Lowe's
Senior Engineer, Vendor Identity & Access Management
Lowe's Charlotte Technology Hub 3505
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.5M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Senior
- Country
- US
- Work mode
- On-site / unstated
- First seen by hirly
- 27 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Innovate in Charlotte
Thank you for dedicating your time and talent to Lowe’s. We want to give you more opportunities to learn and grow, so if you find a position you’re interested in below, we encourage you to apply!
The primary purpose of this role is to design, engineer, implement, enhance, and support Lowe's Vendor Identity & Access Management (IAM) platform, providing secure identity lifecycle management, authentication, authorization, federation, and Single Sign-On capabilities for Lowe's vendors, suppliers, partners, and other external business users.
The Senior Engineer serves as a hands-on senior technical contributor responsible for engineering and supporting the Vendor IAM platform, including ForgeRock Access Management (AM), Identity Management (IDM), Directory Services (DS), and Identity Gateway (IG).
Your Impact
This role requires technical depth across identity platforms, authentication protocols, Linux infrastructure, directory services, networking, automation, observability, and production troubleshooting. The engineer will independently drive complex technical assignments and investigations while collaborating with application owners, infrastructure, network, security, and other engineering teams.
A major focus of this role is improving the stability, resiliency, performance, observability, and operational maturity of the Vendor IAM platform while contributing to its continued modernization.
What You Will Do
Vendor IAM Platform Engineering
- Design, engineer, implement, enhance, and support Lowe's Vendor IAM platform across ForgeRock AM, IDM, DS, and IG.
- Configure, maintain, optimize, and troubleshoot authentication journeys/trees, realms, applications, agents, identity stores, authentication policies, scripts, and platform integrations.
- Develop and support IDM managed objects, connectors, provisioning, synchronization, reconciliation, REST APIs, and vendor identity lifecycle workflows.
- Engineer and troubleshoot ForgeRock DS capabilities including LDAP operations, replication, indexing, schema, performance, capacity, availability, backup/recovery, and data integrity.
- Configure and troubleshoot ForgeRock IG routes, filters, authentication integrations, policies, and application access patterns.
- Independently implement complex identity platform configurations, scripts, integrations, and enhancements.
- Develop and document engineering standards, implementation procedures, troubleshooting guidance, and platform best practices.
Authentication, Authorization & Federation
- Design, implement, and troubleshoot authentication and authorization solutions using OAuth 2.0, OpenID Connect, SAML 2.0, LDAP, TLS/SSL, Single Sign-On, federation, MFA, token management, and session management.
- Support B2B and partner federation patterns involving vendors, suppliers, external organizations, and external Identity Providers.
- Troubleshoot protocol-level issues involving OAuth, OIDC, SAML, LDAP, certificates, claims, tokens, sessions, redirects, and authentication flows.
- Support modern authentication capabilities including step-up, passwordless, and risk-based authentication.
- Apply secure engineering practices to authentication, authorization, identity federation, session management, and application integrations.
Vendor Identity Lifecycle
- Engineer identity lifecycle capabilities supporting vendor, supplier, partner, and other external identities.
- Develop and troubleshoot identity creation, update, activation, deactivation, provisioning, reconciliation, and synchronization processes.
- Engineer integrations between ForgeRock IDM, DS, authoritative identity sources, applications, APIs, and downstream services.
- Troubleshoot identity data flows, synchronization failures, reconciliation issues, provisioning failures, and data inconsistencies.
- Develop REST APIs, scripts, and automated integrations supporting vendor identity services.
- Collaborate with application owners and business stakeholders to translate identity requirements into secure technical solutions.
Platform Stability & Production Engineering
- Drive platform stability through performance analysis, resiliency improvements, capacity planning, root-cause analysis, and continuous service optimization.
- Independently investigate complex issues spanning ForgeRock AM, IDM, DS, IG, applications, Linux, networks, load balancers, firewalls, directories, certificates, APIs, and external integrations.
- Diagnose authentication failures, latency, timeouts, performance degradation, token and session issues, synchronization failures, replication problems, certificate issues, and connectivity failures.
- Correlate logs, metrics, and events across multiple systems to identify failure patterns and determine root cause.
- Respond to escalated production issues and technically lead complex break/fix and recovery activities when required.
- Perform root-cause analysis and define corrective and preventive engineering actions following production incidents.
- Identify technical debt, capacity constraints, recurring failure patterns, reliability gaps, and opportunities for platform improvement.
- Drive technical issues through resolution by coordinating with application, network, infrastructure, security, directory, vendor, and support teams.
Observability & Monitoring
- Develop and improve telemetry, logging, monitoring, alerting, dashboards, and operational reporting for the Vendor IAM platform.
- Use telemetry proactively to identify performance, reliability, availability, and capacity concerns before they result in production incidents.
- Analyze and correlate application, identity, infrastructure, directory, and network telemetry.
- Identify gaps in monitoring and alerting and implement improvements that increase operational visibility.
- Establish meaningful health and performance metrics for critical identity services.
Development, Automation & CI/CD
- Develop, review, debug, and troubleshoot authentication scripts, identity lifecycle logic, policies, claims, and integration code.
- Develop automation using Shell scripting, JavaScript, Python, Java, or comparable technologies.
- Automate deployment, monitoring, validation, administration, and support activities.
- Develop reusable tooling that reduces manual operational work and improves platform reliability.
- Support CI/CD pipelines and automated deployment and configuration-promotion processes.
- Use Git-based source control, pull requests, peer review, and controlled configuration promotion across Development, Test, Stage, and Production.
- Apply configuration-as-code and Infrastructure-as-Code practices where appropriate.
Infrastructure Engineering
- Troubleshoot identity services running within Linux/Unix environments.
- Diagnose issues involving processes, services, CPU, memory, storage, file systems, permissions, certificates, and network connectivity.
- Troubleshoot across DNS, HTTP/HTTPS, TLS, load balancers, reverse proxies, firewalls, virtual IPs, and network routing.
- Understand high availability, clustering, failover, disaster recovery, and multi-data-center architectures.
- Diagnose problems that cross application, operating system, network, infrastructure, directory, and IAM platform boundaries.
Modernization & Emerging Identity Capabilities
- Contribute to modernization of the Vendor IAM platform from existing on-premises identity infrastructure toward modern cloud and SaaS-based identity capabilities.
- Evaluate new identity technologies and provide technical input into future-state architecture and migration decisions.
- Support modern OAuth/OIDC capabilities including Dynamic Client Registration, API authentication, machine-to-machine authentication, and API gateway integrations.
- Contribute to authentication and authorization patterns supporting APIs, machine identities, intelligent agents, and emerging identity use cases.
- Identify opportunities to simplify architecture, improve automati
Listed on hirly, a job board. hirly is not the employer: Lowe's is hiring for this role.
Similar jobs
- Senior Data Engineer, Pricing and CompsClera · San FranciscoFirst seen today
- Senior R&D Engineer, Space PV Product Design & PrototypingTandempv · FremontFirst seen today
- Senior AI Training Infrastructure EngineerDesignworkstalent · BellevueFirst seen today
- Enterprise Logging Solution (ELS) Engineer - Junior, Mid-Level & Senior [U.S. Citizenship & CBP BI – High Trust Required]Vialogic · Ashburn, VAFirst seen today
- Senior DevOps EngineerRedwoodmaterials · McCarran, NVFirst seen today
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job