> Markdown version of [/jobs/ext/1937001-sr-staff-iam-architect](https://www.wearedevelopers.com/jobs/ext/1937001-sr-staff-iam-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Staff IAM Architect - **Company:** UKG Inc. - **Location:** Fort Lauderdale, FL, United States - **Experience:** Expert - **Salary:** $145,600.0 - $209,300.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, User Authentication, Microsoft Azure, Software as a Service, Cloud Computing, Cyber Security, Information Systems, Software Design Patterns, Identity and Access Management, Lightweight Directory Access Protocols (LDAP), Microsoft Software, OAuth, OpenID, Ping (Networking Utility), Role-Based Access Control, Openid Connect, Zero Trust Network Access, Security Assertion Markup Language (SAML), Session Management, Google Cloud, Enterprise Software Applications, Cloud Platform System, Okta, Cyberark, Infrastructure as Code (IaC), Customer Identity Access Management, Information Technology, SailPoint, Devsecops - **Published:** August 5, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3341854085&tx=FJ3532FFP&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or equivalent experience. * 8+ years of experience in Identity & Access Management, Security Architecture, or related security engineering roles. * 3+ years designing and implementing enterprise IAM architectures. * Deep expertise in: Identity Governance & Administration (IGA), Privileged Access Management (PAM), Identity Lifecycle Management, Authentication and Authorization frameworks * Strong understanding of: SAML, OAuth 2.0, OpenID Connect (OIDC), LDAP, SCIM, Zero Trust principles, RBAC and ABAC models, Cloud identity architecture, Service accounts and machine identity management * Experience supporting cloud platforms such as Azure, AWS, or Google Cloud. * Strong written and verbal communication skills with the ability to communicate architectural concepts to technical and non-technical audiences., * Experience with Saviynt, SailPoint, Okta, CyberArk, BeyondTrust, Ping Identity, or similar IAM technologies. * Industry certifications such as: CISSP, CIAM, CISM, Microsoft Identity & Access Administrator, Certified Identity Management Professional (CIMP) * Experience supporting SaaS or large-scale cloud-native environments. * Familiarity with Infrastructure as Code (IaC), automation, and DevSecOps practices., * Strategic and systems thinker. * Strong security architecture and design skills. * Ability to balance security, usability, and operational efficiency. * Strong problem-solving and analytical capabilities. * Excellent stakeholder management and collaboration skills. * Ability to influence without direct authority. * Passion for driving identity modernization and continuous improvement. ## Description UKG is seeking an experienced Identity & Access Management (IAM) Architect to help define, design, and evolve the identity security architecture supporting our global workforce, enterprise platforms, and cloud environments. As a key member of the Global Security Identity & Access Management team, you will serve as the technical authority for identity architecture, partnering closely with Security Engineering, Product Engineering, Infrastructure, Cloud, and Enterprise Technology teams to build scalable and secure identity solutions. This role combines deep technical expertise, strategic thinking, and strong collaboration skills to help secure one of the world's largest workforce technology platforms., * Define and maintain enterprise IAM reference architectures, standards, and design patterns. * Develop scalable identity and access management solutions. * Partner with business and technology stakeholders to align identity capabilities with strategic security objectives. * Evaluate emerging identity technologies and recommend architectural improvements. * Design and optimize identity lifecycle management processes including provisioning, deprovisioning, role management, and access certification. * Develop scalable RBAC and ABAC models across enterprise applications and platforms. * Ensure identity governance solutions align with security, compliance, and business requirements. * Support implementation and enhancement of IGA platforms. * Drive modernization of enterprise authentication services and identity providers. * Develop secure access patterns for workforce, partner, and third-party access scenarios. * Design secure privileged access architectures across cloud, infrastructure, and application environments. * Enable just-in-time (JIT) access, credential vaulting, session management, and privileged account governance. * Support expansion of PAM capabilities across both human and non-human identities. * Partner with platform and engineering teams to reduce standing privilege and enforce least privilege principles. * Improve security, scalability, and operational efficiency of core identity services. * Perform security architecture reviews and threat modeling for identity-related initiatives. * Support audit, compliance, and regulatory requirements including SOC, ISO 27001, PCI, and privacy frameworks. * Identify and mitigate identity-related risks across the enterprise. * Collaborate with Security Engineering, Platform Engineering, Infrastructure, Cloud Operations, and Enterprise Technology teams. * Provide architectural guidance during projects, design reviews, and strategic initiatives. * Create and maintain architecture documentation, standards, and implementation guidance. * Mentor IAM engineers and contribute to the development of identity security best practices. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)