Company Summary As the recognized global standard for project-based businesses, Deltek delivers software and information solutions to help organizations achieve their purpose. Our market leadership stems from the work of our diverse employees who are united by a passion for learning, growing and making a difference. At Deltek, we take immense pride in creating a balanced, values-driven environment, where every employee feels included and empowered to do their best work. Our employees put our core values into action daily, creating a one-of-a-kind culture that has been recognized globally. Thanks to our incredible team, Deltek has been named one of America's Best Midsize Employers by Forbes, a Best Place to Work by Glassdoor, a Top Workplace by The Washington Post and a Best Place to Work in Asia by World HRD Congress. www.deltek.com
Business Summary At Deltek, security isn't a gate at the end of the process - it's in the foundation. Enterprise Security & Technology Services (ESTS) brings together security, infrastructure, and technology operations under one organization, led by our CISO, with a mandate to make sure Deltek builds and operates with integrity at every layer. We're a passionate team of technologists and security professionals who work across the entire company - embedded in how services are built, delivered, and supported. We run agile, we embrace intelligent automation to amplify what our people can do, and we hold ourselves to a high standard because the organizations that depend on Deltek's platform are doing work that can't afford mistakes. If you take your craft seriously, want visibility into how a complex, global technology organization really operates, and believe security should be a first principle - not an afterthought - this is a team that will feel like home.
Position Responsibilities Key Responsibilities
Define Deltek's enterprise identity architecture and multi-year roadmap across workforce, privileged, non-human, cloud, AI-agent, partner, and customer identity domains.
Establish reference architectures, standards, integration patterns, identity data models, control requirements, and lifecycle-management principles.
Translate enterprise security, risk, compliance, user-experience, and business objectives into scalable identity capabilities.
Maintain strong implementation accountability by supporting prototypes, critical integrations, design validation, and complex technical problem solving.
Identity Governance & Administration
Design identity lifecycle, RBAC, ABAC, entitlement, role-mining, segregation-of-duties, access-request, and certification strategies.
Lead integration architecture across HR systems, Active Directory, Microsoft Entra ID, cloud platforms, enterprise applications, directories, and security tooling.
Define data-quality, identity-correlation, ownership, authoritative-source, and reconciliation standards required for reliable governance.
Guide automation of provisioning, deprovisioning, birthright access, approvals, revocation, remediation, and evidence production.
Privileged Access Management
Define Deltek's enterprise PAM architecture, target state, control model, and implementation roadmap.
Establish patterns for credential vaulting, session management, just-in-time and just-enough access, administrative tiering, emergency access, and privileged identity governance.
Integrate privileged access into the broader identity lifecycle, certification, policy, monitoring, and Zero Trust strategy.
Non-Human Identity & AI-Agent Governance
Define governance models for service accounts, machine identities, workload identities, service principals, API credentials, tokens, certificates, secrets, automation identities, and AI agents.
Establish requirements for discovery, registration, accountable ownership, purpose, risk tiering, least privilege, lifecycle management, periodic certification, monitoring, and retirement.
Partner with Cloud, Security, Automation, and AI teams to define secure patterns for workload identity federation, delegated access, secrets management, approval gates, and runtime guardrails.
Help prevent orphaned identities, unmanaged credentials, excessive permissions, shadow agents, and lifecycle drift through architecture, automation, and continuous governance.
Qualifications Required Qualifications
20+ years of experience in Identity and Access Management, security architecture, or closely related disciplines, including significant enterprise architecture responsibility.
Demonstrated experience defining enterprise IAM strategy, target-state architecture, roadmaps, and reusable design patterns.
Strong expertise in identity lifecycle management, RBAC, ABAC, least privilege, segregation of duties, access certification, authentication, authorization, federation, and PAM.
Experience designing identity architecture for complex enterprise environments spanning cloud, SaaS, on-premises applications, directories, and regulated workloads.
Strong knowledge of Active Directory, Microsoft Entra ID, Azure identity services, AWS IAM, and identity concepts applicable to GCP.
Strong knowledge of SAML, OAuth 2.0, OpenID Connect, SCIM, REST APIs, JSON, certificates, secrets, tokens, and modern application-integration patterns.
Experience leading enterprise IAM transformations and influencing decisions across security, infrastructure, cloud, application, product, audit, and business teams.
Ability to move between executive communication, architecture definition, design review, and hands-on technical validation.
Excellent communication, facilitation, decision-making, documentation, and stakeholder-management skills.
Preferred Qualifications
Experience governing non-human identities, workload identities, secrets, service accounts, or AI agents.
Hands-on experience with PAM platforms such as Saviynt, CyberArk, BeyondTrust, or equivalent technologies.
Experience with additional IGA and identity platforms such as SailPoint, Okta, Ping Identity, Microsoft Entra ID Governance, or equivalent solutions.
Experience supporting SOX, SOC 1, SOC 2, NIST, FedRAMP, ISO 27001, GDPR, or similar regulatory and compliance frameworks.
Experience with scripting, APIs, orchestration, infrastructure-as-code, and automation-first engineering practices.
Relevant certifications such as Saviynt Certified Professional, CISSP, CIAM, SC-300, cloud architecture or security certifications, SABSA, or TOGAF.
Career Interests Information Technology
Compensation Info The U.S. salary range for this position is $124,500.00-$219,500.00. This range is subject to change as Deltek takes a number of factors into consideration when determining individual base pay, such as location, job-related knowledge, skills and experience. Certain roles are eligible for additional rewards, including incentive compensation and equity.
Benefits and perks listed here may vary depending on the nature of employment with Deltek. Employees have access to healthcare benefits, a 401(k) plan and company match, paid vacation time and holidays, well-living programs, short-term and long-term disability coverage, basic life insurance and tuition reimbursement.
Compliance Requirements Certain roles may have additional privacy, security and compliance requirements to the extent they support Costpoint GCCM or similar product offerings.
EEO Statement Deltek, Inc. is an Equal Opportunity / Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected veteran status.
E-Verify Statement Deltek, Inc., utilizes the E-Verify program with every potential new hire. This makes it possible for us to make certain that every employee who works for Deltek is eligible to work in the United States. To learn more about E-Verify you can call 1-800-255-7688 or visit their website by clicking the logo below. E-Verify is a registered trademark of the United States Department of Homeland Security.
Applicant Privacy Notice Deltek is committed to the protection and promotion of your privacy. In connection with your application for employment with us at Deltek, it is necessary for us to collect, store and use information about you ("Personal Data") to administer and evaluate your application. We are the "controller" of the Personal Data you provide us and will process any such Personal Data in accordance with applicable law and the statements contained in this Candidate Privacy Notice Additionally, we have not sold and do not sell Personal Data you provide to us through the job application process.
Important: Protect Yourself from Recruitment Scams Bad actors or scammers may try to impersonate Deltek and send fake job offers to people. Messages from Deltek about employment opportunities will be from an @deltek.com account or Enterprise@trm.brassring.com, never from free services like Gmail or Yahoo. Please look carefully at the email address that provides any job offer, as some fake accounts are created to look like a legitimate domain name or email address. We will also never ask you to pay money at any point in the hiring process, whether for training, equipment, background checks, or anything else. If you receive a suspicious offer claiming to be from Deltek, do not share personal or financial information. Report any suspicious communication to Secure@deltek.com and consider reporting it to law enforcement.
|