System Architect I
| Hours | Full-time, Part-time |
|---|---|
| Location | Herndon, Virginia |
About this job
29-Sep-2026
US (Remote)
11280BR
Company Summary
As the recognized global standard for project-based businesses, Deltek delivers software and information solutions to help organizations achieve their purpose. Our market leadership stems from the work of our diverse employees who are united by a passion for learning, growing and making a difference. At Deltek, we take immense pride in creating a balanced, values-driven environment, where every employee feels included and empowered to do their best work. Our employees put our core values into action daily, creating a one-of-a-kind culture that has been recognized globally. Thanks to our incredible team, Deltek has been named one of America's Best Midsize Employers by Forbes, a Best Place to Work by Glassdoor, a Top Workplace by The Washington Post and a Best Place to Work in Asia by World HRD Congress. www.deltek.com
Business Summary
At Deltek, security isn't a gate at the end of the process - it's in the foundation. Enterprise Security & Technology Services (ESTS) brings together security, infrastructure, and technology operations under one organization, led by our CISO, with a mandate to make sure Deltek builds and operates with integrity at every layer.
We're a passionate team of technologists and security professionals who work across the entire company - embedded in how services are built, delivered, and supported. We run agile, we embrace intelligent automation to amplify what our people can do, and we hold ourselves to a high standard because the organizations that depend on Deltek's platform are doing work that can't afford mistakes. If you take your craft seriously, want visibility into how a complex, global technology organization really operates, and believe security should be a first principle - not an afterthought - this is a team that will feel like home.
Position Responsibilities
Key Responsibilities
Define Deltek's enterprise identity architecture and multi-year roadmap across workforce, privileged, non-human, cloud, AI-agent, partner, and customer identity domains.
Serve as the technical design authority for IAM-related initiatives and lead architecture reviews, design decisions, and exception evaluations.
Establish reference architectures, standards, integration patterns, identity data models, control requirements, and lifecycle-management principles.
Translate enterprise security, risk, compliance, user-experience, and business objectives into scalable identity capabilities.
Evaluate emerging identity technologies and recommend strategic investments, sequencing, and platform direction.
Maintain strong implementation accountability by supporting prototypes, critical integrations, design validation, and complex technical problem solving.
Identity Governance & Administration
Provide architectural leadership for Saviynt Enterprise Identity Cloud and the broader IGA operating model.
Define scalable onboarding patterns and governance models for enterprise applications across SaaS, on-premises, and cloud environments.
Design identity lifecycle, RBAC, ABAC, entitlement, role-mining, segregation-of-duties, access-request, and certification strategies.
Lead integration architecture across HR systems, Active Directory, Microsoft Entra ID, cloud platforms, enterprise applications, directories, and security tooling.
Define data-quality, identity-correlation, ownership, authoritative-source, and reconciliation standards required for reliable governance.
Guide automation of provisioning, deprovisioning, birthright access, approvals, revocation, remediation, and evidence production.
Privileged Access Management
Define Deltek's enterprise PAM architecture, target state, control model, and implementation roadmap.
Establish patterns for credential vaulting, session management, just-in-time and just-enough access, administrative tiering, emergency access, and privileged identity governance.
Integrate privileged access into the broader identity lifecycle, certification, policy, monitoring, and Zero Trust strategy.
Partner with Security and Infrastructure teams to reduce standing privilege and improve accountability for administrative access across critical systems.
Non-Human Identity & AI-Agent Governance
Define governance models for service accounts, machine identities, workload identities, service principals, API credentials, tokens, certificates, secrets, automation identities, and AI agents.
Establish requirements for discovery, registration, accountable ownership, purpose, risk tiering, least privilege, lifecycle management, periodic certification, monitoring, and retirement.
Partner with Cloud, Security, Automation, and AI teams to define secure patterns for workload identity federation, delegated access, secrets management, approval gates, and runtime guardrails.
Help prevent orphaned identities, unmanaged credentials, excessive permissions, shadow agents, and lifecycle drift through architecture, automation, and continuous governance.
Qualifications
Required Qualifications
20+ years of experience in Identity and Access Management, security architecture, or closely related disciplines, including significant enterprise architecture responsibility.
Demonstrated experience defining enterprise IAM strategy, target-state architecture, roadmaps, and reusable design patterns.
Deep expertise in Identity Governance & Administration platforms, preferably Saviynt Enterprise Identity Cloud.
Strong expertise in identity lifecycle management, RBAC, ABAC, least privilege, segregation of duties, access certification, authentication, authorization, federation, and PAM.
Experience designing identity architecture for complex enterprise environments spanning cloud, SaaS, on-premises applications, directories, and regulated workloads.
Strong knowledge of Active Directory, Microsoft Entra ID, Azure identity services, AWS IAM, and identity concepts applicable to GCP.
Strong knowledge of SAML, OAuth 2.0, OpenID Connect, SCIM, REST APIs, JSON, certificates, secrets, tokens, and modern application-integration patterns.
Experience leading enterprise IAM transformations and influencing decisions across security, infrastructure, cloud, application, product, audit, and business teams.
Ability to move between executive communication, architecture definition, design review, and hands-on technical validation.
Excellent communication, facilitation, decision-making, documentation, and stakeholder-management skills.
Preferred Qualifications
Experience developing identity architecture as part of a Zero Trust security program.
Experience governing non-human identities, workload identities, secrets, service accounts, or AI agents.
Hands-on experience with PAM platforms such as Saviynt, CyberArk, BeyondTrust, or equivalent technologies.
Experience with additional IGA and identity platforms such as SailPoint, Okta, Ping Identity, Microsoft Entra ID Governance, or equivalent solutions.
Experience defining or implementing customer identity and access management solutions and B2B federation patterns.
Experience supporting SOX, SOC 1, SOC 2, NIST, FedRAMP, ISO 27001, GDPR, or similar regulatory and compliance frameworks.
Experience with scripting, APIs, orchestration, infrastructure-as-code, and automation-first engineering practices.
Relevant certifications such as Saviynt Certified Professional, CISSP, CIAM, SC-300, cloud