Apply now »

Platform & Identity Architect

Req ID:  16577
Work Flexibility:  Onsite

Acuity Inc. (NYSE: AYI) is a market-leading industrial technology company. We use technology to solve problems in spaces, light and more things to come. Through our two business segments, Acuity Brands Lighting (ABL) and Acuity Intelligent Spaces (AIS), we design, manufacture, and bring to market products and services that make a valuable difference in people’s lives. 

We achieve growth through the development of innovative new products and services, including lighting, lighting controls, building management solutions, and an audio, video and control platform. We focus on customer outcomes and drive growth and productivity to increase market share and deliver superior returns. We look to aggressively deploy capital to grow the business and to enter attractive new verticals. 

Acuity Inc. is based in Atlanta, Georgia, with operations across North America, Europe and Asia. The Company is powered by approximately 13,000 dedicated and talented associates. Visit us at www.acuityinc.com. 

The Opportunity

At Acuity, we are building a modern, scalable Identity and Access Management (IAM) and Customer Identity and Access Management (CIAM) platform to support our growing portfolio of digital products and services.

This role will play a critical part in shaping and delivering our unified identity strategy, enabling secure, seamless authentication and authorization experiences for employees, customers, and partners.

You will work across both enterprise IAM and CIAM domains, leveraging industry leading platforms such as Microsoft Entra ID, Okta etc. and modern identity standards, while partnering with engineering, security, and product teams to drive standardization, scalability, and security-first design.

Key Tasks & Responsibilities (Essential Functions)

Architecture & Strategy

  • Define and evolve the IAM & CIAM architecture, aligned to Zero Trust and enterprise security principles
  • Design scalable authentication and authorization models across internal platforms and customer-facing applications
  • Establish standards, patterns, and reference architectures for identity services across the organization
  • Drive platform selection, integration strategy, and roadmap for identity capabilities

Identity Platform Engineering

    • Lead design and implementation of identity solutions using industry leading technologies like Microsoft Entra ID, Okta, Auth0, Ping or any other Identity Providers (IdPs)
  • Build and maintain:
    • Authentication flows (SSO, MFA, passwordless)
    • Authorization models (RBAC / ABAC)
    • Federation and identity brokering integrations
    • B2B and B2C flows
  • Ensure scalable handling of user identities, tokens, sessions, and lifecycle management

CIAM (Customer Identity & Access)

  • Design and implement customer-facing identity services, including:
    • Self-service registration and onboarding flows
    • Customer lifecycle management and identity governance
    • Secure access across multiple products and platforms
  • Enable consistent authentication and authorization across digital products
  • Drive improvements in user experience, security, and scalability for customer identity

Security & Compliance

  • Implement and enforce:
    • MFA, adaptive authentication, and conditional access policies
    • Identity governance, audit logging, and access reviews
  • Align identity systems with regulatory and compliance requirements (e.g., GDPR, data protection)

Integration & Enablement

  • Partner with engineering teams to integrate identity services into applications
  • Enable adoption through SDKs, APIs, documentation, and patterns
  • Act as an internal consultant and SME for identity across product and platform teams
  • Experience with public cloud ecosystems like Microsoft Azure (Preferred), GCP and AWS.
  • Any exposure to Kubernetes and related technologies is an advantage

Operational Excellence

  • Ensure identity platforms are:
    • Highly available, scalable, and secure
    • Monitored and observable
    • Integrated into CI/CD and DevSecOps practices
  • Support continuous improvement of identity operations and automation

