We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
Remote New

System Architect I

Deltek, Inc.
life insurance, tuition reimbursement, 401(k)
United States
Sep 29, 2026

29-Sep-2026


Identity Architect I

US (Remote)

11280BR

Company Summary

As the recognized global standard for project-based businesses, Deltek delivers software and information solutions to help organizations achieve their purpose. Our market leadership stems from the work of our diverse employees who are united by a passion for learning, growing and making a difference. At Deltek, we take immense pride in creating a balanced, values-driven environment, where every employee feels included and empowered to do their best work. Our employees put our core values into action daily, creating a one-of-a-kind culture that has been recognized globally. Thanks to our incredible team, Deltek has been named one of America's Best Midsize Employers by Forbes, a Best Place to Work by Glassdoor, a Top Workplace by The Washington Post and a Best Place to Work in Asia by World HRD Congress. www.deltek.com

Business Summary

At Deltek, security isn't a gate at the end of the process - it's in the foundation. Enterprise Security & Technology Services (ESTS) brings together security, infrastructure, and technology operations under one organization, led by our CISO, with a mandate to make sure Deltek builds and operates with integrity at every layer.
We're a passionate team of technologists and security professionals who work across the entire company - embedded in how services are built, delivered, and supported. We run agile, we embrace intelligent automation to amplify what our people can do, and we hold ourselves to a high standard because the organizations that depend on Deltek's platform are doing work that can't afford mistakes. If you take your craft seriously, want visibility into how a complex, global technology organization really operates, and believe security should be a first principle - not an afterthought - this is a team that will feel like home.

Position Responsibilities

Key Responsibilities

  • Define Deltek's enterprise identity architecture and multi-year roadmap across workforce, privileged, non-human, cloud, AI-agent, partner, and customer identity domains.

  • Serve as the technical design authority for IAM-related initiatives and lead architecture reviews, design decisions, and exception evaluations.

  • Establish reference architectures, standards, integration patterns, identity data models, control requirements, and lifecycle-management principles.

  • Translate enterprise security, risk, compliance, user-experience, and business objectives into scalable identity capabilities.

  • Evaluate emerging identity technologies and recommend strategic investments, sequencing, and platform direction.

  • Maintain strong implementation accountability by supporting prototypes, critical integrations, design validation, and complex technical problem solving.

Identity Governance & Administration

  • Provide architectural leadership for Saviynt Enterprise Identity Cloud and the broader IGA operating model.

  • Define scalable onboarding patterns and governance models for enterprise applications across SaaS, on-premises, and cloud environments.

  • Design identity lifecycle, RBAC, ABAC, entitlement, role-mining, segregation-of-duties, access-request, and certification strategies.

  • Lead integration architecture across HR systems, Active Directory, Microsoft Entra ID, cloud platforms, enterprise applications, directories, and security tooling.

  • Define data-quality, identity-correlation, ownership, authoritative-source, and reconciliation standards required for reliable governance.

  • Guide automation of provisioning, deprovisioning, birthright access, approvals, revocation, remediation, and evidence production.

Privileged Access Management

  • Define Deltek's enterprise PAM architecture, target state, control model, and implementation roadmap.

  • Establish patterns for credential vaulting, session management, just-in-time and just-enough access, administrative tiering, emergency access, and privileged identity governance.

  • Integrate privileged access into the broader identity lifecycle, certification, policy, monitoring, and Zero Trust strategy.

  • Partner with Security and Infrastructure teams to reduce standing privilege and improve accountability for administrative access across critical systems.

Non-Human Identity & AI-Agent Governance

  • Define governance models for service accounts, machine identities, workload identities, service principals, API credentials, tokens, certificates, secrets, automation identities, and AI agents.

  • Establish requirements for discovery, registration, accountable ownership, purpose, risk tiering, least privilege, lifecycle management, periodic certification, monitoring, and retirement.

  • Partner with Cloud, Security, Automation, and AI teams to define secure patterns for workload identity federation, delegated access, secrets management, approval gates, and runtime guardrails.

  • Help prevent orphaned identities, unmanaged credentials, excessive permissions, shadow agents, and lifecycle drift through architecture, automation, and continuous governance.

Qualifications

Required Qualifications

  • 20+ years of experience in Identity and Access Management, security architecture, or closely related disciplines, including significant enterprise architecture responsibility.

