Why UKG:
At UKG, the work you do matters. The code you ship, the decisions you make, and the care you show a customer all add up to real impact. Today, tens of millions of workers start and end their days with our workforce operating platform. Helping people get paid, grow in their careers, and shape the future of their industries. That’s what we do.
We never stop learning. We never stop challenging the norm. We push for better, and we celebrate the wins along the way. Here, you’ll get flexibility that’s real, benefits you can count on, and a team that succeeds together. Because at UKG, your work matters—and so do you.
About the Role
UKG is seeking a highly skilled Staff Information Security Engineer to join our Identity & Access Management (IAM) team. In this role, you will provide technical leadership in building, automating, and operating secure, scalable, and resilient IAM platforms. You will drive DevSecOps best practices across identity services, enabling secure software delivery, infrastructure automation, and cloud-native security.
As a Staff Engineer, you will collaborate closely with Security, Platform Engineering, Cloud Infrastructure, Product Engineering, and DevOps teams to improve platform reliability, accelerate deployments, and strengthen UKG's identity security capabilities through automation and engineering excellence.
Key Responsibilities
- Design, build, and maintain secure, scalable, and highly available IAM platform infrastructure.
- Lead DevSecOps initiatives by implementing CI/CD pipelines, Infrastructure as Code (IaC), and automated deployment strategies.
- Develop automation for IAM platform provisioning, configuration management, monitoring, patching, and operational workflows.
- Partner with IAM engineering teams to automate deployment and lifecycle management of identity platforms and security services.
- Design and implement cloud-native architectures supporting high availability, resiliency, and disaster recovery.
- Build reusable automation frameworks using scripting languages and infrastructure automation tools.
- Integrate security controls, secrets management, certificate management, and policy enforcement into CI/CD pipelines.
- Establish platform observability through logging, monitoring, alerting, and performance optimization.
- Lead root cause analysis for complex production issues and implement long-term reliability improvements.
- Drive engineering standards, platform modernization, and operational excellence across IAM services.
- Mentor engineers, conduct design and code reviews, and promote DevSecOps best practices throughout the organization.
- Collaborate with cross-functional teams to ensure security, compliance, and operational requirements are incorporated into engineering solutions.
Required Qualifications
- Bachelor's degree in computer science, Information Technology, Cybersecurity, or a related field.
- 8+ years of experience in DevOps, Platform Engineering, Site Reliability Engineering (SRE), Cloud Engineering, or Security Engineering.
- Strong experience designing and supporting enterprise CI/CD platforms using tools such as GitHub Actions, Jenkins, Azure DevOps, or GitLab CI.
- Hands-on experience with Infrastructure as Code using Terraform, Ansible, or similar automation frameworks.
- Experience with container technologies including Docker and Kubernetes/OpenShift.
- Strong expertise in Linux administration and scripting using Python, Bash, or PowerShell.
- Experience with public cloud platforms, preferably AWS, Azure, or Google Cloud Platform.
- Experience implementing monitoring and observability solutions such as Prometheus, Grafana, Splunk, Datadog, or ELK.
- Working knowledge of identity and access management concepts, including authentication, authorization, RBAC, SSO, and federation.
- Experience integrating secrets management and certificate management solutions such as HashiCorp Vault, Google Secret Manager, DigiCert, or similar technologies.
- Strong understanding of DevSecOps principles, secure software delivery, and cloud security best practices.
Preferred Qualifications
- Experience supporting enterprise IAM platforms such as Saviynt, SailPoint, Ping Identity, Okta, Microsoft Entra ID, or CyberArk.
- Experience implementing Zero Trust architecture and security automation.
- Knowledge of authentication protocols including OAuth 2.0, OpenID Connect (OIDC), SAML, LDAP, and SCIM.
- Experience working in Agile environments and leading technical initiatives across distributed teams.
- Relevant certifications in AWS, Azure, Kubernetes (CKA), Terraform, HashiCorp Vault, or Security (CISSP, Security+, etc.) are highly desirable.
Technical Skills
- DevSecOps & CI/CD
- GitHub Actions, Jenkins, Azure DevOps, GitLab CI
- Terraform, Ansible
- Docker & Kubernetes/OpenShift
- AWS, Azure, Google Cloud Platform
- Python, Bash, PowerShell
- Linux Administration
- HashiCorp Vault, Google Secret Manager
- DigiCert & Certificate Lifecycle Management
- Prometheus, Grafana, Splunk, Datadog
- Git & Version Control
- OAuth 2.0, OpenID Connect (OIDC), SAML, LDAP, SCIM
- Infrastructure as Code (IaC)
- Site Reliability Engineering (SRE)
Company Overview:
UKG is the Workforce Operating Platform that puts workforce understanding to work. With the world's largest collection of workforce insights, and people-first AI, our ability to reveal unseen ways to build trust, amplify productivity, and empower talent, is unmatched. It's this expertise that equips our customers with the intelligence to solve any challenge in any industry — because great organizations know their workforce is their competitive edge. Learn more at ukg.com.
UKG is proud to be an equal opportunity employer and is committed to promoting diversity and inclusion in the workplace, including the recruitment process.
Disability Accommodation in the Application and Interview Process
For individuals with disabilities that need additional assistance at any point in the application and interview process, please email [email protected]