About this role
System Engineer II
Company Summary: As the recognized global standard for project-based businesses, Deltek delivers software and information solutions to help organizations achieve their purpose. Our market leadership stems from the work of our diverse employees who are united by a passion for learning, growing and making a difference. At Deltek, we take immense pride in creating a balanced, values-driven environment, where every employee feels included and empowered to do their best work. Our employees put our core values into action daily, creating a one-of-a-kind culture that has been recognized globally. Thanks to our incredible team, Deltek has been named one of America's Best Midsize Employers by Forbes, a Best Place to Work by Glassdoor, a Top Workplace by The Washington Post and a Best Place to Work in Asia by World HRD Congress. www.deltek.com
Position Responsibilities: Key Responsibilities Identity & Access Management (Primary Focus)
• Own the design, administration, and continuous improvement of Entra ID (Azure AD) and on-premises Active Directory, including user lifecycle (Joiner-Mover-Leaver), group architecture, and directory synchronization.
• Design and manage group policies, MFA, and authentication controls; lead to troubleshooting of complex identity and access issues.
• Drive access provisioning and identity governance practices, including entitlement design, role-based access control (RBAC), least-privilege enforcement, and access certification/recertification campaigns.
• Contribute to segregation of duties (SoD) analysis, audit readiness, and access attestation processes.
• Partner with security teams to advance Zero Trust initiatives, identity protection, and compliance controls; act as an IAM subject matter expert in cross-functional security discussions.
• Help evaluate, pilot, and support the onboarding of Saviynt as our IGA platform, shaping how identity governance workflows evolve over time.
Messaging & Collaboration (Supporting Scope)
• Administer Exchange Online, hybrid mail flow, and Microsoft Teams, including distribution lists, shared mailboxes, and transport rules.
• Troubleshoot escalated issues related to mail delivery, Outlook, calendaring, and their integration with identity services.
Operations, Reliability, and Incident Management
• Own resolution of complex incidents and service requests through ITSM platforms (e.g., ServiceNow), ensuring timely communication and adherence to SLAs.
• Lead or participate in on-call rotation and major incident response as a senior escalation point.
• Drive root cause analysis and problem management, translating recurring issues into permanent fixes and system improvements.
Automation and AI-Driven Process Improvement
• Design and maintain PowerShell scripts and automation workflows (including Microsoft Graph API) that streamline identity and access operations end-to-end.
• Champion an automation-first approach, identifying manual processes across identity platform operations that can be eliminated or self-serviced.
• Leverage AI-powered tools such as Microsoft Copilot, scripting assistants, and workflow automation platforms to accelerate troubleshooting, generate scripts, improve documentation, and surface operational insights.
• Apply AI to enhance identity governance activities such as access reviews, anomaly detection, and reporting.
User Experience and Continuous Improvement
• Partner with service desk, endpoint, and security teams to resolve identity and access issues and elevate the overall user experience.
• Analyze recurring access and authentication trends; build knowledge base content and self-service capabilities to reduce ticket volume.
• Mentor junior team members on identity concepts, tooling, and troubleshooting methodology.
Qualifications: Required Qualifications
• 5+ years of experience supporting enterprise Microsoft identity environments, with hands-on depth in Entra ID (Azure AD), Active Directory, and Microsoft 365 administration.
• Advanced troubleshooting skills across identity, authentication, and access management.
• Strong understanding of directory services, group policy, DNS, and access control models (RBAC, least privilege).
• Proficient automation & scripting with PowerShell, AI agents using Copilot & Claude, including experience with Microsoft Graph API/SDK for automation.
• Demonstrated experience designing or administering Conditional Access, MFA, and identity protection controls.
Preferred Qualifications
• Experience with identity governance concepts or platforms (e.g., Saviynt, SailPoint, Okta IGA, CyberArk) — access certifications, entitlement management, SoD.
• Familiarity with Microsoft Defender for Office 365 and broader identity-related security controls.
• Experience with audit, compliance, or access to attestation processes (e.g., SOX controls).
• Experience with ITSM platforms such as ServiceNow.
• Experience using AI tools and developing agents (e.g., Microsoft Copilot) to improve operational efficiency and automation.
• Microsoft certifications in Azure or Microsoft 365 (e.g., SC-300, MS-102) are a plus.
Applicant Privacy Notice: Deltek is committed to the protection and promotion of your privacy. In connection with your application for employment with us at Deltek, it is necessary for us to collect, store and use information about you (“Personal Data”) to administer and evaluate your application. We are the “controller” of the Personal Data you provide us and will process any such Personal Data in accordance with applicable law and the statements contained in this Employment Candidate Privacy Notice. Additionally, we have not sold and do not sell Personal Data you provide to us through the job application process.