Sr. Staff IAM Architect

UKG Inc.
Lowell, MA, United States
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
0 years minimum
Working hours
Regular working hours

Tech stack

Amazon Web Services User Authentication Microsoft Azure Cloud Computing Cloud Foundry Cyber Security Information Systems Software Design Patterns Identity and Access Management Lightweight Directory Access Protocols (LDAP) OAuth OpenID
+8 more
Role-Based Access Control Openid Connect Zero Trust Network Access Security Assertion Markup Language (SAML) Session Management Google Cloud Enterprise Software Applications Information Technology

Job description

Experteer Overview As a Sr. Staff IAM Architect, you define and evolve UKG’s identity security architecture for a global workforce and cloud environments. You will act as the technical authority for identity across security, product, and infrastructure teams to build scalable, secure identity solutions. You’ll drive modernization of authentication, access governance, and privilege management in a large, cloud-native platform. This role offers impact through shaping identity strategy, improving security posture, and enabling scalable operations. You will join a mission-driven security team that partners across the organization to protect critical workforce data. Compensation / Benefits * Define and maintain enterprise IAM reference architectures, standards, and design patterns * Develop scalable identity and access management solutions * Partner with business and technology stakeholders to align identity capabilities with security objectives * Evaluate emerging identity technologies and recommend architectural improvements * Design and optimize identity lifecycle management processes including provisioning, deprovisioning, role management, and access certification * Develop scalable RBAC and ABAC models across enterprise applications and platforms * Ensure identity governance solutions align with security, compliance, and business requirements * Support implementation and enhancement of IGA platforms * Drive modernization of enterprise authentication services and identity providers * Develop secure access patterns for workforce, partner, and third-party access scenarios * Design secure privileged access architectures across cloud, infrastructure, and application environments * Enable just-in-time (JIT) access, credential vaulting, session management, and privileged account governance * Support expansion of PAM capabilities across both human and non-human identities * Partner with platform and engineering teams to reduce standing privilege and enforce least privilege principles * Improve security, scalability, and operational efficiency of core identity services * Perform security architecture reviews and threat modeling for identity-related initiatives * Support audit, compliance, and regulatory requirements including SOC, ISO 27001, PCI, and privacy frameworks * Identify and mitigate identity-related risks across the enterprise * Collaborate with Security Engineering, Platform Engineering, Infrastructure, Cloud Operations, and Enterprise Technology teams * Provide architectural guidance during projects, design reviews, and strategic initiatives * Create and maintain architecture documentation, standards, and implementation guidance * Mentor IAM engineers and contribute to the development of identity security best practices Tasks * Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or equivalent experience * 8+ years of experience in Identity & Access Management, Security Architecture, or related security engineering roles * 3+ years designing and implementing enterprise IAM architectures * Deep expertise in: Identity Governance & Administration (IGA), Privileged Access Management (PAM), Identity Lifecycle Management, Authentication and Authorization frameworks * Strong understanding of: SAML, OAuth 2.0, OpenID Connect (OIDC), LDAP, SCIM, Zero Trust principles, RBAC and ABAC models, Cloud identity architecture, Service accounts and machine identity management * Experience supporting cloud platforms such as Azure, AWS, or Google Cloud * Strong written and verbal communication skills with the ability to communicate architectural concepts to technical and non-technical audiences Key requirements * performance-based bonus plan * restricted stock unit awards

Requirements

including * Improve security, scalability, and operational efficiency of core identity services * Perform security architecture reviews and threat modeling for identity-related initiatives * Support audit, compliance, and regulatory requirements including SOC, ISO 27001, PCI, and privacy frameworks * Identify and mitigate identity-related risks across the enterprise * Collaborate with Security Engineering, Platform Engineering, Infrastructure, Cloud Operations, and Enterprise Technology teams * Provide architectural guidance during projects, design reviews, and strategic initiatives * Create and maintain architecture documentation, standards, and implementation guidance * Mentor IAM engineers and contribute to the development of identity security best practices Tasks * Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or equivalent experience * 8+ years of experience in Identity & Access Management, Security Architecture, or related security engineering roles * 0 _ years designing and implementing enterprise IAM architectures * Deep expertise in: Identity Governance & Administration (IGA), Privileged Access Management (PAM), Identity Lifecycle Management, Authentication and Authorization frameworks * Strong understanding of: SAML, OAuth 2.0, OpenID Connect (OIDC), LDAP, SCIM, Zero Trust principles, RBAC and ABAC models, Cloud identity architecture, Service accounts and machine identity management * Experience supporting cloud platforms such as Azure, AWS, or Google Cloud * Strong written and verbal communication skills with the ability to communicate architectural concepts to technical and non-technical audiences Key requirements * performance-based bonus plan * restricted stock unit awards

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · WWC 2024

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

2:24 min

Securing cloud deployments by utilizing OpenID Connect mapping

Chris Ayers · LIVE

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

Videos

See all

Related articles

See all