Identity Architect I

Deltek, Inc
United States
3 days ago
Apply on sjobs.brassring.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Compensation
$124,500.0 - $219,500.0
Working hours
Regular working hours

Tech stack

Microsoft Access Active Directory Application Programming Interfaces (APIs) Artificial Intelligence Application Integration Architecture User Authentication Microsoft Azure Software as a Service Cloud Computing Cloud Engineering Cyber Security Software Design Patterns
+22 more
Identity and Access Management JSON OAuth Software Architecture Role-Based Access Control Openid Connect Azure Active Directory Zero Trust Network Access Sherwood Applied Business Security Architecture Security Assertion Markup Language (SAML) Session Management Systems Integration Scripting Enterprise Software Applications Cloud Platform System Okta Cyberark Togaf Customer Identity Access Management HR Software SailPoint Restful APIs

Job description

  • Define Deltek’s enterprise identity architecture and multi-year roadmap across workforce, privileged, non-human, cloud, AI-agent, partner, and customer identity domains.

  • Serve as the technical design authority for IAM-related initiatives and lead architecture reviews, design decisions, and exception evaluations.

  • Establish reference architectures, standards, integration patterns, identity data models, control requirements, and lifecycle-management principles.

  • Translate enterprise security, risk, compliance, user-experience, and business objectives into scalable identity capabilities.

  • Evaluate emerging identity technologies and recommend strategic investments, sequencing, and platform direction.

  • Maintain strong implementation accountability by supporting prototypes, critical integrations, design validation, and complex technical problem solving.

Identity Governance & Administration

  • Provide architectural leadership for Saviynt Enterprise Identity Cloud and the broader IGA operating model.

  • Define scalable onboarding patterns and governance models for enterprise applications across SaaS, on-premises, and cloud environments.

  • Design identity lifecycle, RBAC, ABAC, entitlement, role-mining, segregation-of-duties, access-request, and certification strategies.

  • Lead integration architecture across HR systems, Active Directory, Microsoft Entra ID, cloud platforms, enterprise applications, directories, and security tooling.

  • Define data-quality, identity-correlation, ownership, authoritative-source, and reconciliation standards required for reliable governance.

  • Guide automation of provisioning, deprovisioning, birthright access, approvals, revocation, remediation, and evidence production.

Privileged Access Management

  • Define Deltek’s enterprise PAM architecture, target state, control model, and implementation roadmap.

  • Establish patterns for credential vaulting, session management, just-in-time and just-enough access, administrative tiering, emergency access, and privileged identity governance.

  • Integrate privileged access into the broader identity lifecycle, certification, policy, monitoring, and Zero Trust strategy.

  • Partner with Security and Infrastructure teams to reduce standing privilege and improve accountability for administrative access across critical systems.

Non-Human Identity & AI-Agent Governance

  • Define governance models for service accounts, machine identities, workload identities, service principals, API credentials, tokens, certificates, secrets, automation identities, and AI agents.

  • Establish requirements for discovery, registration, accountable ownership, purpose, risk tiering, least privilege, lifecycle management, periodic certification, monitoring, and retirement.

  • Partner with Cloud, Security, Automation, and AI teams to define secure patterns for workload identity federation, delegated access, secrets management, approval gates, and runtime guardrails.

  • Help prevent orphaned identities, unmanaged credentials, excessive permissions, shadow agents, and lifecycle drift through architecture, automation, and continuous governance.

Requirements

  • 20+ years of experience in Identity and Access Management, security architecture, or closely related disciplines, including significant enterprise architecture responsibility.

  • Demonstrated experience defining enterprise IAM strategy, target-state architecture, roadmaps, and reusable design patterns.

  • Deep expertise in Identity Governance & Administration platforms, preferably Saviynt Enterprise Identity Cloud.

  • Strong expertise in identity lifecycle management, RBAC, ABAC, least privilege, segregation of duties, access certification, authentication, authorization, federation, and PAM.

