We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
Remote New

System Engineer II

Deltek, Inc.
life insurance, tuition reimbursement, 401(k)
United States
Sep 12, 2026

11-Sep-2026


IAM Engineer, Identity Governance (IGA & PAM)

US (Remote)

11236BR

Company Summary

As the recognized global standard for project-based businesses, Deltek delivers software and information solutions to help organizations achieve their purpose. Our market leadership stems from the work of our diverse employees who are united by a passion for learning, growing and making a difference. At Deltek, we take immense pride in creating a balanced, values-driven environment, where every employee feels included and empowered to do their best work. Our employees put our core values into action daily, creating a one-of-a-kind culture that has been recognized globally. Thanks to our incredible team, Deltek has been named one of America's Best Midsize Employers by Forbes, a Best Place to Work by Glassdoor, a Top Workplace by The Washington Post and a Best Place to Work in Asia by World HRD Congress. www.deltek.com

Business Summary

At Deltek, security isn't a gate at the end of the process - it's in the foundation. Enterprise Security & Technology Services (ESTS) brings together security, infrastructure, and technology operations under one organization, led by our CISO, with a mandate to make sure Deltek builds and operates with integrity at every layer.
We're a passionate team of technologists and security professionals who work across the entire company - embedded in how services are built, delivered, and supported. We run agile, we embrace intelligent automation to amplify what our people can do, and we hold ourselves to a high standard because the organizations that depend on Deltek's platform are doing work that can't afford mistakes. If you take your craft seriously, want visibility into how a complex, global technology organization really operates, and believe security should be a first principle - not an afterthought - this is a team that will feel like home.

Position Responsibilities

Identity Governance & Access Management / PAM

  1. Serve as the technical point of contact for all IGA implementation and development efforts.

  1. Assist in the design and development of IGA connectors and integrations with enterprise applications - SaaS, on-premise, and cloud.

  1. Build and configure certification campaigns in Saviynt (user access reviews, entitlement certifications, role certifications), including workflows and decision routing.

  1. Build and customize workflows, rules, roles, and policies in IGA to support provisioning, deprovisioning, and access reviews.

  1. Build reviewer hierarchies and delegation rules so the correct approvers are assigned automatically.

  1. Configure auto-remediation so revocations flow into connected systems (AD, SaaS apps) without manual execution.

  1. Extend governance into Privileged Access Management (PAM) - onboarding privileged accounts, vaults, and elevated entitlements into the same certification, workflow, and review model as standard access.

  1. Implement and operate PAM controls including credential vaulting, session management, just-in-time (JIT) elevation, and privileged session monitoring.

  1. Partners with security teams to reduce standing privilege and enforce least-privilege access across critical systems.

  1. Maintain the data quality behind certifications - identity correlation, role definitions, and application onboarding into Saviynt

Non-Human & Agentic Identity Governance

  1. Govern the full lifecycle of non-human identities (NHIs) - service accounts, machine identities, secrets, and API credentials - including discovery, ownership assignment, risk-tiering, and periodic recertification.

  1. Extend the identity governance plane to AI agents - registering agents, scoping least-privilege access via Saviynt, integrating with secrets management (e.g., Azure Key Vault), and enforcing runtime guardrails and approval gates.

  1. Help eliminate shadow agents and orphaned NHIs through continuous discovery, dormancy detection, and drift alerts.

Automation & AI-Driven Engineering

  1. Champion an automation-first approach - identifying manual identity and access processes that can be eliminated, self-serviced, or fully automated.

  1. Design and maintain automation using REST APIs, JSON, SQL, and scripting languages (PowerShell, Python, JavaScript).

  1. Leverage AI-powered tools and agents (e.g., Microsoft Copilot, Claude) to accelerate connector development, troubleshooting, documentation, and operational insights.

  1. Apply AI to enhance governance activities such as access reviews, anomaly detection, and reporting - including Saviynt's native AI/rapid-onboarding capabilities.

Compliance, Audit & Operations

  1. Support audit readiness and access attestation for regulatory and compliance frameworks (e.g., SOX, SOC 1 / SOC 2, NIST, FedRAMP).

  1. Maintain the data quality behind certifications - identity correlation, role definitions, and application onboarding.

  1. Own resolution of complex incidents and service requests through ITSM platforms (e.g., ServiceNow), ensuring SLA adherence, and mentor junior engineers on identity concepts and tooling.