  • Demonstrated experience defining enterprise IAM strategy, target-state architecture, roadmaps, and reusable design patterns.

  • Deep expertise in Identity Governance & Administration platforms, preferably Saviynt Enterprise Identity Cloud.

  • Strong expertise in identity lifecycle management, RBAC, ABAC, least privilege, segregation of duties, access certification, authentication, authorization, federation, and PAM.

  • Experience designing identity architecture for complex enterprise environments spanning cloud, SaaS, on-premises applications, directories, and regulated workloads.

  • Strong knowledge of Active Directory, Microsoft Entra ID, Azure identity services, AWS IAM, and identity concepts applicable to GCP.

  • Strong knowledge of SAML, OAuth 2.0, OpenID Connect, SCIM, REST APIs, JSON, certificates, secrets, tokens, and modern application-integration patterns.

  • Experience leading enterprise IAM transformations and influencing decisions across security, infrastructure, cloud, application, product, audit, and business teams.

  • Ability to move between executive communication, architecture definition, design review, and hands-on technical validation.

  • Excellent communication, facilitation, decision-making, documentation, and stakeholder-management skills.

Preferred Qualifications

  • Experience developing identity architecture as part of a Zero Trust security program.

  • Experience governing non-human identities, workload identities, secrets, service accounts, or AI agents.

  • Hands-on experience with PAM platforms such as Saviynt, CyberArk, BeyondTrust, or equivalent technologies.

  • Experience with additional IGA and identity platforms such as SailPoint, Okta, Ping Identity, Microsoft Entra ID Governance, or equivalent solutions.

  • Experience defining or implementing customer identity and access management solutions and B2B federation patterns.

  • Experience supporting SOX, SOC 1, SOC 2, NIST, FedRAMP, ISO 27001, GDPR, or similar regulatory and compliance frameworks.

  • Experience with scripting, APIs, orchestration, infrastructure-as-code, and automation-first engineering practices.

  • Relevant certifications such as Saviynt Certified Professional, CISSP, CIAM, SC-300, cloud architecture or security certifications, SABSA, or TOGAF.

Career Interests

Information Technology

Compensation Info

The U.S. salary range for this position is $124,500.00-$219,500.00. This range is subject to change as Deltek takes a number of factors into consideration when determining individual base pay, such as location, job-related knowledge, skills and experience. Certain roles are eligible for additional rewards, including incentive compensation and equity.

Benefits and perks listed here may vary depending on the nature of employment with Deltek. Employees have access to healthcare benefits, a 401(k) plan and company match, paid vacation time and holidays, well-living programs, short-term and long-term disability coverage, basic life insurance and tuition reimbursement.

Position Type

FT

Travel Requirements

10%

Compliance Requirements

Certain roles may have additional privacy, security and compliance requirements to the extent they support Costpoint GCCM or similar product offerings.

EEO Statement

Deltek, Inc. is an Equal Opportunity / Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected veteran status.

E-Verify Statement

Deltek, Inc., utilizes the E-Verify program with every potential new hire. This makes it possible for us to make certain that every employee who works for Deltek is eligible to work in the United States. To learn more about E-Verify you can call 1-800-255-7688 or visit their website by clicking the logo below. E-Verify is a registered trademark of the United States Department of Homeland Security.

Applicant Privacy Notice

Deltek is committed to the protection and promotion of your privacy. In connection with your application for employment with us at Deltek, it is necessary for us to collect, store and use information about you ("Personal Data") to administer and evaluate your application. We are the "controller" of the Personal Data you provide us and will process any such Personal Data in accordance with applicable law and the statements contained in this
Candidate Privacy Notice
Additionally, we have not sold and do not sell Personal Data you provide to us through the job application process.

Important: Protect Yourself from Recruitment Scams
Bad actors or scammers may try to impersonate Deltek and send fake job offers to people. Messages from Deltek about employment opportunities will be from an @deltek.com account or Enterprise@trm.brassring.com, never from free services like Gmail or Yahoo. Please look carefully at the email address that provides any job offer, as some fake accounts are created to look like a legitimate domain name or email address. We will also never ask you to pay money at any point in the hiring process, whether for training, equipment, background checks, or anything else. If you receive a suspicious offer claiming to be from Deltek, do not share personal or financial information. Report any suspicious communication to Secure@deltek.com and consider reporting it to law enforcement.

Job Expires

29-Sep-2027

Applied = 0

(web-9db6c7984-lzvp8)