
SAP Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Illinois.
• Provide support for SAP security within an IL5 S/4HANA environment, utilizing integrated security modules and adhering to Zero Trust design principles.
• Design, enhance, and manage SAP authorization objects, composite roles, and profile administration.
• Carry out Segregation of Duties (SoD) enforcement and conduct access reviews via SAP GRC Access Control.
• Integrate SAP Enterprise Threat Detection with SIEM platforms, including Splunk, utilizing LEEF syslog.
• Implement and maintain AES-256 encryption for SAP HANA data at rest, employing PKCS#11 external key management alongside CloudHSM.
• Oversee SAP Information Lifecycle Management (ILM) processes and participate in data governance projects.
• Utilize SAP attribute-based access control mechanisms, including BUKRS, KOSTL, PRCTR, WERKS, PERNR, and ORGEH.
• Assist with SAP Single Sign-On (SSO) SAML 2.0 integrations involving corporate identity providers such as Okta.
• Ensure secure communication between interfaces through protocols like RFC/3300, HTTPS/8000, and others.
• Contribute to Risk Management Framework (RMF) and Authorization to Operate (ATO) documentation, update eMASS, implement DISA STIGs, and prepare CORA evidence.
• Aid in managing role governance workflows and ISSM approval processes.
• Help define Zero Trust architecture, enhance system security, and support readiness for mission-critical operations.
• Collaborate effectively with cybersecurity and audit teams.
• Interim Secret clearance is mandatory.
• A minimum of 5 years of experience in SAP Basis/Security, specifically with S/4HANA.
• One or more DoD 8140-approved certifications are required, such as CCSP, Cloud+, GICSP, GISF, GSEC, or Security+.
• Strong knowledge of SAP authorization concepts, composite roles, and profile management is essential.
• Hands-on experience with SAP GRC Access Control, focusing on SoD enforcement and role management.
• Familiarity with SAP Enterprise Threat Detection and SIEM integrations is necessary.
• Knowledge of SAP HANA encryption methods and IL5 key management utilizing CloudHSM is required.
• Understanding of SAP ILM, secure data lifecycle management, and related governance frameworks is important.
• Awareness of SAP-ABAC attributes and secure SSO integration methodologies is needed.
• Knowledge of SAP protocol security and interface hardening techniques is crucial.
• Experience with RMF/ATO processes and eMASS documentation is sought.
• Ability to apply DISA STIGs within SAP environments is required.
• Experience in developing CORA evidence and supporting audit preparedness is essential.
• Familiarity with NIST 800-171 / 800-53 controls is preferred.
• Proven experience in managing multi-step role governance workflows and ISSM gate approvals is necessary.
• Willingness to travel to Scott Air Force Base on a quarterly basis is required.
• DoD 8140 Residential SAP Security certification is preferred.
• Experience with AWS GovCloud IL5 environments is highly desirable.
• Skills in SAP CUA and SAP SNC configuration are preferred.
• Desired experience includes integrating CyberArk PAM for privileged SAP access.
• Understanding of hybrid SAP architecture, especially regarding on-premises to AWS Direct Connect, is a plus.
• Flexible time off benefit.
• Robust learning resources.
• Healthcare benefits.
• Wellness benefits.
• Financial benefits.
• Retirement benefits.
• Family support benefits.
• Continuing education benefits.
• Time off benefits.
• Competitive compensation.
• Opportunities for learning and development.
Reli Group
Second Nature
ASRC Federal
Kyndryl
Get handpicked remote jobs straight to your inbox weekly.