About this role
Job Type: Permanent Work Model: Remote Reference code: 135442 Primary Location: Toronto, ON All Available Locations: Toronto, ON; Ottawa, ON Our Purpose At Deloitte, our Purpose is to make an impact that matters. We exist to inspire and help our people, organizations, communities, and countries to thrive by building a better future. Our work underpins a prosperous society where people can find meaning and opportunity. It builds consumer and business confidence, empowers organizations to find imaginative ways of deploying capital, enables fair, trusted, and functioning social and economic institutions, and allows our friends, families, and communities to enjoy the quality of life that comes with a sustainable future. And as the largest 100% Canadian-owned and operated professional services firm in our country, we are proud to work alongside our clients to make a positive impact for all Canadians. By living our Purpose, we will make an impact that matters. Have many careers in one Firm. Enjoy flexible, proactive, and practical benefits that foster a culture of well-being and connectedness. Learn from deep subject matter experts through mentoring and on the job coaching -- Deloitte Global is the engine of the Deloitte network. Our professionals reach across disciplines and borders to develop and lead global initiatives. We deliver strategic programs and services that unite our organization. This role owns security architecture and design across the Enterprise Solutions portfolio. It defines how the portfolio's platforms — predominantly SAP (S/4HANA, SAP BTP, SAP Business Data Cloud, SAP HANA, Ariba, Fieldglass, Concur, and SuccessFactors), together with the Azure services and the AI and agentic platforms that increasingly surround and extend them — are designed, integrated, and operated securely. Working as a hands-on technical authority within the Enterprise Solutions Architecture team, the role establishes security patterns, identity and access designs, and control standards that every solution in the portfolio is expected to follow, and partners closely with the global cyber team to see those designs safely into production. As the portfolio is modernized and “agentified” — embedding AI copilots and autonomous agents such as SAP Joule into core business platforms — the security expertise this role brings is central to success. Securing agentic AI (how agents authenticate, what data and actions they are authorized for, and how their behavior is governed) is the fastest-growing and highest-stakes area of the portfolio's risk surface. This role is expected to lead that agenda, not merely keep pace with it, and a genuine passion for agentic AI and its secure adoption is essential to the position. The position is an individual-contributor architect role: it leads through technical expertise, influence, and the strength of its designs rather than through direct people management. Although the role has no direct reports, it provides dotted-line technical leadership — defining security architecture, standards, and security-related priorities for the DTECH Enterprise Solutions security team and the Basis team to implement. It does not guide these teams' day-to-day work. It is a trusted advisor to project teams, platform owners, and leadership on how to protect enterprise data and identities across a complex, multi-cloud, SAP-centric estate. What will your typical day look like? Security architecture & design Own Enterprise Solutions security architecture, reference designs, patterns and controls across SAP/non-SAP platforms. Produce architecture overviews, high/low-level designs and decision records; review security risk before deployment. Embed security-by-design and zero-trust principles, including data protection, encryption, segmentation and secure SAP BTP/Azure integrations. Conduct risk assessments, threat modeling and design reviews; define and track mitigations. AI & agentic platform security Lead security architecture for AI/agentic platforms, including SAP Joule and GenAI capabilities. Define agent identity, authentication, authorization, least-privilege access, delegation, data limits and human-in-the-loop controls. Establish prompt-injection/data-exfiltration defenses and secure agent-to-system and agent-to-agent (A2A) patterns. Set guardrails for agentic development, including Claude and MCP integrations, protecting enterprise data and risk posture. SAP platform security Govern S/4HANA, SAP BTP, BDC, HANA, Ariba, Fieldglass, Concur and SuccessFactors security, including authorization, role design, segregation of duties and secure data flows. Define standards for SAP data in transit/at rest and third-party integrations. Identity & access management Define BTP identity architecture covering SAP Cloud Identity Services (IAS/IPS), trust, role collections and federation; a design/advisory role, not hands-on configuration. Design authentication/SSO using OAuth 2.0/OIDC, SAML 2.0 and token patterns; define federation across SAP and Microsoft Entra ID/Azure AD. Define identity lifecycle, provisioning/de-provisioning and least-privilege patterns aligned with IAM governance. Cloud (Azure) security Advise on Azure identity, network security, key/secrets management and workload protection. Ensure landing-zone, networking and resilience patterns meet security/compliance expectations. Leadership, governance & advisory Provide dotted-line technical leadership to the DTECH Enterprise Solutions security team, setting standards and guidance. Define Basis standards for secure configuration, hardening, patching and access. Act as security design authority, providing assurance/sign-off for security-critical designs. Align with global cyber strategy and standards; ensure compliance with SOX, data-privacy and regulatory requirements. Facilitate cyber reviews/remediation and support Annual Controls and Member Firm Controls Audits with security evidence. Advise senior stakeholders on security risks/trade-offs and mentor architects and engineers. About the team Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in "what is" but rather "what can be" to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived. Enough about us, let’s talk about you Qualifications Required 10+ years of experience in enterprise IT, with a substantial track record in solution or security architecture on large, complex