> Markdown version of [/jobs/ext/3571222-sap-security-engineer](https://www.wearedevelopers.com/jobs/ext/3571222-sap-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SAP Security Engineer - **Company:** CACI International Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $75,200.0 - $158,100.0 - **Contract:** Contract - **Skills:** Amazon Web Services, Configuration Management, Data Governance, Data Security, Key Management, SAP ERP, Zero Trust Network Access, Security Assertion Markup Language (SAML), SAP (Applications), SAP GRC, SAP HANA, SAP Security, Security Information and Event Management, Systems Integration, Okta, Cyberark, SAPBasis, SAP S/4HANA, SAP Enterprise Threat Detection (ETD), Splunk - **Published:** October 3, 2026 - **Apply:** https://www.dice.com/job-detail/828aa735-7038-4335-be56-11711cb9f40d ## About the Role * Clearance: Interim Secret (minimum). * Experience: 5+ years of SAP Basis/Security experience with S/4HANA. * Certifications: DoD 8140 - Foundational - 461 (Systems Security Analyst - Intermediate or above) CCSP, Cloud+, GICSP, GISF, GSEC, Security+ (one or more) DoD 8140 - Residential SAP Security certification (preferred) * Technical Expertise: + Strong proficiency with SAP authorization concepts, composite roles, and profile management. + Hands-on SAP GRC Access Control experience, including SoD enforcement and role management. + Experience working with SAP ETD and SIEM integrations. + Knowledge of SAP HANA encryption and CloudHSM-based IL5 key management. + Understanding of SAP ILM, secure data lifecycle management, and governance frameworks. + Familiarity with SAP-ABAC attributes and secure SSO integrations. + Understanding of SAP protocol security and interface hardening. * DoD & Compliance Experience: + RMF/ATO processes and eMASS documentation. + DISA STIG application for SAP environments. + CORA evidence development and audit readiness. + Familiarity with NIST 800-171 / 800-53 controls. + Experience managing multi-step role governance workflows and ISSM gate approvals. * Required to travel to Scott Airforce base on a quarterly basis Desired: * Experience with AWS GovCloud IL5 environments. * SAP CUA and SAP SNC configuration skills. * Integration experience with CyberArk PAM for privileged SAP access. * Understanding of hybrid SAP architecture (on-prem to AWS, including Direct Connect). ## Description Join a high-impact cybersecurity and SAP engineering team supporting a DoD IL5-accredited SAP S/4HANA enterprise environment. As a SAP Security Engineer, you will help shape a modern Zero Trust architecture, strengthen system security, and directly contribute to mission-critical readiness. This role is ideal for engineers who enjoy solving complex security challenges, working collaboratively across cyber and audit teams, and building secure, scalable SAP platforms., * Support SAP security across an IL5 S/4HANA enterprise with integrated security modules and Zero Trust design principles. * Develop, maintain, and optimize SAP authorization objects, composite roles, and profile management. * Execute SoD enforcement and access reviews through SAP GRC Access Control. * Integrate SAP Enterprise Threat Detection (ETD) with SIEM platforms such as Splunk using LEEF syslog. * Implement and support SAP HANA encryption (AES-256 at rest) using PKCS#11 external key management with CloudHSM. * Manage SAP ILM processes and contribute to data governance initiatives. * Apply SAP attribute-based access control using BUKRS, KOSTL, PRCTR, WERKS, PERNR, ORGEH. * Support SAP SSO (SAML 2.0) integrations with enterprise identity providers, including Okta. * Ensure secure interface communication using RFC/3300, HTTPS/8000, and related protocols. * Contribute to RMF/ATO documentation, eMASS updates, DISA STIG implementations, and CORA evidence preparation. * Support role governance workflows and ISSM approval processes. ## Related Videos - [Headless by Design: Building Enterprise Systems That Agents Can Actually Use](https://www.wearedevelopers.com/videos/100092-headless-by-design-building-enterprise-systems-that-agents-can-actually-use) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)