About this role
Why UKG:
At UKG, the work you do matters. The code you ship, the decisions you make, and the care you show a customer all add up to real impact. Today, tens of millions of workers start and end their days with our workforce operating platform. Helping people get paid, grow in their careers, and shape the future of their industries. That’s what we do.
We never stop learning. We never stop challenging the norm. We push for better, and we celebrate the wins along the way. Here, you’ll get flexibility that’s real, benefits you can count on, and a team that succeeds together. Because at UKG, your work matters—and so do you.
Staff Information Security Engineer
About the Team
UKG is seeking a Staff Information Security Engineer to join our Enterprise Identity and Access Management (IAM) team within Global Security. This role is responsible for designing, developing, and supporting solutions that secure machine identities, certificates, secrets, and access management across UKG's enterprise and cloud environments.
You will work closely with Security Engineering, Cloud Engineering, Platform Engineering, Infrastructure Engineering, and application teams to build scalable certificate lifecycle management, secrets management, and IAM capabilities while driving automation, operational excellence, platform reliability, and observability across critical security services.
This role is ideal for a highly technical engineer who enjoys solving complex security and infrastructure challenges at the intersection of cloud security, identity management, automation, certificate management, and platform engineering.
About the Role
- Design, develop, and maintain enterprise certificate lifecycle management solutions supporting internal and external PKI environments
- Build and enhance secrets management capabilities utilizing HashiCorp Vault, Consul, and cloud-native security services
- Design, implement, and support highly available HashiCorp Vault environments, including disaster recovery, resiliency, performance optimization, and platform scalability
- Design and implement secure authentication and authorization patterns for applications, platforms, infrastructure, and machine identities
- Develop scalable solutions to automate certificate issuance, renewal, rotation, revocation, and inventory management
- Build and maintain automation and tooling utilizing PowerShell, Python, Terraform, GitHub Actions, APIs, and cloud-native technologies
- Design and implement secure secrets management workflows for credentials, API keys, tokens, certificates, and service accounts
- Develop and maintain Infrastructure-as-Code (IaC) solutions supporting IAM, secrets management, and certificate management services
- Design and implement IAM solutions across Amazon Web Services (AWS) and Google Cloud Platform (GCP)
- Develop automation to support identity lifecycle management, access provisioning, privileged access workflows, and machine identity governance
- Collaborate with application, infrastructure, and platform teams to integrate enterprise services with certificate management, IAM, and secrets management platforms
- Build reusable Terraform modules, automation frameworks, and deployment patterns that improve consistency, scalability, and operational efficiency
- Implement monitoring, observability, and operational dashboards utilizing Grafana, Prometheus, PagerDuty, and related tooling to improve platform reliability, alerting, and service health visibility
- Develop and maintain operational metrics, dashboards, alerts, and automated response workflows supporting IAM, secrets management, certificate management, and cloud security services
- Participate in architecture reviews and provide guidance on certificate management, machine identity security, secrets management, cloud IAM, and access management best practices
- Troubleshoot and resolve complex issues involving certificates, IAM, authentication, authorization, secrets management, and cloud security services
- Partner with Security Engineering teams to implement and improve security controls, monitoring, automation, and governance capabilities
- Contribute to engineering standards, technical documentation, automation frameworks, platform reliability initiatives, and operational maturity improvements
- Identify opportunities to reduce operational risk and manual effort through automation and process improvements
- Mentor engineers and share technical knowledge within the team
About You
Basic Qualifications
- 8+ years of experience in information security engineering, platform engineering, cloud engineering, systems engineering, identity and access management, or a related technical field
- Experience administering and supporting HashiCorp Vault in enterprise environments, including high availability and disaster recovery configurations
- Experience working with HashiCorp Consul and service discovery technologies
- Experience designing, implementing, or supporting certificate lifecycle management and PKI solutions
- Experience working with AWS IAM and/or GCP IAM
- Experience developing Infrastructure-as-Code solutions using Terraform
- Experience developing automation using PowerShell, Python, and scripting frameworks
- Experience building CI/CD automation utilizing GitHub Actions or similar platforms
- Experience implementing observability, monitoring, and alerting solutions utilizing Grafana, Prometheus, PagerDuty, or similar platforms
- Experience designing and supporting highly available, secure enterprise platforms
- Experience troubleshooting authentication, authorization, certificate, secrets management, and access-related issues
- Experience working with REST APIs, system integrations, and automation frameworks
- Strong analytical, problem-solving, and debugging skills
- Ability to collaborate effectively across engineering, infrastructure, security, and platform teams
Preferred Qualifications
- Experience designing and operating highly available HashiCorp Vault deployments at enterprise scale
- Experience implementing enterprise certificate lifecycle management platforms and automation frameworks
- Experience managing public and private PKI environments
- Experience implementing automated certificate issuance and renewal using ACME or similar protocols
- Experience designing and implementing machine identity management solutions
- Experience implementing Workload Identity Federation (WIF) or other keyless authentication solutions
- Experience securing and managing non-human identities, service accounts, and workload identities
- Experience working with Kubernetes, containerized workloads, and cloud-native platforms
- Experience developing reusable automation frameworks utilizing Terraform, PowerShell, Python, and GitHub Actions
- Experience implementing security controls and governance capabilities within AWS and GCP environments
- Experience implementing observability strategies for security and infrastructure platforms using Grafana, Prometheus, PagerDuty, and related monitoring technologies
- Familiarity with Identity Governance and Administration (IGA) and Privileged Access Management (PAM) platforms
- Experience supporting compliance and audit requirements related to identity, access management, certificates, and secrets management
- Experience improving operational maturity, platform observability, reliability, and automation at enterprise scale
- Experience working in Agile engineering environments
Company Overview:
UKG is the Workforce Operating Platform that puts workforce understanding to work. With the world's largest collection of workforce insights, and people-first AI, our ability to reveal unseen ways to build trust, amplify productivity, and empower talent, is unmatched. It's this expertise that equips our customers with the intelligence to solve any challenge in any industry — because great organizations know their workforce is their competitive edge. Learn more at ukg.com.
Equal Opportunity Employer
UKG is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, disability, religion, sex, age, national origin, veteran status, genetic information, and other legally protected categories.
View The EEO Know Your Rights poster
UKG participates in E-Verify. View the E-Verify posters here .
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Disability Accommodation in the Application and Interview Process
For individuals with disabilities that need additional assistance at any point in the application and interview process, please email [email protected] .
The pay range for this position is $115,100 to $165,450. The actual base pay offered may vary depending on skills, experience, job-related knowledge and work location. In addition to base pay, employees may be eligible to participate in a performance-based bonus plan and to receive restricted stock unit awards as part of total compensation. Learn more about UKG’s benefits and rewards at https://www.ukg.com/about-us/careers/benefits