Now hiring

Lead Engineer – Enterprise Workforce Access Management, Information Security @ Lowes

Lowe's Charlotte Technology Hub 3505OnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

Innovate in Charlotte

Thank you for dedicating your time and talent to Lowe’s. We want to give you more opportunities to learn and grow, so if you find a position you’re interested in below, we encourage you to apply!

Key Responsibilities Enterprise Platform Engineering

• Lead the engineering, lifecycle management, modernization, and operational excellence of Lowe's Enterprise Access Management platform supporting workforce authentication across hundreds of enterprise applications. • Design, implement, and optimize secure enterprise authentication and Single Sign-On solutions for workforce access. • Design authentication and authorization solutions using OAuth 2.0, OpenID Connect (OIDC), SAML 2.0, LDAP, TLS/SSL, Single Sign-On, federation, multi-factor authentication (MFA), passwordless authentication, adaptive authentication, token management, and session management. • Own platform architecture decisions with accountability for security, scalability, resilience, availability, recoverability, and performance. • Lead platform upgrades, feature adoption, engineering improvements, and modernization initiatives. Platform Stability & Operational Excellence

• Drive platform stability through proactive performance analysis, resiliency improvements, observability, capacity planning, root cause analysis, and continuous service optimization. • Lead troubleshooting, incident response, root cause analysis, and corrective actions for complex authentication, application, infrastructure, network, directory, certificate, token, session, and integration issues. • Respond to escalated production issues and provide technical leadership during major incidents involving enterprise authentication services. • Establish engineering standards for monitoring, alerting, logging, operational readiness, disaster recovery, and service reliability. • Continuously improve platform performance and operational maturity through automation and engineering best practices. Application Integration & Technical Leadership

• Serve as the technical advisor for application teams onboarding to the Enterprise Access Management platform. • Partner with application owners, infrastructure teams, cybersecurity, architects, and business stakeholders to design secure authentication solutions and integration patterns. • Engineer secure federation and trust relationships with enterprise applications using OAuth 2.0, OpenID Connect, SAML 2.0, LDAP, REST APIs, and modern identity standards. • Design and implement modern OAuth 2.0 capabilities including Dynamic Client Registration, machine-to-machine authentication, API gateway integrations, and secure application onboarding. • Design and troubleshoot integrations with enterprise identity providers, LDAP directories, and authentication services supporting workforce access management. Modernization & Innovation

• Lead technical initiatives supporting the modernization of enterprise authentication services, including migration from on-premises identity infrastructure toward cloud-native and SaaS-based identity platforms. • Evaluate emerging authentication technologies and identity trends to improve security, reliability, and user experience. • Evaluate and implement authentication patterns supporting emerging AI services, intelligent agents, APIs, and machine identities while maintaining enterprise security standards. • Make recommendations to Technology and Security leadership regarding future authentication architecture and platform strategy. Automation & Engineering Excellence

• Develop and maintain automation, scripts, integrations, Infrastructure-as-Code, and CI/CD pipelines to improve platform deployment, validation, monitoring, administration, and support. • Evaluate technical designs, configuration changes, scripts, integrations, deployment plans, and engineering standards to identify potential risks to security or platform stability. • Design secure deployment pipelines and engineering processes that improve operational efficiency while reducing risk. Leadership

• Mentor engineers and provide hands-on technical leadership across the Enterprise Access Management engineering team. • Lead architecture reviews and establish engineering standards, documentation, and implementation guidance. • Educate engineers and project teams on enterprise authentication architecture, engineering best practices, and modern identity technologies. • Solve complex cross-functional architecture, engineering, and operational challenges while driving continuous improvement across the platform. Required Qualifications

• Bachelor's degree in Computer Science, Information Systems, Engineering, Cybersecurity, or related field (or equivalent experience). • 7+ years of experience in software engineering, platform engineering, infrastructure engineering, or information security. • 5+ years designing, engineering, or supporting enterprise authentication, identity, or access management platforms. • 4+ years of hands-on experience implementing authentication and authorization solutions using OAuth 2.0, OpenID Connect, SAML 2.0, LDAP, TLS/SSL, federation, Single Sign-On, token management, session management, and multi-factor authentication. • 5+ years troubleshooting complex issues spanning applications, authentication platforms, operating systems, networking, directories, certificates, APIs, and integrations. • Experience engineering highly available, mission-critical authentication platforms supporting large enterprise environments. • Experience improving platform reliability, resiliency, operational maturity, and production stability. • Experience producing architecture documentation, engineering standards, operational procedures, implementation guides, and troubleshooting documentation. • Experience developing automation using JavaScript, Shell scripting, Python, or comparable scripting languages. • Experience administering and troubleshooting Linux or Unix operating systems. • Strong understanding of REST APIs, authentication flows, secure integration patterns, and modern identity protocols. Preferred Qualifications

• Master's degree in Computer Science, Information Systems, Business Administration, or related field. • 3+ years of experience implementing or engineering ForgeRock Access Management (version 7.x or later preferred). • Experience with enterprise authentication platforms such as ForgeRock Access Management, Okta Workforce Identity, Ping Identity, Microsoft Entra ID, or comparable enterprise access management platforms. • Experience integrating enterprise applications using OAuth 2.0, OpenID Connect, SAML 2.0, LDAP, REST APIs, and modern federation standards. • Experience supporting enterprise LDAP integrations and identity repositories. • Experience planning or executing authentication platform modernization initiatives, including migration from on-premises infrastructure to cloud-based or SaaS identity platforms. • Experience with Dynamic Client Registration, API gateway integrations (e.g., Kong), and machine-to-machine authentication. • Experience with CI/CD pipelines, Git-based source control, automated deployments, Infrastructure-as-Code, and configuration management. • Experience with certificate lifecycle management, encryption, PKI, secrets management, and secure key management. • Experience supporting containerized or cloud-native authentication platforms. • Experience with performance testing, capacity planning, platform upgrades, vulnerability remediation, and operational readiness. • Experience working within an ITIL-based operational environment. What You'll Work On

• Secure authentication for approximately 300,000 Lowe's associates. • Authentication services supporting hundreds of enterprise applications across stores, distribution centers, supply chain, and corporate systems. • A mission-critical ForgeRock Access Management platform that requires continuous engineering improvements in reliability, scalability, and operational excellence. • Enterprise modernization initiatives evaluating cloud-native and SaaS identity platforms. • Modern authentication capabilities including OAuth 2.0, OpenID Connect, Dynamic Client Registration, API integrations, and emerging AI identity use cases. • Cross-functional collaboration with application engineering teams across one of the world's largest retailers.

About Lowe’s Lowe’s Companies, Inc. (NYSE: LOW) is a FORTUNE® 100 home improvement company with total fiscal 2025 sales of more than $86 billion. Lowe’s employs approximately 300,000 associates and operates over 1,750 home improvement stores, 540 branches and 120 distribution centers. Based in Mooresville, N.C., Lowe’s supports the communities it serves through programs focused on creating safe, affordable housing, improving community spaces, helping to develop the next generation of skilled trade experts and providing disaster relief to communities in need. For more information, visit Lowes.com.

Lowe’s is an equal opportunity employer and administers all personnel practices without regard to race, color, religious creed, sex, gender, age, ancestry, national origin, mental or physical disability or medical condition, sexual orientation, gender identity or expression, marital status, military or veteran status, genetic information, or any other category protected under federal, state, or local law.

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores