Staff Information Security Engineer

Cybersecurity Jobs

Florida

Hybrid

USD 115,000 - 165,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

UKG is seeking a Staff Information Security Engineer to support IAM across enterprise and cloud environments, focusing on machine identities, certificates, and secrets. This hybrid role emphasizes designing, developing, and supporting secure solutions for identity and access management.

You will implement certificate lifecycle management for PKI, automate IAM workflows, and build scalable, observable platforms using Vault, Consul, Terraform, and cloud-native tools across AWS and GCP.

Qualifications

  • 8+ years of information security engineering, platform engineering, cloud engineering, systems engineering, identity and access management, or a related field.
  • Experience administering and supporting HashiCorp Vault in enterprise environments, including high availability and disaster recovery configurations.
  • Experience working with HashiCorp Consul and service discovery technologies.
  • Experience designing, implementing, or supporting certificate lifecycle management and PKI solutions.
  • Experience working with AWS IAM and/or GCP IAM.
  • Experience developing Infrastructure-as-Code solutions using Terraform.

Responsibilities

  • Design, develop, and maintain enterprise certificate lifecycle management solutions for internal and external PKI environments.
  • Build and enhance secrets management capabilities using HashiCorp Vault, Consul, and cloud-native security services.
  • Design, implement, and support highly available HashiCorp Vault environments, including disaster recovery, resiliency, performance optimization, and scalability.
  • Design and implement secure authentication and authorization patterns for applications, platforms, infrastructure, and machine identities.
  • Develop scalable solutions to automate certificate issuance, renewal, rotation, revocation, and inventory management.
  • Build automation and tooling using PowerShell, Python, Terraform, GitHub Actions, REST APIs, and cloud-native technologies.
  • Design and implement secure secrets management workflows for credentials, API keys, tokens, certificates, and service accounts.
  • Develop and maintain Infrastructure-as-Code (IaC) solutions supporting IAM, secrets management, and certificate management services.
  • Design and implement IAM solutions across AWS and GCP.

Skills

HashiCorp Vault
HashiCorp Consul
PowerShell
Python
Terraform
GitHub Actions
Grafana
Prometheus
PagerDuty
AWS IAM
GCP IAM
REST APIs
Kubernetes
CI/CD
IaC

Tools

Terraform
GitHub Actions
Grafana
Prometheus
PagerDuty
AWS IAM
GCP IAM
Kubernetes

Job description

UKG is hiring a Staff Information Security Engineer to support the Enterprise Identity and Access Management (IAM) team within Global Security. This hybrid role is focused on designing, developing, and supporting solutions for machine identities, certificates, secrets, and access management across UKG’s enterprise and cloud environments.

Key Responsibilities
  • Design, develop, and maintain enterprise certificate lifecycle management solutions for internal and external PKI environments
  • Build and enhance secrets management capabilities using HashiCorp Vault, Consul, and cloud-native security services
  • Design, implement, and support highly available HashiCorp Vault environments, including disaster recovery, resiliency, performance optimization, and scalability
  • Design and implement secure authentication and authorization patterns for applications, platforms, infrastructure, and machine identities
  • Develop scalable solutions to automate certificate issuance, renewal, rotation, revocation, and inventory management
  • Build automation and tooling using PowerShell, Python, Terraform, GitHub Actions, REST APIs, and cloud-native technologies
  • Design and implement secure secrets management workflows for credentials, API keys, tokens, certificates, and service accounts
  • Develop and maintain Infrastructure-as-Code (IaC) solutions supporting IAM, secrets management, and certificate management services
  • Design and implement IAM solutions across AWS and GCP
  • Develop automation for identity lifecycle management, access provisioning, privileged access workflows, and machine identity governance
  • Collaborate with application, infrastructure, and platform teams to integrate enterprise services with certificate management, IAM, and secrets management platforms
  • Create reusable Terraform modules, automation frameworks, and deployment patterns to improve consistency, scalability, and operational efficiency
  • Implement monitoring, observability, and operational dashboards using Grafana, Prometheus, PagerDuty, and related tooling
  • Maintain operational metrics, dashboards, alerts, and automated response workflows for IAM, secrets management, certificate management, and cloud security services
  • Participate in architecture reviews and provide guidance on certificate management, machine identity security, secrets management, cloud IAM, and access management best practices
  • Troubleshoot and resolve complex issues involving certificates, IAM, authentication, authorization, secrets management, and cloud security services
  • Partner with Security Engineering teams to implement and improve security controls, monitoring, automation, and governance capabilities
  • Contribute to engineering standards, technical documentation, automation frameworks, platform reliability initiatives, and operational maturity improvements
  • Identify opportunities to reduce operational risk and manual effort through automation and process improvements
  • Mentor engineers and share technical knowledge within the team
Required Qualifications
  • 8+ years of experience in information security engineering, platform engineering, cloud engineering, systems engineering, identity and access management, or a related technical field
  • Experience administering and supporting HashiCorp Vault in enterprise environments, including high availability and disaster recovery configurations
  • Experience working with HashiCorp Consul and service discovery technologies
  • Experience designing, implementing, or supporting certificate lifecycle management and PKI solutions
  • Experience working with AWS IAM and/or GCP IAM
  • Experience developing Infrastructure-as-Code solutions using Terraform
  • Experience developing automation using PowerShell, Python, and scripting frameworks
  • Experience building CI/CD automation using GitHub Actions or similar platforms
  • Experience implementing observability, monitoring, and alerting using Grafana, Prometheus, PagerDuty, or similar platforms
  • Experience designing and supporting highly available, secure enterprise platforms
  • Experience troubleshooting authentication, authorization, certificate, secrets management, and access-related issues
  • Experience working with REST APIs, system integrations, and automation frameworks
  • Strong analytical, problem-solving, and debugging skills
  • Ability to collaborate effectively across engineering, infrastructure, security, and platform teams
Technologies

