IAM Software Engineer III- Eng
Role details
Job location
Tech stack
Job description
UKG is seeking a Software Engineer III to join our Enterprise Identity and Access Management (IAM) team within Global Security. This role is responsible for designing, developing, and supporting software solutions that enable secure identity governance, privileged access management, authentication, and authorization across UKG's enterprise and cloud environments.
You will work closely with Security Engineering, Cloud Engineering, Platform Engineering, and application teams to develop scalable IAM capabilities, automate security controls, and integrate applications with enterprise identity platforms. This role is ideal for a highly technical engineer who enjoys building solutions at the intersection of software development, cloud security, and identity management.
About the Role
- Design, develop, and maintain IAM, IGA, and PAM solutions that support secure access management across enterprise and cloud environments
- Develop and enhance integrations between applications, cloud platforms, and identity providers using REST APIs and industry-standard authentication protocols
- Build and maintain services, automation, and tooling utilizing Go, C#, Python, and cloud-native technologies
- Develop scalable solutions to automate identity lifecycle management, access provisioning, de-provisioning, and privileged access workflows
- Design and implement integrations leveraging SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), LDAP, and Active Directory
- Collaborate with application teams to onboard enterprise applications into IAM, IGA, and PAM platforms
- Develop and maintain integrations with Saviynt and other enterprise identity solutions using APIs, workflows, and automation frameworks
- Design and implement secure access patterns across Google Cloud Platform (GCP), Amazon Web Services (AWS), and enterprise infrastructure
- Build automation and orchestration capabilities that improve operational efficiency, scalability, and reliability
- Participate in architecture reviews and provide guidance on authentication, authorization, identity governance, and privileged access management best practices
- Troubleshoot and resolve complex identity, authentication, authorization, and integration issues across cloud and enterprise environments
- Develop and maintain Infrastructure-as-Code (IaC) solutions to support IAM and cloud security services
- Partner with Security Engineering teams to implement and improve security controls, monitoring, and access management capabilities
- Contribute to engineering standards, code reviews, technical documentation, and platform reliability initiatives
Requirements
- 5+ years of experience in software engineering, security engineering, identity and access management, or a related technical field
- Experience developing applications or services using one or more programming languages such as Go, C#, or Python
- Experience working with REST APIs, microservices, and system integrations
- Experience implementing or supporting Identity and Access Management (IAM), Identity Governance and Administration (IGA), or Privileged Access Management (PAM) solutions
- Experience integrating applications using SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), LDAP, and Active Directory
- Experience working with cloud platforms such as Google Cloud Platform (GCP) and/or Amazon Web Services (AWS)
- Experience troubleshooting authentication, authorization, and identity federation issues
- Understanding of secure software development practices and application security principles
- Experience using GitHub, source control systems, CI/CD pipelines, and modern development workflows
- Strong analytical, problem-solving, and debugging skills
- Ability to collaborate effectively across engineering, security, and platform teams, * Experience developing integrations with Saviynt or other enterprise identity governance platforms
- Experience building automation for identity lifecycle management, access provisioning, and privileged access workflows
- Experience working with Infrastructure-as-Code tools such as Terraform
- Experience building cloud-native applications and services
- Experience with event-driven architectures, serverless technologies, or workflow orchestration platforms
- Experience implementing security controls within AWS and GCP environments
- Familiarity with Active Directory, Entra ID, or enterprise directory services
- Experience with PAM technologies and privileged account automation
- Experience optimizing and scaling enterprise identity platforms through automation and software development
- Experience working in Agile software development environments, UKG will never ask you for a copy of your driver's license, social security card, or passport during a job inter
Benefits & conditions
4.14.1 out of 5 stars Lowell, MA Hybrid work $102,300 - $147,050 a year, The pay range for this position is $102,300 to $147,050. The actual base pay offered may vary depending on skills, experience, job-related knowledge and work location. In addition to base pay, employees may be eligible to participate in a performance-based bonus plan and to receive restricted stock unit awards as part of total compensation. Learn more about UKG's benefits and rewards at https://www.ukg.com/about-us/careers/benefits