System Architect I

Deltek, Inc.

United States

Remote

USD 125,000 - 220,000

Full time

9 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Deltek, Inc. is seeking an Identity Architect I to shape enterprise IAM strategy and define multi-year roadmaps across workforce, privileged, non-human, cloud, and partner identities.

You will lead design reviews, model data, and establish standards while collaborating with security, infrastructure, and application teams to deliver scalable identity capabilities across SaaS, on-prem, and cloud environments.

Qualifications

  • 20+ years in Identity and Access Management or security architecture.
  • Experience defining enterprise IAM strategy and roadmaps.
  • Deep expertise in identity lifecycle management, RBAC/ABAC, and access certification.
  • Experience with cloud, SaaS, on-premise directories and regulated workloads.
  • Strong knowledge of AD/Entra ID, Azure identity services, and IAM protocols.

Responsibilities

  • Define Deltek's enterprise identity architecture and multi-year roadmap across workforce, privileged, non-human, cloud, AI-agent, partner, and customer identity domains.
  • Serve as the technical design authority for IAM initiatives and lead architecture reviews.
  • Establish reference architectures, standards, integration patterns, and lifecycle-management principles.
  • Translate security, risk, and business objectives into scalable identity capabilities.
  • Evaluate emerging identity technologies and recommend strategic investments.
  • Provide implementation accountability and support for prototypes and complex integrations.

Skills

IAM architecture
IAM strategy
RBAC / ABAC
PAM
SAML / OAuth / OIDC
Zero Trust
Cloud security
AD / Entra ID / Azure

Tools

Saviynt Enterprise Identity Cloud
CyberArk
BeyondTrust
SailPoint
Okta
Ping Identity
Microsoft Entra ID Governance

Job description

Identity Architect I

US (Remote)

11280BR

Company Summary

As the recognized global standard for project-based businesses, Deltek delivers software and information solutions to help organizations achieve their purpose. Our market leadership stems from the work of our diverse employees who are united by a passion for learning, growing and making a difference. At Deltek, we take immense pride in creating a balanced, values-driven environment, where every employee feels included and empowered to do their best work. Our employees put our core values into action daily, creating a one-of-a-kind culture that has been recognized globally. Thanks to our incredible team, Deltek has been named one of America's Best Midsize Employers by Forbes, a Best Place to Work by Glassdoor, a Top Workplace by The Washington Post and a Best Place to Work in Asia by World HRD Congress. www.deltek.com

Business Summary

At Deltek, security isn't a gate at the end of the process - it's in the foundation. Enterprise Security & Technology Services (ESTS) brings together security, infrastructure, and technology operations under one organization, led by our CISO, with a mandate to make sure Deltek builds and operates with integrity at every layer. We're a passionate team of technologists and security professionals who work across the entire company - embedded in how services are built, delivered, and supported. We run agile, we embrace intelligent automation to amplify what our people can do, and we hold ourselves to a high standard because the organizations that depend on Deltek's platform are doing work that can't afford mistakes. If you take your craft seriously, want visibility into how a complex, global technology organization really operates, and believe security should be a first principle - not an afterthought - this is a team that will feel like home.