  • Experience designing identity architecture for complex enterprise environments spanning cloud, SaaS, on-premises applications, directories, and regulated workloads.

  • Strong knowledge of Active Directory, Microsoft Entra ID, Azure identity services, AWS IAM, and identity concepts applicable to GCP.

  • Strong knowledge of SAML, OAuth 2.0, OpenID Connect, SCIM, REST APIs, JSON, certificates, secrets, tokens, and modern application-integration patterns.

  • Experience leading enterprise IAM transformations and influencing decisions across security, infrastructure, cloud, application, product, audit, and business teams.

  • Ability to move between executive communication, architecture definition, design review, and hands-on technical validation.

  • Excellent communication, facilitation, decision-making, documentation, and stakeholder-management skills.

Preferred Qualifications

  • Experience developing identity architecture as part of a Zero Trust security program.

  • Experience governing non-human identities, workload identities, secrets, service accounts, or AI agents.

  • Hands-on experience with PAM platforms such as Saviynt, CyberArk, BeyondTrust, or equivalent technologies.

  • Experience with additional IGA and identity platforms such as SailPoint, Okta, Ping Identity, Microsoft Entra ID Governance, or equivalent solutions.

  • Experience defining or implementing customer identity and access management solutions and B2B federation patterns.

  • Experience supporting SOX, SOC 1, SOC 2, NIST, FedRAMP, ISO 27001, GDPR, or similar regulatory and compliance frameworks.

  • Experience with scripting, APIs, orchestration, infrastructure-as-code, and automation-first engineering practices.

  • Relevant certifications such as Saviynt Certified Professional, CISSP, CIAM, SC-300, cloud architecture or security certifications, SABSA, or TOGAF.

Benefits & conditions

The U.S. salary range for this position is $124,500.00-$219,500.00. This range is subject to change as Deltek takes a number of factors into consideration when determining individual base pay, such as location, job-related knowledge, skills and experience. Certain roles are eligible for additional rewards, including incentive compensation and equity.

Benefits and perks listed here may vary depending on the nature of employment with Deltek. Employees have access to healthcare benefits, a 401(k) plan and company match, paid vacation time and holidays, well-living programs, short-term and long-term disability coverage, basic life insurance and tuition reimbursement.

About the company

As the recognized global standard for project-based businesses, Deltek delivers software and information solutions to help organizations achieve their purpose. Our market leadership stems from the work of our diverse employees who are united by a passion for learning, growing and making a difference. At Deltek, we take immense pride in creating a balanced, values-driven environment, where every employee feels included and empowered to do their best work. Our employees put our core values into action daily, creating a one-of-a-kind culture that has been recognized globally. Thanks to our incredible team, Deltek has been named one of America’s Best Midsize Employers by Forbes, a Best Place to Work by Glassdoor, a Top Workplace by The Washington Post and a Best Place to Work in Asia by World HRD Congress. www.deltek.com, At Deltek, security isn’t a gate at the end of the process - it’s in the foundation. Enterprise Security & Technology Services (ESTS) brings together security, infrastructure, and technology operations under one organization, led by our CISO, with a mandate to make sure Deltek builds and operates with integrity at every layer. We’re a passionate team of technologists and security professionals who work across the entire company - embedded in how services are built, delivered, and supported. We run agile, we embrace intelligent automation to amplify what our people can do, and we hold ourselves to a high standard because the organizations that depend on Deltek’s platform are doing work that can’t afford mistakes. If you take your craft seriously, want visibility into how a complex, global technology organization really operates, and believe security should be a first principle - not an afterthought - this is a team that will feel like home.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on sjobs.brassring.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann Chris Heilmann +2 · LIVE

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

2:08 min

Managing complex structures and corporate guidelines

Alexandra Petri · World Congress 2023

2:03 min

Distinguishing type definition constructs from data validation routines

Clemens Vasters Clemens Vasters · World Congress 2025

Videos

See all

Related articles

See all