> Markdown version of [/jobs/ext/1918082-sap-cybersecurity-specialist](https://www.wearedevelopers.com/jobs/ext/1918082-sap-cybersecurity-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SAP Cybersecurity Specialist - **Company:** Groundswell, LLC - **Location:** Washington, DC, United States - **Experience:** Starter - **Salary:** $87,952.0 - $166,356.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, User Authentication, Cyber Security, Information Systems, Data Security, Linux, Multi-Factor Authentication, Internet Security, Intrusion Detection and Prevention, Intrusion Detection Systems, Information Systems Security Architecture Professional, SAP ERP, Requirements Management, SAP (Applications), Service Pack, Security Information and Event Management, Software Vulnerability Management, Information Security Management System, Patch Management, Devsecops - **Published:** August 4, 2026 - **Apply:** https://www.careerbuilder.com/job-details/sap-cybersecurity-specialist-washington-dc--6fcfaf16-32a0-4fa5-8e38-2fd8157fbec8 ## About the Role * Must be a U.S. Citizen (no dual status) * Active DoD Secret security clearance (or higher) required * Preference given to candidates with current or recent DoD experience * 1-3 years relevant experience as a business analyst in ERP environment * 2 years focused specifically on SAP years' experience * 1 year SAP experience in FI, CO, FM or Supply Management. * Working knowledge of Information Assurance (IA) concepts such as patch management, multi-factor authentication, host-based security, intrusion detection, security event management and defense-in-depth is required * Experience with Plan of Actions and Milestones (POAM), Information Assurance Vulnerability Management (IAVM), and compliance reporting for mission systems * Active DoD 8570 certification required or must obtain prior to onboarding to the program * Experience in agile development implementation, preferably SAFe and/or DevSecOps. * Bachelor's Degree or equivalent experience * Must be local to the DC Metro area and willing to be on client site in DC up to 5 days/week, * At least one Security Certification (in order of preference): + Certified Information Systems Security Professional (CISSP) + Certified Info Sys Auditor (CISA)/Certified Info Sec Manager (CISM) + Certified Ethical Hacker (CEH) + Other similar certs may be acceptable on a case-by-case basis, Agile Programming Methodologies, Analysis Skills, Authentication, Best Practices, Business Analysis, Business Solutions, CEH - Certified Ethical Hacker, CISA - Certified Information Systems Auditor, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Computer Security, Contingency Plans, Cross-Functional, Customer Relations, Defense in Depth, Dental Insurance, DoD Directive 8140, DoD Directive 8570, DoD Secret Clearance, Documentation, ERP (Enterprise Resource Planning), Federal Government, Finance, Flexible Spending Accounts, Government, Human Resources, Incident Response, Information/Data Security (InfoSec), Internet Security, Intrusion Detection Systems, Leadership, Linux Media Players, Onboarding, Privacy Impact Assessment (PIA), Problem Solving Skills, Process Improvement, Product Programs, Progress Reports, Project Estimates, Project Tracking, Recruiting/Staffing Agency, Reporting Skills, Requirements Management, Risk Analysis, Risk Management, Risk Management Framework (RMF), Root Cause Analysis, SAP, Security Analysis, Security Attacks, Security Clearance, Security Information and Event Management (SIEM), Service Level Agreement (SLA), Small Company, Software Patches, Support Documentation, United States Citizen, United States Department of Defense (DoD), Vendor/Supplier Management, Vision Plan, White Papers, Writing Skills ## Description We are seeking an SAP Cybersecurity Specialist with experience supporting the Department of Defense to help apply industry best practices and deliver effective business solutions. The candidate will leverage their expertise to analyze and define Multilevel Security issues. Typical areas addressed include Human Resources, Finance, Supply, and operations., * Analyze and define security requirements for Multilevel Security (MLS) issues. * Design, develop, engineer, and implement solutions to MLS requirements. * Gather and organize technical information about an organization's mission goals and needs, existing security products, and ongoing programs in the MLS arena. * Perform risk analyses which also include risk assessment. * Work with clients to ensure security solution satisfies the objectives as defined in the security and operational requirements * Work in multi-disciplined teams to define and design complex processes and procedures for the security maintenance of SAP and related application systems * Support enhancement requests and resolve reported incidents within defined service level agreements * Support all Risk Management Framework (RMF) activities to include Ongoing Security Assessments (OSA) such as updating control implementation statements and providing evidence to compliance assessment activities * Support updating security documentation such as System Security Plan, Contingency Plan, Incident Response Plan, Privacy Impact Assessment, and other similar documents * Prepare progress reports for internal leadership and for client and monitor project progress * Mitigate risks, address issues, interface with clients, and keep the leadership informed on project status * Develop basis of estimates and program schedule for multiple solution alternatives * Author white papers, root cause analysis, other solution related documentation as needed * Provide support to the management and perform duties as assign ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Headless by Design: Building Enterprise Systems That Agents Can Actually Use](https://www.wearedevelopers.com/videos/100092-headless-by-design-building-enterprise-systems-that-agents-can-actually-use) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)