System Engineer II

Deltek, Inc.

Herndon (VA)

On-site

USD 87,000 - 153,000

Full time

9 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Healthcare benefits
401(k) plan
Paid vacation
Disability coverage
Life insurance
Tuition reimbursement

Job summary

Deltek, Inc. is seeking an experienced Identity Governance & PAM engineer in the United States (Herndon/VA area) to lead IGA implementations and PAM controls.

You will design, develop, and optimize identity governance across enterprise applications, including Saviynt, with a focus on least-privilege access and secure privileged workflows. The role requires strong IAM expertise (RBAC, SoD) and hands-on experience with Saviynt EIC, ServiceNow, and cloud platforms (Azure/AWS/GCP).

Qualifications

  • Strong IAM fundamentals: user lifecycle, RBAC, least privilege, SoD.
  • 5+ years IAM engineering with Saviynt IGA experience.
  • Experience with enterprise-scale IAM implementations.
  • Proficient with REST APIs, JSON, SQL, and scripting languages.

Responsibilities

  • Serve as the technical point of contact for IGA implementation and development.
  • Design and develop IGA connectors and integrations with SaaS, on-premise, and cloud.
  • Build certification campaigns in Saviynt (reviews, certifications, roles).
  • Configure PAM controls and privilege workflows; extend governance to PAM.
  • Maintain data quality behind certifications and onboarding into Saviynt.
  • Support audit readiness and compliance activities (SOX, SOC 1/2, NIST).

Skills

IAM engineering
RBAC & SoD
Saviynt EIC
REST APIs & JSON
PowerShell/Python/JS
Cloud platforms (Azure/AWS/GCP)
Audit & Compliance
Incident resolution

Tools

Saviynt EIC
ServiceNow
Azure
AWS
GCP

Job description

Company Summary

As the recognized global standard for project-based businesses, Deltek delivers software and information solutions to help organizations achieve their purpose. Our market leadership stems from the work of our diverse employees who are united by a passion for learning, growing and making a difference. At Deltek, we take immense pride in creating a balanced, values-driven environment, where every employee feels included and empowered to do their best work. Our employees put our core values into action daily, creating a one-of-a-kind culture that has been recognized globally. Thanks to our incredible team, Deltek has been named one of America's Best Midsize Employers by Forbes, a Best Place to Work by Glassdoor, a Top Workplace by The Washington Post and a Best Place to Work in Asia by World HRD Congress. www.deltek.com

Business Summary

At Deltek, security isn't a gate at the end of the process - it's in the foundation. Enterprise Security & Technology Services (ESTS) brings together security, infrastructure, and technology operations under one organization, led by our CISO, with a mandate to make sure Deltek builds and operates with integrity at every layer. We're a passionate team of technologists and security professionals who work across the entire company - embedded in how services are built, delivered, and supported. We run agile, we embrace intelligent automation to amplify what our people can do, and we hold ourselves to a high standard because the organizations that depend on Deltek's platform are doing work that can't afford mistakes. If you take your craft seriously, want visibility into how a complex, global technology organization really operates, and believe security should be a first principle - not an afterthought - this is a team that will feel like home.

Position Responsibilities
Identity Governance & Access Management / PAM
  1. Serve as the technical point of contact for all IGA implementation and development efforts.

  2. Assist in the design and development of IGA connectors and integrations with enterprise applications - SaaS, on-premise, and cloud.

  3. Build and configure certification campaigns in Saviynt (user access reviews, entitlement certifications, role certifications), including workflows and decision routing.

  4. Build and customize workflows, rules, roles, and policies in IGA to support provisioning, deprovisioning, and access reviews.

  5. Build reviewer hierarchies and delegation rules so the correct approvers are assigned automatically.

  6. Configure auto-remediation so revocations flow into connected systems (AD, SaaS apps) without manual execution.

  7. Extend governance into Privileged Access Management (PAM) - onboarding privileged accounts, vaults, and elevated entitlements into the same certification, workflow, and review model as standard access.

  8. Implement and operate PAM controls including credential vaulting, session management, just-in-time (JIT) elevation, and privileged session monitoring.

  9. Partners with security teams to reduce standing privilege and enforce least-privilege access across critical systems.

  10. Maintain the data quality behind certifications - identity correlation, role definitions, and application onboarding into Saviynt

Non-Human & Agentic Identity Governance
  1. Govern the full lifecycle of non-human identities (NHIs) - service accounts, machine identities, secrets, and API credentials - including discovery, ownership assignment, risk-tiering, and periodic recertification.

  2. Extend the identity governance plane to AI agents - registering agents, scoping least-privilege access via Saviynt, integrating with secrets management (e.g., Azure Key Vault), and enforcing runtime guardrails and approval gates.

  3. Help eliminate shadow agents and orphaned NHIs through continuous discovery, dormancy detection, and drift alerts.

Automation & AI-Driven Engineering
  1. Champion an automation-first approach - identifying manual identity and access processes that can be eliminated, self-serviced, or fully automated.

  2. Design and maintain automation using REST APIs, JSON, SQL, and scripting languages (PowerShell, Python, JavaScript).

  3. Leverage AI-powered tools and agents (e.g., Microsoft Copilot, Claude) to accelerate connector development, troubleshooting, documentation, and operational insights.

  4. Apply AI to enhance governance activities such as access reviews, anomaly detection, and reporting - including Saviynt's native AI/rapid-onboarding capabilities.

Compliance, Audit & Operations
  1. Support audit readiness and access attestation for regulatory and compliance frameworks (e.g., SOX, SOC 1 / SOC 2, NIST, FedRAMP).

