> Markdown version of [/jobs/ext/1322081-sap-security-specialist](https://www.wearedevelopers.com/jobs/ext/1322081-sap-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SAP Security Specialist - **Company:** NSAP, LLC - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems Security Architecture Professional, SAP ERP, SAP (Applications), SAP Security, Security Support Provider Interface, Automated Information System (AIS), SAPBasis, National Industrial Security Program Operating Manual (NISPOM), Vulnerability Analysis - **Published:** July 17, 2026 - **Apply:** https://jobs.military.com/career/280830/sap-security-specialist-ii-ts-sci-26-124-virginia-va-arlington ## About the Role u2022 BS with a minimum of 7 years of related DoD or IC experience \n \u2022 Candidates must hold a TS/SCI with the willingness and ability to pass a CI polygraph, it is highly desirable for candidates to have taken and passed CI polygraph within the past three years\n \u2022 Senior-level knowledge of SAP security principles, regulations, and emerging best practices.\n \u2022 Deep understanding of physical, personnel, and industrial security requirements within a complex SAP environment.\n \u2022 Exceptional written and verbal communication, briefing, and interpersonal skills.\n \u2022 Proven ability to lead and manage large security teams and complex projects.\n \u2022 Strategic thinking and problem-solving skills.\n \u2022 Qualifying relevant experience includes demonstrated recent experience in successfully performing as a program security representative (or similar title) for one or more programs on a contract or in an organization that provides security support to a federal entity or private corporation in a classified environment\n ## Description Working collaboratively across government and contractor organizations, the SAP Security Specialist II develops security documentation, supports facility and system accreditations, coordinates security requirements throughout the program lifecycle, and ensures compliance with Department of Defense (DoD), Intelligence Community (IC), and customer-specific security policies. This position operates with considerable independence while supporting highly sensitive research, acquisition, and operational programs.\n \n \nResponsibilities:\n \u2022 Independently administer security requirements supporting Special Access Programs (SAP), SCI, collateral, and other classified programs throughout the program lifecycle. \n \u2022 Develop, coordinate, and maintain program security documentation including DD Form 254s, Security Classification Guides (SCGs), Program Protection Plans (PPPs), Test Security Plans, MOUs, MOAs, SOPs, accreditation packages, and related security artifacts. \n \u2022 Coordinate SAP Facility (SAPF), Sensitive Compartmented Information Facility (SCIF), and Automated Information Systems (AIS) accreditation activities with government customers and mission partners. \n \u2022 Interpret and apply Executive Order 13526, NISPOM, ICDs, DoD SAP Manuals, and other applicable security policies while providing guidance to program personnel. \n \u2022 Advise program managers, engineers, contracting personnel, and government stakeholders regarding classification, program protection, personnel security, and security compliance requirements. \n \u2022 Develop and implement security architectures and protection strategies that support classified research, development, acquisition, and operational programs. \n \u2022 Coordinate personnel security activities including nominations, access requests, indoctrinations, debriefings, visit authorizations, adverse information reporting, and security documentation. \n \u2022 Conduct OPSEC assessments, risk analyses, Critical Program Information (CPI) identification, and vulnerability assessments supporting program protection planning. \n \u2022 Prepare executive-level reports, briefings, metrics, and recommendations regarding program security readiness, compliance, and risk mitigation. \n \u2022 Support classified meetings, technical reviews, program milestones, and customer engagements requiring integrated security planning. \n \u2022 Conduct security self-inspections, compliance reviews, and corrective action planning while identifying opportunities to improve security processes and operational efficiency. \n \u2022 Mentor junior security personnel and provide guidance regarding SAP security processes, documentation, and customer expectations. \n \u2022 Partner with physical security, personnel security, industrial security, cybersecurity, and information security professionals to provide integrated security support across classified programs. \n \u2022 Recommend and implement process improvements that enhance customer service, compliance, reporting accuracy, and overall program effectiveness. \n \n ## Related Videos - [Headless by Design: Building Enterprise Systems That Agents Can Actually Use](https://www.wearedevelopers.com/videos/100092-headless-by-design-building-enterprise-systems-that-agents-can-actually-use) - [AI Pair Programming with GitHub Copilot at SAP: Looking Back, Looking Forward!](https://www.wearedevelopers.com/videos/1546-ai-pair-programming-with-github-copilot-at-sap-looking-back-looking-forward) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Beyond GPT: Building Unified GenAI Platforms for the Enterprise of Tomorrow](https://www.wearedevelopers.com/videos/1525-beyond-gpt-building-unified-genai-platforms-for-the-enterprise-of-tomorrow) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)