Qualifications

Required Qualifications

  1. Strong understanding of IAM principles, including user lifecycle management, role-based access control (RBAC), least privilege, and segregation of duties (SoD), and PAM.

  1. 5+ years of hands-on IAM engineering experience, including deep, demonstrable expertise configuring and developing on Saviynt EIC (IGA).

  1. Demonstrated experience with enterprise-scale IAM implementations, ideally in organizations with hundreds of applications.

  1. Proficient with REST APIs, JSON, SQL, and scripting languages (e.g., PowerShell, Python, JavaScript).

  1. Experience conducting or supporting access certification campaigns, audit activities, and compliance-driven controls.

  1. Familiarity with application infrastructure and architecture (Windows/Linux, cloud platforms like Azure, AWS, GCP).

  1. Excellent troubleshooting, debugging, communication, and documentation skills.

  1. Ability to work independently and manage priorities in a fast-paced environment.

Preferred Qualifications

  1. Experience with PAM platforms, procedures, implementations, and best practices. (Privileged Access Management).

  1. Experience governing non-human and/or agentic (AI agent) identities and secrets management (e.g., Azure Key Vault).

  1. Knowledge of Active Directory, Azure AD, and identity federation technologies (SAML, OAuth, OIDC).

  1. Experience using AI tools and developing agents (e.g., Microsoft Copilot, Claude) to improve operational efficiency.

  1. Prior experience in regulated environments (e.g., SOX, HIPAA, GDPR).

  1. IAM certifications (e.g., CIAM, CISSP, Saviynt Certified Professional) are a plus.

  1. 5+ years of hands-on development experience with IGA, including configuration, workflows, and connector development.

  1. U.S. Citizenship is required for this position due to the sensitive nature of the identity and access systems supported and applicable regulatory/compliance obligations.

Career Interests

Information Technology

Compensation Info

The U.S. salary range for this position is $86,500.00-$152,500.00. This range is subject to change as Deltek takes a number of factors into consideration when determining individual base pay, such as location, job-related knowledge, skills and experience. Certain roles are eligible for additional rewards, including incentive compensation and equity.

Benefits and perks listed here may vary depending on the nature of employment with Deltek. Employees have access to healthcare benefits, a 401(k) plan and company match, paid vacation time and holidays, well-living programs, short-term and long-term disability coverage, basic life insurance and tuition reimbursement.

Position Type

FT

Travel Requirements

10%

Compliance Requirements

Certain roles may have additional privacy, security and compliance requirements to the extent they support Costpoint GCCM or similar product offerings.

EEO Statement

Deltek, Inc. is an Equal Opportunity / Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected veteran status.

E-Verify Statement

Deltek, Inc., utilizes the E-Verify program with every potential new hire. This makes it possible for us to make certain that every employee who works for Deltek is eligible to work in the United States. To learn more about E-Verify you can call 1-800-255-7688 or visit their website by clicking the logo below. E-Verify is a registered trademark of the United States Department of Homeland Security.

Applicant Privacy Notice

Deltek is committed to the protection and promotion of your privacy. In connection with your application for employment with us at Deltek, it is necessary for us to collect, store and use information about you ("Personal Data") to administer and evaluate your application. We are the "controller" of the Personal Data you provide us and will process any such Personal Data in accordance with applicable law and the statements contained in this
Candidate Privacy Notice
Additionally, we have not sold and do not sell Personal Data you provide to us through the job application process.

Important: Protect Yourself from Recruitment Scams
Bad actors or scammers may try to impersonate Deltek and send fake job offers to people. Messages from Deltek about employment opportunities will be from an @deltek.com account or Enterprise@trm.brassring.com, never from free services like Gmail or Yahoo. Please look carefully at the email address that provides any job offer, as some fake accounts are created to look like a legitimate domain name or email address. We will also never ask you to pay money at any point in the hiring process, whether for training, equipment, background checks, or anything else. If you receive a suspicious offer claiming to be from Deltek, do not share personal or financial information. Report any suspicious communication to Secure@deltek.com and consider reporting it to law enforcement.

Job Expires

11-Sep-2027

Applied = 0

(web-665cd84569-z5knv)