Senior Manager, SAP Security Architect, Deloitte Global Technology
DeloitteDeloitte Global Technology is looking for a Senior Manager, SAP Security Architect to help shape security for a broad SAP-centric technology estate. The role is based in Toronto with a hybrid work arrangement, and an option to be located in Ottawa as part of the firm’s multi-city footprint. It’s a hands-on, technical authority position that suits a security architect who enjoys defining patterns, guiding complex solutions, and collaborating with global cyber teams to make secure production designs a reality.
In this role, you’ll operate as an individual contributor who leads by technical example and influence, not by direct reports. Deloitte’s Global Technology group backs a modern, agent-driven technology stack, where SAP platforms sit alongside Azure and AI-enabled capabilities. If you’re excited by the challenge of securing a modern, multi-cloud SAP landscape and shaping how AI copilots and agents integrate safely with core business systems, you’ll find this a rewarding fit.
As a part of a larger Deloitte ecosystem, this position sits at the intersection of architecture, security, and governance. Deloitte aims to make an impact that matters, and this role plays a critical part in protecting enterprise data and identities across a complex SAP-centric estate while aligning with global cyber strategy and regulatory requirements.
Guarding the SAP fortress: a typical day
Your days will orbit around defining and refining security architecture for the Enterprise Solutions portfolio, covering SAP and non-SAP platforms, and producing design artifacts that guide how designs are implemented and secured. You’ll weave security-by-design and zero-trust principles into data protection, encryption, segmentation, and secure SAP BTP and Azure integrations, then run risk assessments and threat modeling to reveal mitigations that feed into project plans.
Another key focus is the security of AI and agentic platforms, including SAP Joule and GenAI capabilities. You’ll shape how agents authenticate, what data they may access, how they’re authorized, and how human oversight remains in the loop. You’ll also design guardrails for prompt handling, data limits, and safe agent-to-system and agent-to-agent interactions to protect enterprise data and risk posture.
You’ll govern the security of the SAP landscape, S/4HANA, SAP BTP, Business Data Cloud, HANA, Ariba, Fieldglass, Concur, and SuccessFactors, covering authorization, role design, data flows, and third-party integrations. You’ll establish standards for data in transit and at rest and participate in shaping secure integration patterns across the portfolio.
Identity and access management will be a central thread: you’ll outline a cloud identity architecture for SAP Cloud Identity Services, design federation and trust patterns, and define authentication and SSO approaches using OAuth 2.0/OIDC and SAML 2.0. You’ll also map identity lifecycles, provisioning, and least-privilege concepts in line with IAM governance, while guiding how these designs translate into real-world configurations via advisory collaboration with delivery teams.
When it comes to cloud security, you’ll advise on Azure identity, network security, key and secret management, and workload protection, ensuring landing zones and networking patterns meet security and compliance expectations. You’ll provide dotted-line technical leadership to security and Basis teams, set secure configuration standards, and act as a security design authority to review and sign off on critical designs. In parallel, you’ll help the organization align with SOX, data-privacy, and regulatory requirements and support cyber reviews and audits with the right evidence. You’ll mentor architects and engineers and share guidance with senior stakeholders on security trade-offs.
What the role demands from you
Required
- A track record of 10+ years in enterprise IT, with substantial experience in security or solution architecture on large, complex programs.
- Deep practical security architecture experience across a SAP-centric landscape, including work that secured S/4HANA and built secure integrations between SAP components.
- Strong command of identity and access management, including OAuth 2.0/OIDC, SAML 2.0, single sign-on, federation, and lifecycle provisioning.
- Solid knowledge of SAP Cloud Identity Services (IAS/IPS), trust, role collections, and federation, enough to define architectures, standards, and guidelines for implementation teams.
- Working knowledge of Microsoft Azure security services and cloud security patterns, with experience integrating Azure and SAP.
- Proven ability to produce security architecture artifacts (high-level and low-level designs, ADRs), lead threat modeling and risk assessments, and drive designs into production.
- Experience partnering with an enterprise or global cyber function to align designs with cyber and regulatory standards and to navigate security architecture reviews.
- Demonstrated knowledge of AI and agentic security concepts, with experience or training in LLMs, AI agents, SAP Joule, Claude, MCP-based integrations, or comparable technologies.
- Ability to influence and advise senior stakeholders and delivery teams as a trusted technical authority, using influence rather than direct managerial authority.
Preferred
- Familiarity with SAP Business Data Cloud and SAP HANA security, plus knowledge of cloud-procurement or HR SaaS platforms in the portfolio (Ariba, Fieldglass, Concur, SuccessFactors).
- Hands-on experience securing production AI/agent deployments, agent identity and authorization, prompt safeguards, and agent-to-agent or MCP-based integration security.
- Relevant security certifications (for example CISSP, CCSP, SABSA, TOGAF) and/or Azure security credentials and SAP credentials.
- Familiarity with zero-trust, OWASP, RBAC/ABAC/ReBAC models, and regulatory/compliance frameworks (SOX, data privacy regulations).
What you’ll earn and the big-picture perks
The salary range for this role is 104,000 CAD to 215,000 CAD per year, with eligible participants in the firm’s bonus program. Deloitte’s Total Rewards package goes beyond base pay, recognizing contributions and supporting well-being through a mix of programs and benefits. In addition to the competitive base, the package includes a mental health benefit up to 4,000 CAD per year, a 1,300 CAD flexible benefit spending account, and firm-wide events and growth opportunities such as Deloitte Days and Development and Innovation Days, along with flexible work arrangements and a hybrid setup.
The role sits in Deloitte’s Toronto presence with permission for Ottawa as part of the available locations, and the work model is hybrid. Deloitte highlights its Canadian scope and its commitment to flexible options that help people contribute where they work best.
Tips for making your case, with a buddy‑to‑buddy touch
First, put SAP security architecture and agentic AI expertise up front on your resume. Lead with a concise snapshot of your 10+ years in enterprise IT, then highlight hands-on work securing SAP S/4HANA and integrations, plus your experience with SAP BTP, IAS/IPS, and Azure integrations. Tie in concrete artifacts you produced, such as architecture designs, risk assessments, and threat models tied to real projects.
Second, prove you’ve got the must-haves by weaving in outcomes. For example, point to specific security architecture artifacts you authored (high-level and low-level designs, ADRs), risk mitigation plans you led, and how you partnered with a global cyber function to pass architecture reviews. Show evidence of delivering designs into production and how you aligned them with SOX and privacy safeguards.
Third, prepare to talk through AI security in detail. Be ready to discuss agent identity, authentication, authorization, and data limits for agentic platforms, plus guardrails you’ve set for prompt handling and A2A or MCP-based integrations. A concrete example of safeguarding enterprise data in an AI deployment can go a long way.
Fourth, consider a thoughtful question to close with. Ask how Deloitte plans to govern agentic AI security across SAP Joule and related AI integrations, and how the team balances innovation with risk, especially during cyber reviews and audits. This shows you’re thinking about both business impact and risk posture from day one.