SAP · 21 hours ago
SAP NS2 Intel Cloud Security and Information Systems Security Officer (ISSO) Onsite-TS/SCI/+poly req
SAP is the global market leader for business software and related services. The SAP NS2 Cloud Security and Information Systems Security Officer (ISSO) Consultant maintains the cybersecurity posture, regulatory compliance, and continuous authorization of SAP S/4HANA systems and supporting services hosted in AWS GovCloud and SAP NS2 Private Cloud Environments.
AnalyticsBusiness IntelligenceBusiness Process Automation (BPA)ComputerData ManagementFinanceSoftware
Responsibilities
Maintain RMF authorization packages for SAP S/4HANA, SAP Business Technology Platform (BTP), and supporting AWS services
Develop and maintain ATO artifacts, including SSPs, BoE, POA&Ms, waivers, exceptions, and continuous monitoring documentation
Enforce compliance with NIST SP 800-53 Rev. 5 and applicable DoD SRG overlays for IL5 and IL6 environments
Identify security vulnerabilities, assess risk, and coordinate remediation and mitigation activities with engineering and operations teams
Execute and oversee vulnerability and compliance scanning; analyze results and track remediation to closure
Manage continuous monitoring activities, including artifact collection, anomaly analysis, and security reporting
Review and analyze security logs from AWS, SAP, and operating systems (e.g., CloudTrail, GuardDuty, SAP audit logs)
Track and manage POA&M remediation efforts and support incident response and change management processes
Enforce least privilege and segregation-of-duties (SoD) across SAP roles and AWS IAM configurations
Serve as the primary security liaison with Authorizing Officials (AO/AODR) and government stakeholders
Document system boundaries, data flows, and system interconnections
Qualification
Required
U.S. citizenship and an active TS/SCI with polygraph are required
Hands-on experience implementing cloud security controls, policies, and procedures
Proficiency managing AWS IAM roles, policies, and permissions using least-privilege principles
Experience securing workloads in AWS GovCloud, including EC2, RDS, S3, IAM, CloudTrail, AWS Config, and Security Hub
Working knowledge of SAP S/4HANA architecture, SAP Basis concepts, and SoD controls
Experience conducting vulnerability management using tools such as Tenable and Splunk (or equivalent SIEM platforms)
Strong written and verbal communication skills with demonstrated experience producing audit-ready security documentation
Ability to monitor, investigate, mitigate, and report cloud security incidents and vulnerabilities
Experience executing RMF processes from system onboarding through ATO and continuous monitoring
Understanding of enterprise security technologies, including firewalls, IDS/IPS, vulnerability scanners, and log analysis tools
Knowledge of NIST, SOX, IT General Controls (ITGC), and compliance-driven security requirements
Possession of, or ability to obtain within 6 months, a DoD 8570–compliant certification (e.g., CISSP, CASP+, CISM, CAP)
Bachelor's degree required, preferably in Computer Science, Cybersecurity, Information Security, Engineering, or Information Technology
Preferred
Experience securing SAP workloads in AWS for DoD, DHS, or IC customers
Experience implementing security automation and compliance-as-code (e.g., AWS Config, Terraform)
Working knowledge of Windows and Linux system hardening and secure configuration
Knowledge of SAP HANA database security principles
Experience supporting disconnected or air-gapped cloud environments
Familiarity with SAP Business Technology Platform (BTP)
AWS, Linux, Windows, cloud, or systems administration certifications
Benefits
Health and well-being
Flexible working models
Commitment to pay equity
Company
SAP
SAP provides enterprise application software to various industries, including consumer, discrete manufacturing, public services.
Funding
Current Stage
Public CompanyTotal Funding
$1.3BKey Investors
Elliott Management Corp.
2019-04-24Post Ipo Equity· $1.3B
2015-06-01Grant· $1.37M
1998-08-03IPO
Leadership Team
Recent News
2026-01-03
2025-12-30
Company data provided by crunchbase