Innovate in Charlotte
Thank you for dedicating your time and talent to Lowe’s. We want to give you more opportunities to learn and grow, so if you find a position you’re interested in below, we encourage you to apply!
The primary purpose of this role is to design, engineer, implement, enhance, and support Lowe's Vendor Identity & Access Management (IAM) platform, providing secure identity lifecycle management, authentication, authorization, federation, and Single Sign-On capabilities for Lowe's vendors, suppliers, partners, and other external business users.
The Senior Engineer serves as a hands-on senior technical contributor responsible for engineering and supporting the Vendor IAM platform, including ForgeRock Access Management (AM), Identity Management (IDM), Directory Services (DS), and Identity Gateway (IG).
Your Impact
This role requires technical depth across identity platforms, authentication protocols, Linux infrastructure, directory services, networking, automation, observability, and production troubleshooting. The engineer will independently drive complex technical assignments and investigations while collaborating with application owners, infrastructure, network, security, and other engineering teams.
A major focus of this role is improving the stability, resiliency, performance, observability, and operational maturity of the Vendor IAM platform while contributing to its continued modernization.
What You Will Do
Vendor IAM Platform Engineering
- Design, engineer, implement, enhance, and support Lowe's Vendor IAM platform across ForgeRock AM, IDM, DS, and IG.
- Configure, maintain, optimize, and troubleshoot authentication journeys/trees, realms, applications, agents, identity stores, authentication policies, scripts, and platform integrations.
- Develop and support IDM managed objects, connectors, provisioning, synchronization, reconciliation, REST APIs, and vendor identity lifecycle workflows.
- Engineer and troubleshoot ForgeRock DS capabilities including LDAP operations, replication, indexing, schema, performance, capacity, availability, backup/recovery, and data integrity.
- Configure and troubleshoot ForgeRock IG routes, filters, authentication integrations, policies, and application access patterns.
- Independently implement complex identity platform configurations, scripts, integrations, and enhancements.
- Develop and document engineering standards, implementation procedures, troubleshooting guidance, and platform best practices.
Authentication, Authorization & Federation
- Design, implement, and troubleshoot authentication and authorization solutions using OAuth 2.0, OpenID Connect, SAML 2.0, LDAP, TLS/SSL, Single Sign-On, federation, MFA, token management, and session management.
- Support B2B and partner federation patterns involving vendors, suppliers, external organizations, and external Identity Providers.
- Troubleshoot protocol-level issues involving OAuth, OIDC, SAML, LDAP, certificates, claims, tokens, sessions, redirects, and authentication flows.
- Support modern authentication capabilities including step-up, passwordless, and risk-based authentication.
- Apply secure engineering practices to authentication, authorization, identity federation, session management, and application integrations.
Vendor Identity Lifecycle
- Engineer identity lifecycle capabilities supporting vendor, supplier, partner, and other external identities.
- Develop and troubleshoot identity creation, update, activation, deactivation, provisioning, reconciliation, and synchronization processes.
- Engineer integrations between ForgeRock IDM, DS, authoritative identity sources, applications, APIs, and downstream services.
- Troubleshoot identity data flows, synchronization failures, reconciliation issues, provisioning failures, and data inconsistencies.
- Develop REST APIs, scripts, and automated integrations supporting vendor identity services.
- Collaborate with application owners and business stakeholders to translate identity requirements into secure technical solutions.
Platform Stability & Production Engineering
- Drive platform stability through performance analysis, resiliency improvements, capacity planning, root-cause analysis, and continuous service optimization.
- Independently investigate complex issues spanning ForgeRock AM, IDM, DS, IG, applications, Linux, networks, load balancers, firewalls, directories, certificates, APIs, and external integrations.
- Diagnose authentication failures, latency, timeouts, performance degradation, token and session issues, synchronization failures, replication problems, certificate issues, and connectivity failures.
- Correlate logs, metrics, and events across multiple systems to identify failure patterns and determine root cause.