  2. Maintain the data quality behind certifications - identity correlation, role definitions, and application onboarding.

  3. Own resolution of complex incidents and service requests through ITSM platforms (e.g., ServiceNow), ensuring SLA adherence, and mentor junior engineers on identity concepts and tooling.

Qualifications
Required Qualifications
  1. Strong understanding of IAM principles, including user lifecycle management, role-based access control (RBAC), least privilege, and segregation of duties (SoD), and PAM.

  2. 5+ years of hands-on IAM engineering experience, including deep, demonstrable expertise configuring and developing on Saviynt EIC (IGA).

  3. Demonstrated experience with enterprise-scale IAM implementations, ideally in organizations with hundreds of applications.

  4. Proficient with REST APIs, JSON, SQL, and scripting languages (e.g., PowerShell, Python, JavaScript).

  5. Experience conducting or supporting access certification campaigns, audit activities, and compliance-driven controls.

  6. Familiarity with application infrastructure and architecture (Windows/Linux, cloud platforms like Azure, AWS, GCP).

  7. Excellent troubleshooting, debugging, communication, and documentation skills.

  8. Ability to work independently and manage priorities in a fast-paced environment.

Preferred Qualifications
  1. Experience with PAM platforms, procedures, implementations, and best practices. (Privileged Access Management).

  2. Experience governing non-human and/or agentic (AI agent) identities and secrets management (e.g., Azure Key Vault).

  3. Knowledge of Active Directory, Azure AD, and identity federation technologies (SAML, OAuth, OIDC).

  4. Experience using AI tools and developing agents (e.g., Microsoft Copilot, Claude) to improve operational efficiency.

  5. Prior experience in regulated environments (e.g., SOX, HIPAA, GDPR).

  6. IAM certifications (e.g., CIAM, CISSP, Saviynt Certified Professional) are a plus.

  7. 5+ years of hands-on development experience with IGA, including configuration, workflows, and connector development.

  8. U.S. Citizenship is required for this position due to the sensitive nature of the identity and access systems supported and applicable regulatory/compliance obligations.

Career Interests

Information Technology

Compensation Info

The U.S. salary range for this position is $86,500.00-$152,500.00. This range is subject to change as Deltek takes a number of factors into consideration when determining individual base pay, such as location, job-related knowledge, skills and experience. Certain roles are eligible for additional rewards, including incentive compensation and equity.

Benefits and perks listed here may vary depending on the nature of employment with Deltek. Employees have access to healthcare benefits, a 401(k) plan and company match, paid vacation time and holidays, well-living programs, short-term and long-term disability coverage, basic life insurance and tuition reimbursement.

Position Type

FT

Travel Requirements

10%

Compliance Requirements

Certain roles may have additional privacy, security and compliance requirements to the extent they support Costpoint GCCM or similar product offerings.

EEO Statement

Deltek, Inc. is an Equal Opportunity / Affiantative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected veteran status.

E-Verify Statement

Deltek, Inc., utilizes the E‑Verify program with every potential new hire. This makes it possible for us to make certain that every employee who works for Deltek is eligible to work in the United States. To learn more about E‑Verify you can call or visit their website by clicking the logo below. E‑Verify is a registered trademark of the United States Department of Homeland Security.

Applicant Privacy Notice

Deltek is committed to the protection and promotion of your privacy. In connection with your application for employment with us at Deltek, it is necessary for us to collect, store and use information about you ("Personal Data") to administer and evaluate your application. We are the "controller" of the Personal Data you provide us and will process any such Personal Data in accordance with applicable law and the statements contained in this.

Candidate Privacy Notice

Additionally, we have not sold and do not sell Personal Data you provide to us through the job application process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Analyst
Senior GRC Analyst

Deltek • Chicago (IL)

On-site
USD 76,000 - 134,000
Assoc Consultant
Assoc Consultant

Deltek, Inc. • Herndon (VA)

On-site
USD 53,000 - 71,000
Healthcare benefits
401(k) with company match
Paid vacation and holidays
+4
Team Lead, Security Eng III
Team Lead, Security Eng III

Deltek, Inc. • Tampa (FL)

Hybrid
USD 140,000 - 170,000
Senior Software Developer
Senior Software Developer

Deltek • Chicago (IL)

On-site
USD 72,000 - 127,000
Healthcare benefits
401(k) plan with company match
Paid vacation and holidays
+3
Testing - Associate Support Services Analyst
Testing - Associate Support Services Analyst

Deltek • Chicago (IL)

On-site
USD 22,000 - 23,000
Healthcare benefits
401(k) plan with company match
Paid vacation and holidays
Customer Success Manager
Customer Success Manager

Deltek • United States

Hybrid
USD 75,000 - 110,000
Health benefits
401(k) match
Paid vacation
+4
Customer Success Mgr
Customer Success Mgr

Deltek, Inc. • United States

Hybrid
USD 75,000 - 110,000
Healthcare benefits
401(k) plan and company match
Paid vacation time and holidays
+4
Principal Customer Success Manager - GOVCON
Principal Customer Success Manager - GOVCON

Deltek • Chicago (IL)

Hybrid
USD 92,000 - 150,000
Healthcare benefits
401(k) plan
Paid vacation
+3
Manager, Software Engineering
Manager, Software Engineering

Delinea • United States

On-site
PHP 1,800,000 - 3,000,000
Healthcare insurance
Pension matching
Life insurance
+2
Sr Sales Representative
Sr Sales Representative

Deltek, Inc. • Herndon (VA)

Hybrid
USD 182,000 - 207,000
Healthcare benefits
401(k) plan with company match
Paid vacation time
+1