programs. Deep, hands-on security architecture experience across a SAP-centric landscape — demonstrable work securing S/4HANA and other SAP applications, and designing secure integrations between them. Strong command of identity and access management, including practical experience with OAuth 2.0 / OIDC and SAML 2.0, single sign-on, federation, and identity lifecycle/provisioning. Strong knowledge of identity management on SAP BTP (SAP Cloud Identity Services — IAS/IPS, trust, role collections, and federation), sufficient to define the architecture, standards, and guidelines for implementation teams. Working knowledge of Microsoft Azure security services and cloud security patterns (identity, network, key/secrets management), including integration between Azure and SAP. Proven ability to produce security architecture artifacts (HLD/LLD/ADRs), lead threat modeling and security/risk assessments, and drive designs into production. Experience partnering with an enterprise or global cyber function — aligning designs to cyber and regulatory standards, and preparing for and successfully navigating cyber/security architecture reviews. Demonstrated knowledge of AI and agentic AI concepts and associated security risks, with experience, training, certification, or project work involving LLMs, AI agents, SAP Joule, Claude, MCP-based integrations, or comparable technologies. Experience influencing and advising senior stakeholders and delivery teams as a recognized technical authority, and leading technical teams through influence and dotted-line relationships rather than direct authority. Preferred Familiarity with SAP Business Data Cloud (BDC) and SAP HANA security, and with cloud procurement/HR SaaS platforms in the portfolio (Ariba, Fieldglass, Concur, SuccessFactors). Hands-on experience securing production AI/agentic deployments — agent identity and authorization, prompt/output safeguards, and agent-to-agent (A2A) or MCP-based integration security. Relevant security certifications (e.g., CISSP, CCSP, SABSA, TOGAF) and/or Azure security certifications (e.g., AZ-500) and SAP credentials. Familiarity with zero-trust, OWASP, RBAC/ABAC/ReBAC authorization models, and regulatory/compliance frameworks (e.g., SOX, data-privacy regulations). Total Rewards The salary range for this position is $104,000 - $215,000, and individuals may be eligible to participate in our bonus program. Deloitte is fair and competitive when it comes to the salaries of our people. We regularly benchmark across a variety of positions, industries, sectors, targets, and levels. Our approach is grounded on recognizing people's unique strengths and contributions and rewarding the value that they deliver. Our Total Rewards Package extends well beyond traditional compensation and benefit programs and is designed to recognize employee contributions, encourage personal wellness, and support firm growth. Along with a competitive base salary and variable pay opportunities, we offer a wide array of initiatives that differentiate us as a people-first organization. On top of our regular paid vacation days, some examples include: $4,000 per year for mental health support benefits, a $1,300 flexible benefit spending account, firm-wide closures known as "Deloitte Days", dedicated days of for learning (known as Development and Innovation Days), flexible work arrangements and a hybrid work structure. Our promise to our people: Deloitte is where potential comes to life. Be yourself, and more. We are a group of talented people who want to learn, gain experience, and develop skills. Wherever you are in your career, we want you to advance. You shape how we make impact. Diverse perspectives and life experiences make us better. Whoever you are and wherever you’re from, we want you to feel like you belong here. We provide flexible working options to support you and how you can contribute. Be the leader you want to be Some guide teams, some change culture, some build essential expertise. We offer opportunities and experiences that support your continuing growth as a leader. Have as many careers as you want. We are uniquely able to offer you new challenges and roles – and prepare you for them. We bring together people with unique experiences and talents, and we are the place to develop a lasting network of friends, peers, and mentors. The next step is yours At Deloitte, we are all about doing business inclusively – that starts with having diverse colleagues of all abilities. Deloitte encourages applications from all qualified candidates who represent the full diversity of communities across Canada. This includes, but is not limited to, people with disabilities, candidates from Indigenous communities, and candidates from the Black community in support of living our values, creating a culture of Diversity Equity and Inclusion and our commitment to our AccessAbility Action Plan , Reconciliation Action Plan and the BlackNorth Initiative . We encourage you to connect with us at [email protected] if you require an accommodation for the recruitment process (including alternate formats of materials, accessible meeting rooms or other accommodations) or [email protected] for any questions relating to careers for Indigenous peoples at Deloitte (First Nations, Inuit, Métis). When you apply, we will review your application using Deloitte's Global Talent Standards to ensure a consistent recruitment experience. Our recruitment advisors and hiring teams will utilize human screening combined with AI technology to help identify the skills and qualities that matter most to our business, while safeguarding your privacy and using AI responsibly. Deloitte Canada has 20 offices with representation across most of the country. We acknowledge that Deloitte offices stand on traditional, treaty, and unceded territories in what is now known as Canada. We recognize that Indigenous Peoples have been the caretakers of this land since time immemorial, nurturing its resources and preserving its natural beauty. We acknowledge this land is still home to many First Nations, Inuit, and Métis Peoples, who continue to maintain their deep connection to the land and its sacred teachings. We humbly acknowledge that we are all Treaty people, and we commit to fostering a relationship of respect, collaboration, and stewardship with Indigenous communities in our shared goal of reconciliation and environmental sustainability.