An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Acuity Inc. is seeking a senior Identity & Access Management architect to lead the design and delivery of a unified IAM and CIAM platform.
You will shape authentication and authorization across internal and customer-facing products, collaborating with security, engineering, and product teams to enable secure, scalable access at scale. You will work with Microsoft Entra ID, Okta and related standards (OAuth2, OIDC, SAML) to implement MFA, passwordless and adaptable access, while aligning with
Acuity Inc. (NYSE: AYI) is a market-leading industrial technology company. We use technology to solve problems in spaces, light and more things to come. Through our two business segments, Acuity Brands Lighting (ABL) and Acuity Intelligent Spaces (AIS), we design, manufacture, and bring to market products and services that make a valuable difference in people’s lives.
We achieve growth through the development of innovative new products and services, including lighting, lighting controls, building management solutions, and an audio, video and control platform. We focus on customer outcomes and drive growth and productivity to increase market share and deliver superior returns. We look to aggressively deploy capital to grow the business and to enter attractive new verticals.
Acuity Inc. is based in Atlanta, Georgia, with operations across North America, Europe and Asia. The Company is powered by approximately 13,000 dedicated and talented associates. Visit us at www.acuityinc.com .
At Acuity, we are building a modern, scalable Identity and Access Management (IAM) and Customer Identity and Access Management (CIAM) platform to support our growing portfolio of digital products and services.
This role will play a critical part in shaping and delivering our unified identity strategy, enabling secure, seamless authentication and authorization experiences for employees, customers, and partners.
You will work across both enterprise IAM and CIAM domains, leveraging industry leading platforms such as Microsoft Entra ID, Okta etc. and modern identity standards, while partnering with engineering, security, and product teams to drive standardization, scalability, and security-first design.
Define and evolve the IAM & CIAM architecture, aligned to Zero Trust and enterprise security principles
Design scalable authentication and authorization models across internal platforms and customer-facing applications
Establish standards, patterns, and reference architectures for identity services across the organization
Drive platform selection, integration strategy, and roadmap for identity capabilities
Lead design and implementation of identity solutions using industry leading technologies like Microsoft Entra ID, Okta, Auth0, Ping or any other Identity Providers (IdPs)
Build and maintain:
Authentication flows (SSO, MFA, passwordless)
Authorization models (RBAC / ABAC)
Federation and identity brokering integrations
B2B and B2C flows
Ensure scalable handling of user identities, tokens, sessions, and lifecycle management
Design and implement customer-facing identity services, including:
Self-service registration and onboarding flows
Customer lifecycle management and identity governance
Secure access across multiple products and platforms
Enable consistent authentication and authorization across digital products
Drive improvements in user experience, security, and scalability for customer identity
Implement and enforce:
MFA, adaptive authentication, and conditional access policies
Identity governance, audit logging, and access reviews
Align identity systems with regulatory and compliance requirements (e.g., GDPR, data protection)
Partner with engineering teams to integrate identity services into applications
Enable adoption through SDKs, APIs, documentation, and patterns
Act as an internal consultant and SME for identity across product and platform teams
Experience with public cloud ecosystems like Microsoft Azure (Preferred), GCP and AWS.
Any exposure to Kubernetes and related technologies is an advantage
Ensure identity platforms are:
Highly available, scalable, and secure
Monitored and observable
Integrated into CI/CD and DevSecOps practices
Support continuous improvement of identity operations and automation
Bachelor's degree in computer science, engineering, or related field.
Minimum 8–12 years of overall experience in software engineering, security, or identity domains
Minimum 5+ years of hands‑on experience in IAM and/or CIAM implementations across enterprise or customer‑facing environments
Proven experience designing and delivering identity solutions at scale (multi-application, multi-tenant, or high-volume user environments)
Demonstrated experience working across both authentication (AuthN) and authorization (AuthZ) capabilities
Hands‑on experience with, Microsoft external Entra ID (Azure AD, B2C), Okta or equivalent identity platforms
Deep understanding of:
OAuth 2.0, OpenID Connect (OIDC), SAML
Protocol-level JWT/OIDC (hands‑on Entra ID (workforce)
Identity federation and token-based authentication
Zero Trust security principles
Access governance and compliance frameworks
Experience designing RBAC / ABAC authorization models
Experience with externalized/fine-grained authorization (policy-as-code) using engines such as OPA, Cedar, or XACML, including PDP/PEP architecture, policy testing, and fail-closed design.
Experience with cloud platforms (Azure preferred; AWS or GCP acceptable)
Ability to operate at both architectural and hands‑on engineering level
Excellent communication skills and the ability to influence across teams.
Strong understanding of Agile delivery frameworks.
Exposure to privacy, consent management, and customer data protection
Evolving identity systems to support AI-enabled platforms and services
Experience mentoring engineers or leading small identity teams
Understanding of customer identity UX patterns (frictionless login, conversion optimization, accessibility)
Experience designing or contributing to enterprise-scale CIAM platforms serving multiple products, business units, or regions
Experience enabling identity for AI, platform, or API ecosystems
Exposure to AI-driven security or identity use cases
Experience leveraging automation for:
Identity lifecycle operations
Policy enforcement and remediation
Experience with IAC tools like Terraform, Bicep & CI/CD pipelines (ADO, GitHub Actions)
DevSecOps practices and secure pipeline integration
Certifications like CISSP, Azure Solutions Architect Expert, or any vendor-specific certifications
We value diversity and are an equal opportunity employer. All qualified applicants will be considered for employment without regards to race, color, age, gender, sexual orientation, gender identity and expression, ethnicity or national origin, disability, pregnancy, religion, covered veteran status, protected genetic information, or any other characteristic protected by law.