HashiCorp Vault, HashiCorp Consul, PowerShell, Python, Terraform, GitHub Actions, Grafana, Prometheus, PagerDuty, Amazon Web Services (AWS) IAM, Google Cloud Platform (GCP) IAM, ACME, Workload Identity Federation (WIF), REST APIs, Infrastructure-as-Code (IaC), CI/CD, Kubernetes

About the Team

UKG’s Enterprise Identity and Access Management (IAM) team within Global Security builds and operates solutions that secure machine identities, certificates, secrets, and access management across UKG’s enterprise and cloud environments.

Preferred Qualifications
  • Experience designing and operating highly available HashiCorp Vault deployments at enterprise scale
  • Experience implementing enterprise certificate lifecycle management platforms and automation frameworks
  • Experience managing public and private PKI environments
  • Experience implementing automated certificate issuance and renewal using ACME or similar protocols
  • Experience designing and implementing machine identity management solutions
  • Experience implementing Workload Identity Federation (WIF) or other keyless authentication solutions
  • Experience securing and managing non-human identities, service accounts, and workload identities
  • Experience working with Kubernetes, containerized workloads, and cloud-native platforms
  • Experience developing reusable automation frameworks utilizing Terraform, PowerShell, Python, and GitHub Actions
  • Experience implementing security controls and governance capabilities within AWS and GCP environments
  • Familiarity with observability strategies for security and infrastructure platforms using Grafana, Prometheus, PagerDuty, and related monitoring technologies
  • Familiarity with Identity Governance and Administration (IGA) and Privileged Access Management (PAM) platforms
  • Experience supporting compliance and audit requirements related to identity, access management, certificates, and secrets management
  • Experience improving operational maturity, platform observability, reliability, and automation at enterprise scale
  • Experience working in Agile engineering environments
Role Details
  • Location: Sunrise, FL, United States (hybrid)
  • Salary Range: USD 115,100 - 165,450 per year
  • Employment Type: Regular
  • Work Style: hybrid
  • Job ID: STAFF020425
Company and Benefits

UKG emphasizes continuous learning and improvement, with flexibility that supports real work-life balance, benefits you can count on, and a team culture focused on shared success.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Information Security Engineer
Staff Information Security Engineer

Ukg-6 • Florida

Hybrid
USD 115,000 - 165,000
Sr. Staff IAM Architect
Sr. Staff IAM Architect

UKG • Town of Florida (NY)

On-site
USD 146,000 - 209,000
Sr. Staff IAM Architect
Sr. Staff IAM Architect

UKG • Lowell (MA)

On-site
USD 146,000 - 209,000
Sr. Staff IAM Architect
Sr. Staff IAM Architect

UKG • Atlanta (GA)

On-site
USD 146,000 - 209,000
Staff InfoSec Engineer: IAM, PKI & Vault Automation
Staff InfoSec Engineer: IAM, PKI & Vault Automation

Ukg-6 • Florida

Hybrid
USD 115,000 - 165,000
Staff IAM & Secrets Security Engineer
Staff IAM & Secrets Security Engineer

Cybersecurity Jobs • Florida

Hybrid
USD 115,000 - 165,000
Software Engineer III - Cloud Platform
Software Engineer III - Cloud Platform

UKG • Alpharetta (GA)

On-site
USD 102,000 - 147,000
Software Engineer III - Cloud Platform
Software Engineer III - Cloud Platform

UKG • Atlanta (GA)

On-site
USD 102,300 - 147,050
Staff Information Security Engineer
Staff Information Security Engineer

UKG • Town of Florida (NY)

On-site
USD 140,000 - 180,000
Sr. Staff Cloud Resilience Engineer - Security
Sr. Staff Cloud Resilience Engineer - Security

UKG • Lowell (MA)

On-site
USD 129,500 - 186,100