- Respond to escalated production issues and technically lead complex break/fix and recovery activities when required.
- Perform root-cause analysis and define corrective and preventive engineering actions following production incidents.
- Identify technical debt, capacity constraints, recurring failure patterns, reliability gaps, and opportunities for platform improvement.
- Drive technical issues through resolution by coordinating with application, network, infrastructure, security, directory, vendor, and support teams.
Observability & Monitoring
- Develop and improve telemetry, logging, monitoring, alerting, dashboards, and operational reporting for the Vendor IAM platform.
- Use telemetry proactively to identify performance, reliability, availability, and capacity concerns before they result in production incidents.
- Analyze and correlate application, identity, infrastructure, directory, and network telemetry.
- Identify gaps in monitoring and alerting and implement improvements that increase operational visibility.
- Establish meaningful health and performance metrics for critical identity services.
Development, Automation & CI/CD
- Develop, review, debug, and troubleshoot authentication scripts, identity lifecycle logic, policies, claims, and integration code.
- Develop automation using Shell scripting, JavaScript, Python, Java, or comparable technologies.
- Automate deployment, monitoring, validation, administration, and support activities.
- Develop reusable tooling that reduces manual operational work and improves platform reliability.
- Support CI/CD pipelines and automated deployment and configuration-promotion processes.
- Use Git-based source control, pull requests, peer review, and controlled configuration promotion across Development, Test, Stage, and Production.
- Apply configuration-as-code and Infrastructure-as-Code practices where appropriate.
Infrastructure Engineering
- Troubleshoot identity services running within Linux/Unix environments.
- Diagnose issues involving processes, services, CPU, memory, storage, file systems, permissions, certificates, and network connectivity.
- Troubleshoot across DNS, HTTP/HTTPS, TLS, load balancers, reverse proxies, firewalls, virtual IPs, and network routing.
- Understand high availability, clustering, failover, disaster recovery, and multi-data-center architectures.
- Diagnose problems that cross application, operating system, network, infrastructure, directory, and IAM platform boundaries.
Modernization & Emerging Identity Capabilities
- Contribute to modernization of the Vendor IAM platform from existing on-premises identity infrastructure toward modern cloud and SaaS-based identity capabilities.
- Evaluate new identity technologies and provide technical input into future-state architecture and migration decisions.
- Support modern OAuth/OIDC capabilities including Dynamic Client Registration, API authentication, machine-to-machine authentication, and API gateway integrations.
- Contribute to authentication and authorization patterns supporting APIs, machine identities, intelligent agents, and emerging identity use cases.
- Identify opportunities to simplify architecture, improve automation, remove bottlenecks, and increase platform security and reliability
Senior Engineer Expectations
- Serve as a senior hands-on technical contributor within the Vendor IAM engineering team.
- Independently drive complex assignments from analysis and design through implementation and production validation.
- Take ownership of assigned platform components, technical initiatives, and production issues through completion.
- Lead or significantly contribute to complex technical investigations, major incidents, root-cause analyses, and corrective actions.
- Review technical designs, configuration changes, scripts, integrations, and deployment plans.
- Provide mentoring and technical guidance to junior and mid-level engineers.
- Communicate complex technical issues clearly to technical and non-technical stakeholders.
- Demonstrate strong technical judgment and make sound engineering decisions with limited supervision.
- Act as a technical point of contact for the Vendor IAM platform when required.
- Be capable of stepping into a technical leadership role during projects, incidents, platform changes, or in the absence of the Lead Engineer.
- Work closely with the Lead Engineer and contribute to architecture decisions, technical roadmaps, modernization initiatives, and engineering priorities.
Minimum Qualifications
- Bachelor's degree in Computer Science, CIS, Engineering, Cybersecurity, or related field, or equivalent years of experience in lieu of education requirement, if applicable.
- 5 years of experience in technology system support, software development, platform engineering, infrastructure engineering, or a related field.
