporting multi-system SAP landscapes and enterprise-scale implementations.
Secret security clearance required: must hold an active Secret clearance or be able to obtain and maintain one prior to assignment (requires U.S. citizenship).
Nice to Have:
Active Secret security clearance at time of hire.
Experience supporting federal ERP modernization programs, Department of War (DoW) SAP environments, or other defense business systems acquired under DoDI 5000.75.
CISSP, CISA, or equivalent advanced security or audit certification.
Experience supporting risk management framework authorization activities, including access control family implementation and continuous monitoring evidence.
Experience with identity, credential, and access management integration, including federated authentication and hardware-based multifactor authentication.
Experience with SAP HANA database security and analytic privileges.
Industry or vendor cer
Similar jobs
- SAP Consultant Supply Chain ManagementMiele · BraşovFirst seen today
- Sr.SAP Consultant, Professional Services - SAPAmazon · Dallas, Texas, USAFirst seen 2d ago
- Sr.SAP Consultant, Professional Services - SAPAmazon · Dallas, Texas, USAFirst seen 2d ago
- Senior Buyer - AerospaceStandardAero · Miami, FL, United StatesFirst seen today
- SAP ConsultantPcg · United States (Remote)First seen 3d agoremote
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job