Sr Manager SAP Security Architect
Deloitte US · Cincinnati, United States +5 · 1d ago
This role owns security architecture and design across the Enterprise Solutions portfolio. It defines how the portfolio's platforms — predominantly SAP (S/4HANA, SAP BTP, SAP Business Data Cloud, SAP HANA, Ariba, Fieldglass, Concur, and SuccessFactors), together with the Azure services and the AI and agentic platforms that increasingly surround and extend them — are designed, integrated, and operated securely. Working as a hands-on technical authority within the Enterprise Solutions Architecture team, the role establishes security patterns, identity and access designs, and control standards that every solution in the portfolio is expected to follow, and partners closely with the global cyber team to see those designs safely into production.
As the portfolio is modernized and “agentified” — embedding AI copilots and autonomous agents such as SAP Joule into core business platforms — the security expertise this role brings is central to success. Securing agentic AI (how agents authenticate, what data and actions they are authorized for, and how their behavior is governed) is the fastest-growing and highest-stakes area of the portfolio's risk surface. This role is expected to lead that agenda, not merely keep pace with it, and a genuine passion for agentic AI and its secure adoption is essential to the position.
The position is an individual-contributor architect role: it leads through technical expertise, influence, and the strength of its designs rather than through direct people management. Although the role has no direct reports, it provides dotted-line technical leadership — defining security architecture, standards, and security-related priorities for the DTECH Enterprise Solutions security team and the Basis team to implement. It does not guide these teams' day-to-day work. It is a trusted advisor to project teams, platform owners, and leadership on how to protect enterprise data and identities across a complex, multi-cloud, SAP-centric estate.
Key responsibilities
Security architecture & design
- Own the end-to-end security architecture for the Enterprise Solutions portfolio — defining reference architectures, security design patterns, and control standards that apply across SAP and non-SAP platforms.
- Produce fit-for-purpose security artifacts (security architecture overviews, high- and low-level designs, and architecture decision records) and review solution designs for security risk before build and deployment.
- Embed security-by-design and zero-trust principles into solution and integration architectures, including data protection, encryption, network segmentation, and secure API/integration patterns (e.g., across SAP BTP Integration Suite and Azure).
- Conduct security and risk assessments, threat modeling, and design reviews; define mitigations and track them to closure with delivery teams.
AI & agentic platform security (priority focus)
- Lead security architecture for the AI and agentic platforms that are increasingly embedded across the portfolio — including SAP Joule and other agentic/GenAI capabilities — as SAP and adjacent platforms are modernized and agentified. This is a defining, high-priority dimension of the role.
- Define how AI agents authenticate and are authorized: agent identity, scoped and least-privilege access, delegation and impersonation boundaries, data-access limits, and human-in-the-loop controls for autonomous actions.
- Establish safeguards for prompts, tools, and outputs (e.g., prompt-injection and data-exfiltration defenses) and secure patterns for agent-to-system and agent-to-agent (A2A) interactions across the SAP and cloud estate.
- Set the emerging security standards, guardrails, and reference patterns for agentic developmThe team
Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in "what is" but rather "what can be" to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.
QualificationsRequired
- 10+ years of experience in enterprise IT, with a substantial track record in solution or security architecture on large, complex programs.
- Deep, hands-on security architecture experience across a SAP-centric landscape — demonstrable work securing S/4HANA and other SAP applications, and designing secure integrations between them.
- Strong command of identity and access management, including practical experience with OAuth 2.0 / OIDC and SAML 2.0, single sign-on, federation, and identity lifecycle/provisioning.
- Strong knowledge of identity management on SAP BTP (SAP Cloud Identity Services — IAS/IPS, trust, role collections, and federation), sufficient to define the architecture, standards, and guidelines for implementation teams.
- Working knowledge of Microsoft Azure security services and cloud security patterns (identity, network, key/secrets management), including integration between Azure and SAP.
- Proven ability to produce security architecture artifacts (HLD/LLD/ADRs), lead threat modeling and security/risk assessments, and drive designs into production.
- Experience partnering with an enterprise or global cyber function — aligning designs to cyber and regulatory standards, and preparing for and successfully navigating cyber/security architecture reviews.
- Demonstrated knowledge of AI and agentic AI concepts and associated security risks, with experience, training, certification, or project work involving LLMs, AI agents, SAP Joule, Claude, MCP-based integrations, or comparable technologies.
- Experience influencing and advising senior stakeholders and delivery teams as a recognized technical authority, and leading technical teams through influence and dotted-line relationships rather than direct authority.
Preferred
- Familiarity with SAP Business Data Cloud (BDC) and SAP HANA security, and with cloud procurement/HR SaaS platforms in the portfolio (Ariba, Fieldglass, Concur, SuccessFactors).
- Hands-on experience securing production AI/agentic deployments — agent identity and authorization, prompt/output safeguards, and agent-to-agent (A2A) or MCP-based integration security.
- Relevant security certifications (e.g., CISSP, CCSP, SABSA, TOGAF) and/or Azure security certifications (e.g., AZ-500) and SAP credentials.
- Familiarity with zero-trust, OWASP, RBAC/ABAC/ReBAC authorization models, and regulatory/compliance frameworks (e.g., SOX, data-privacy regulations).
Limited immigration sponsorship may be available.