Position Responsibilities
Key Responsibilities
  • Define Deltek's enterprise identity architecture and multi-year roadmap across workforce, privileged, non-human, cloud, AI-agent, partner, and customer identity domains.
  • Serve as the technical design authority for IAM-related initiatives and lead architecture reviews, design decisions, and exception evaluations.
  • Establish reference architectures, standards, integration patterns, identity data models, control requirements, and lifecycle-management principles.
  • Translate enterprise security, risk, compliance, user-experience, and business objectives into scalable identity capabilities.
  • Evaluate emerging identity technologies and recommend strategic investments, sequencing, and platform direction.
  • Maintain strong implementation accountability by supporting prototypes, critical integrations, design validation, and complex technical problem solving.
Identity Governance & Administration
  • Provide architectural leadership for Saviynt Enterprise Identity Cloud and the broader IGA operating model.
  • Define scalable onboarding patterns and governance models for enterprise applications across SaaS, on-premises, and cloud environments.
  • Design identity lifecycle, RBAC, ABAC, entitlement, role-mining, segregation-of-duties, access-request, and certification strategies.
  • Lead integration architecture across HR systems, Active Directory, Microsoft Entra ID, cloud platforms, enterprise applications, directories, and security tooling.
  • Define data-quality, identity-correlation, ownership, authoritative-source, and reconciliation standards required for reliable governance.
  • Guide automation of provisioning, deprovisioning, birthright access, approvals, revocation, remediation, and evidence production.
Privileged Access Management
  • Define Deltek's enterprise PAM architecture, target state, control model, and implementation roadmap.
  • Establish patterns for credential vaulting, session management, just-in-time and just-enough access, administrative tiering, emergency access, and privileged identity governance.
  • Integrate privileged access into the broader identity lifecycle, certification, policy, monitoring, and Zero Trust strategy.
  • Partner with Security and Infrastructure teams to reduce standing privilege and improve accountability for administrative access across critical systems.
Non-Human Identity & AI-Agent Governance
  • Define governance models for service accounts, machine identities, workload identities, service principals, API credentials, tokens, certificates, secrets, automation identities, and AI agents.
  • Establish requirements for discovery, registration, accountable ownership, purpose, risk tiering, least privilege, lifecycle management, periodic certification, monitoring, and retirement.
  • Partner with Cloud, Security, Automation, and AI teams to define secure patterns for workload identity federation, delegated access, secrets management, approval gates, and runtime guardrails.
  • Help prevent orphaned identities, unmanaged credentials, excessive permissions, shadow agents, and lifecycle drift through architecture, automation, and continuous governance.
Qualifications
Required Qualifications
  • 20+ years of experience in Identity and Access Management, security architecture, or closely related disciplines, including significant enterprise architecture responsibility.
  • Demonstrated experience defining enterprise IAM strategy, target-state architecture, roadmaps, and reusable design patterns.
  • Deep expertise in Identity Governance & Administration platforms, preferably Saviynt Enterprise Identity Cloud.
  • Strong expertise in identity lifecycle management, RBAC, ABAC, least privilege, segregation of duties, access certification, authentication, authorization, federation, and PAM.
  • Experience designing identity architecture for complex enterprise environments spanning cloud, SaaS, on-premises applications, directories, and regulated workloads.
  • Strong knowledge of Active Directory, Microsoft Entra ID, Azure identity services, AWS IAM, and identity concepts applicable to GCP.
  • Strong knowledge of SAML, OAuth 2.0, OpenID Connect, SCIM, REST APIs, JSON, certificates, secrets, tokens, and modern application-integration patterns.
  • Experience leading enterprise IAM transformations and influencing decisions across security, infrastructure, cloud, application, product, audit, and business teams.
  • Ability to move between executive communication, architecture definition, design review, and hands-on technical validation.
  • Excellent communication, facilitation, decision-making, documentation, and stakeholder-management skills.
Preferred Qualifications
  • Experience developing identity architecture as part of a Zero Trust security program.
  • Experience governing non-human identities, workload identities, secrets, service accounts, or AI agents.
  • Hands-on experience with PAM platforms such as Saviynt, CyberArk, BeyondTrust, or equivalent technologies.
  • Experience with additional IGA and identity platforms such as SailPoint, Okta, Ping Identity, Microsoft Entra ID Governance, or equivalent solutions.
  • Experience defining or implementing customer identity and access management solutions and B2B federation patterns.
  • Experience supporting SOX, SOC 1, SOC 2, NIST, FedRAMP, ISO 27001, GDPR, or similar regulatory and compliance frameworks.
  • Experience with scripting, APIs, orchestration, infrastructure-as-code, and automation-first engineering practices.
  • Relevant certifications such as Saviynt Certified Professional, CISSP, CIAM, SC-300, cloud architecture or security certifications, SABSA, or TOGAF.
Career Interests

Information Technology

Compensation Info

The U.S. salary range for this position is $124,500.00-$219,500.00. This range is subject to change as Deltek takes a number of factors into consideration when determining individual base pay, such as location, job-related knowledge, skills and experience. Certain roles are eligible for additional rewards, including incentive compensation and equity.

Benefits and perks listed here may vary depending on the nature of employment with Deltek. Employees have access to healthcare benefits, a 401(k) plan and company match, paid vacation time and holidays, well-living programs, short-term and long-term disability coverage, basic life insurance and tuition reimbursement.

Position Type

FT

Travel Requirements

10%

Compliance Requirements

Certain roles may have additional privacy, security and compliance requirements to the extent they support Costpoint GCCM or similar product offerings.

EEO Statement

Deltek, Inc. is an Equal Opportunity / Affiantive Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

System Architect I
System Architect I

Deltek, Inc. • Herndon (VA)

Remote
USD 130,000 - 170,000
Sr Consultant
Sr Consultant

Deltek • United States

On-site
USD 72,000 - 127,000
Healthcare benefits
401(k) plan
Paid vacation
Assoc Consultant
Assoc Consultant

Deltek, Inc. • Herndon (VA)

On-site
USD 53,000 - 71,000
Healthcare benefits
401(k) with company match
Paid vacation and holidays
+4
Senior Customer Success Systems Administrator
Senior Customer Success Systems Administrator

Deltek • Chicago (IL)

On-site
USD 90,000 - 110,000
Healthcare benefits
401(k) with company match
Paid vacation and holidays
+3
Pncpl Data Scientist
Pncpl Data Scientist

Deltek • United States

On-site
USD 109,000 - 193,000
Advisory IT Business Analyst
Advisory IT Business Analyst

Deltek, Inc. • United States

Remote
USD 125,000 - 220,000
Mgr, Payroll Services
Mgr, Payroll Services

Deltek, Inc. • United States

Remote
USD 71,000 - 125,000
Principal GRC Analyst
Principal GRC Analyst

Communitech • United States

Remote
USD 19,000 - 25,000
Senior Implementation Consultant
Senior Implementation Consultant

Deltek • United States

Remote
USD 72,000 - 127,000
Healthcare benefits
401(k) plan with company match
Paid vacation and holidays
Testing - Associate Support Services Analyst
Testing - Associate Support Services Analyst

Deltek • Chicago (IL)

On-site
USD 22,000 - 23,000
Healthcare benefits
401(k) plan with company match
Paid vacation and holidays