- 2 years of experience with information security applications and systems.
- Hands-on experience designing, engineering, implementing, or supporting enterprise Identity & Access Management platforms.
- Hands-on experience with ForgeRock Identity Platform technologies or comparable enterprise IAM platforms.
- Experience with enterprise authentication and authorization technologies including OAuth 2.0, OpenID Connect, SAML 2.0, LDAP, TLS/SSL, SSO, federation, tokens, and sessions.
- Experience troubleshooting complex production issues across application, IAM platform, Linux/Unix, network, directory, and integration layers.
- Experience developing or troubleshooting scripts, automation, APIs, or platform integrations.
- Experience supporting highly available, business-critical enterprise platforms.
- Experience working with logs, monitoring, telemetry, and production diagnostic tools.
Preferred Skills/Education
- Master's degree in Computer Science, CIS, Business Administration, or related field.
- 3 years of experience evaluating applications and their infrastructure, host platforms, integrations, and dependencies to identify security, reliability, or operational concerns.
- 1 year of DevOps experience.
- 3 years of experience developing or enhancing applications, platform components, automation, or integrations using secure coding practices.
- 5 years of IT experience developing and implementing business systems within an organization.
- 5 years of experience working with defect or incident tracking systems.
- 5 years of experience producing technical documentation in a software development or platform engineering environment.
- 3 years of experience working within an IT Infrastructure Library (ITIL) framework.
- 3 years of experience providing technical leadership or leading teams, with or without direct reports.
- 5 years of experience working with source-code control systems.
- Strong hands-on experience with ForgeRock Access Management, Identity Management, Directory Services, and Identity Gateway, preferably version 7.x or later.
- Experience developing ForgeRock IDM managed objects, connectors, provisioning, reconciliation, synchronization, REST APIs, and identity lifecycle integrations.
- Experience administering ForgeRock DS or comparable LDAP directory technologies, including replication, indexing, schema, performance, capacity, availability, and data integrity.
- Experience configuring and troubleshooting ForgeRock IG or comparable identity-aware gateway technologies.
- Experience supporting vendor-facing, B2B, partner, or external identity platforms.
- Experience supporting ForgeRock or comparable IAM platforms across multiple data centers.
- Experience with CI/CD pipelines and automated deployment processes.
- Experience with cloud technologies and familiarity with containerized identity deployments, Kubernetes, or Docker.
- Experience with performance testing, capacity planning, platform upgrades, patching, and vulnerability remediation.
- Experience diagnosing performance bottlenecks across IAM platforms, directories, applications, networks, and infrastructure.
- Experience with Dynamic Client Registration, API gateways such as Kong, REST APIs, and API security.
- Experience with certificate lifecycle management, encryption, key management, PKI, and secrets management.
- Experience with Infrastructure-as-Code or configuration-as-code practices.
- Experience with identity platform modernization or migration to cloud or SaaS-based identity services.
- ForgeRock or Ping Identity certification preferred but not required.
About Lowe’s
Lowe’s Companies, Inc. (NYSE: LOW) is a FORTUNE® 100 home improvement company with total fiscal year 2025 sales of more than $86 billion. Lowe’s employs approximately 300,000 associates and operates over 1,750 home improvement stores, 540 branches and 120 distribution centers. Lowe’s is a core value S&P 500 equity stock and a dividend aristocrat. Based in Mooresville, N.C., Lowe’s supports the communities it serves through programs focused on creating safe, affordable housing, improving community spaces, helping to develop the next generation of skilled trade experts and providing disaster relief to communities in need. For more information, visit Lowes.com.
Lowe’s is an equal opportunity employer and administers all personnel practices without regard to race, color, religious creed, sex, gender, age, ancestry, national origin, mental or physical disability or medical condition, sexual orientation, gender identity or expression, marital status, military or veteran status, genetic information, or any other category protected under federal, state, or local law.