Sr Manager SAP Security Architect
Requisition ID: 6047
Country: United States
US Locations: Nashville, Cincinnati, Hermitage, Indianapolis, Kansas City, San Antonio, St. Louis, Tampa
Deloitte Global is the engine of the Deloitte network. Our professionals reach across disciplines and borders to develop and lead global initiatives. We deliver strategic programs and services that unite our organization.
Work you'll do
This role owns security architecture and design across the Enterprise Solutions portfolio. It defines how the portfolio's platforms — predominantly SAP (S/4HANA, SAP BTP, SAP Business Data Cloud, SAP HANA, Ariba, Fieldglass, Concur, and SuccessFactors), together with the Azure services and the AI and agentic platforms that increasingly surround and extend them — are designed, integrated, and operated securely. Working as a hands-on technical authority within the Enterprise Solutions Architecture team, the role establishes security patterns, identity and access designs, and control standards that every solution in the portfolio is expected to follow, and partners closely with the global cyber team to see those designs safely into production.
As the portfolio is modernized and “agentified” — embedding AI copilots and autonomous agents such as SAP Joule into core business platforms — the security expertise this role brings is central to success. Securing agentic AI (how agents authenticate, what data and actions they are authorized for, and how their behavior is governed) is the fastest-growing and highest-stakes area of the portfolio's risk surface. This role is expected to lead that agenda, not merely keep pace with it, and a genuine passion for agentic AI and its secure adoption is essential to the position.
The position is an individual-contributor architect role: it leads through technical expertise, influence, and the strength of its designs rather than through direct people management. Although the role has no direct reports, it provides dotted-line technical leadership — defining security architecture, standards, and security-related priorities for the DTECH Enterprise Solutions security team and the Basis team to implement. It does not guide these teams' day-to-day work. It is a trusted advisor to project teams, platform owners, and leadership on how to protect enterprise data and identities across a complex, multi-cloud, SAP-centric estate.
Key responsibilities
Security architecture & design
- Own the end-to-end security architecture for the Enterprise Solutions portfolio — defining reference architectures, security design patterns, and control standards that apply across SAP and non-SAP platforms.
- Produce fit-for-purpose security artifacts (security architecture overviews, high- and low-level designs, and architecture decision records) and review solution designs for security risk before build and deployment.
- Embed security-by-design and zero-trust principles into solution and integration architectures, including data protection, encryption, network segmentation, and secure API/integration patterns (e.g., across SAP BTP Integration Suite and Azure).
- Conduct security and risk assessments, threat modeling, and design reviews; define mitigations and track them to closure with delivery teams.
AI & agentic platform security (priority focus)
- Lead security architecture for the AI and agentic platforms that are increasingly embedded across the portfolio — including SAP Joule and other agentic/GenAI capabilities — as SAP and adjacent platforms are modernized and agentified. This is a defining, high-priority dimension of the role.
- Define how AI agents authenticate and are authorized: agent identity, scoped and least-privilege access, delegation and impersonation boundaries, data-access limits, and human-in-the-loop controls for autonomous actions.
- Establish safeguards for prompts, tools, and outputs (e.g., prompt-injection and data-exfiltration defenses) and secure patterns for agent-to-system and agent-to-agent (A2A) interactions across the SAP and cloud estate.
- Set the emerging security standards, guardrails, and reference patterns for agentic development — including tooling such as Claude and MCP-based integrations — enabling teams to adopt AI and agents rapidly without compromising enterprise data protection or risk posture.
- Act as the organization's go-to authority on agentic AI security, tracking a fast-moving landscape and translating it into practical, defensible guidance for delivery and platform teams.
SAP platform security
- Define and govern security architecture for the SAP estate — S/4HANA, SAP BTP, SAP Business Data Cloud (BDC), SAP HANA, Ariba, Fieldglass, Concur, and SuccessFactors — including authorization concepts, role design principles, segregation-of-duties considerations, and secure data flows between these platforms.
- Establish standards for securing SAP data in transit and at rest, and for secure integration between SAP applications and downstream/third-party systems.
Identity & access management (BTP-centric)
- Define the identity management architecture, strategy, and guidelines for SAP Business Technology Platform (BTP) — including SAP Cloud Identity Services (Identity Authentication / IAS and Identity Provisioning / IPS), trust configuration, role collections, and identity federation across the SAP landscape — for Basis and other teams to implement. This is a design and advisory responsibility, not hands-on configuration or oversight.
- Design authentication and single sign-on architectures using OAuth 2.0 / OIDC, SAML 2.0, and modern token-based patterns; define standards for federation between SAP BTP, SAP applications, and the enterprise identity provider (e.g., Microsoft Entra ID / Azure AD).
- Define identity lifecycle, provisioning/de-provisioning, and least-privilege access patterns spanning SAP and cloud services; align with enterprise IAM tooling and governance.
Cloud (Azure) security
- Apply and advise on Azure security technologies and services — identity (Entra ID), network security, key/secrets management, and workload protection — as they relate to hosting and integrating Enterprise Solutions platforms.
- Ensure cloud landing-zone, networking, and resilience patterns meet enterprise security and compliance expectations.
Leadership, governance & advisory
- Provide dotted-line technical leadership to the DTECH Enterprise Solutions security team — defining the security architecture, standards, and design guidance they follow, without directing their day-to-day work or holding formal reporting lines.
- Define the security standards and guidelines for the Basis team — secure configuration, hardening, patching, and access standards for the SAP technical landscape that the Basis team implements.
- Act as the security design authority within the architecture team; set standards that delivery teams follow and provide sign-off/assurance on security-critical designs.
- Align with the global cyber team, acting as the bridge between Enterprise Solutions architecture and enterprise cyber — ensuring portfolio security designs are consistent with cyber strategy, policy, and standards.
- Ensure security designs meet cyber and regulatory/compliance standards (e.g., SOX, data-privacy regulations), and provide assurance that architectures satisfy those requirements before go-live.
- Facilitate cyber reviews of solution and platform architectures — preparing the necessary artifacts, coordinating with cyber reviewers, and driving the remediation of findings to closure.
- Support the organization's Annual Controls Audit and Member Firm Controls Audits — providing security architecture evidence, control documentation, and remediation input as required.
- Advise and influence senior stakeholders on security risk, trade-offs, and remediation; translate complex security concepts into clear guidance for both technical and non-technical audiences.
- Mentor and uplift the security capability of architects and engineers across the portfolio through technical coaching and knowledge-sharing.
The team
Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in "what is" but rather "what can be" to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.
Qualifications
Required
- 10+ years of experience in enterprise IT, with a substantial track record in solution or security architecture on large, complex programs.
- Deep, hands-on security architecture experience across a SAP-centric landscape — demonstrable work securing S/4HANA and other SAP applications, and designing secure integrations between them.
- Strong command of identity and access management, including practical experience with OAuth 2.0 / OIDC and SAML 2.0, single sign-on, federation, and identity lifecycle/provisioning.
- Strong knowledge of identity management on SAP BTP (SAP Cloud Identity Services — IAS/IPS, trust, role collections, and federation), sufficient to define the architecture, standards, and guidelines for implementation teams.
- Working knowledge of Microsoft Azure security services and cloud security patterns (identity, network, key/secrets management), including integration between Azure and SAP.
- Proven ability to produce security architecture artifacts (HLD/LLD/ADRs), lead threat modeling and security/risk assessments, and drive designs into production.
- Experience partnering with an enterprise or global cyber function — aligning designs to cyber and regulatory standards, and preparing for and successfully navigating cyber/security architecture reviews.
- Demonstrated knowledge of AI and agentic AI concepts and associated security risks, with experience, training, certification, or project work involving LLMs, AI agents, SAP Joule, Claude, MCP-based integrations, or comparable technologies.
- Experience influencing and advising senior stakeholders and delivery teams as a recognized technical authority, and leading technical teams through influence and dotted-line relationships rather than direct authority.
Preferred
- Familiarity with SAP Business Data Cloud (BDC) and SAP HANA security, and with cloud procurement/HR SaaS platforms in the portfolio (Ariba, Fieldglass, Concur, SuccessFactors).
- Hands-on experience securing production AI/agentic deployments — agent identity and authorization, prompt/output safeguards, and agent-to-agent (A2A) or MCP-based integration security.
- Relevant security certifications (e.g., CISSP, CCSP, SABSA, TOGAF) and/or Azure security certifications (e.g., AZ-500) and SAP credentials.
- Familiarity with zero-trust, OWASP, RBAC/ABAC/ReBAC authorization models, and regulatory/compliance frameworks (e.g., SOX, data-privacy regulations).
Limited immigration sponsorship may be available.
Our culture
At Deloitte Global people are valued and respected for who they are – with opportunities to bring their unique perspectives, talents and passions to business challenges. Our global workspace creates room for individuality and collaboration. Ours is an inclusive, supportive, connected culture with a focus on development, flexibility, and well-being. This culture makes Deloitte Global one of the most rewarding places to work, and to transform your career.
Professional development
From entry-level employees to senior leaders, we believe in investing in you, helping you identify and hone your unique strengths at every step of your career. We offer opportunities to build new skills, take on leadership opportunities, and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career.
Benefits
At Deloitte, we value our people and offer employees a broad range of benefits. Our Total Rewards program reflects our continued commitment to lead from the front in everything we do—that’s why we take pride in offering a comprehensive variety of programs and resources to support your health and well-being.
Nearest Major Market: Nashville