Skills and Minimum Experience Required

  • Bachelor's degree in computer science, engineering, or related field.
  • Minimum 8–12 years of overall experience in software engineering, security, or identity domains
  • Minimum 5+ years of hands-on experience in IAM and/or CIAM implementations across enterprise or customer-facing environments
  • Proven experience designing and delivering identity solutions at scale (multi-application, multi-tenant, or high-volume user environments)
  • Demonstrated experience working across both authentication (AuthN) and authorization (AuthZ) capabilities
  • Hands-on experience with, Microsoft external Entra ID (Azure AD, B2C), Okta or equivalent identity platforms
  • Deep understanding of:
    • OAuth 2.0, OpenID Connect (OIDC), SAML
    • Protocol-level JWT/OIDC (hands-on Entra ID (workforce)
    • Identity federation and token-based authentication
    • Zero Trust security principles
    • Access governance and compliance frameworks
  • Experience designing RBAC / ABAC authorization models
  • Experience with externalized/fine-grained authorization (policy-as-code) using engines such as OPA, Cedar, or XACML, including PDP/PEP architecture, policy testing, and fail-closed design.
  • Experience with cloud platforms (Azure preferred; AWS or GCP acceptable)
  • Ability to operate at both architectural and hands-on engineering level
  • Excellent communication skills and the ability to influence across teams.
  • Strong understanding of Agile delivery frameworks.

Preferred Skills and Experience (Nice to Have)

  • Exposure to privacy, consent management, and customer data protection
  • Evolving identity systems to support AI-enabled platforms and services
  • Experience mentoring engineers or leading small identity teams
  • Understanding of customer identity UX patterns (frictionless login, conversion optimization, accessibility)
  • Experience designing or contributing to enterprise-scale CIAM platforms serving multiple products, business units, or regions
  • Experience enabling identity for AI, platform, or API ecosystems
  • Exposure to AI-driven security or identity use cases
  • Experience leveraging automation for:
    • Identity lifecycle operations
    • Policy enforcement and remediation
  • Experience with IAC tools like Terraform, Bicep & CI/CD pipelines (ADO, GitHub Actions)
  • DevSecOps practices and secure pipeline integration
  • Certifications like CISSP, Azure Solutions Architect Expert, or any vendor-specific certifications

 

We value diversity and are an equal opportunity employer.  All qualified applicants will be considered for employment without regards to race, color, age, gender, sexual orientation, gender identity and expression, ethnicity or national origin, disability, pregnancy, religion, covered veteran status, protected genetic information, or any other characteristic protected by law.  

Please click here and here for more information. 

 

Accommodation in the Application Process: Acuity Inc. is an equal opportunity employer.  It complies with the Americans with Disabilities Act (ADA) and other applicable laws requiring reasonable accommodation of persons with disabilities in employment.  This includes the provision of reasonable accommodation in the application process.  If you believe you need reasonable accommodation to assist with our online application system or any aspect of the application process, please contact Human Resources at (770) 922-9000, and select option 4.  Please be prepared to identify the requisition / position applied for and the aspect of the application process for which you believe accommodation is needed.  The company will engage in an interactive process with you to better understand the request and to determine whether reasonable accommodation is needed and available. 

 

Any unsolicited resumes sent to Acuity Inc. from a third party, such as an Agency recruiter, including unsolicited resumes sent to an Acuity Inc. mailing address, fax machine or email address, directly to Acuity Inc. employees, or to Acuity Inc. resume database will be considered Acuity Inc. property. Acuity Inc. will NOT pay a fee for any placement resulting from the receipt of an unsolicited resume. 

 

Acuity Inc. will consider any candidate for whom an Agency has submitted an unsolicited resume to have been referred by the Agency free of any charges or fees. This includes any Agency that is an approved/engaged vendor, but does not have the appropriate approvals to be engaged on a search. 

 

E-Verify Participation Poster

e-verify.gov

eeoc.gov

 

Protecting Yourself from Recruitment Scams:  Acuity is committed to maintaining the integrity of our Talent Acquisition process and the security of our candidates. We are aware of phishing and fraudulent schemes in which individuals impersonate Acuity representatives or recruiting partners to solicit payments or sensitive personal information.

As you navigate your job search, please keep the following in mind:

  • No Financial Requests: Acuity will never ask candidates for payment, credit card information, banking details or other financial information during the interview process.
  • Verify Recruiter Communications: Legitimate communications from Acuity recruiters will come from an “@acuityinc.com” email address. If you are contacted by a recruiting agency regarding a role with Acuity, the agency should clearly identify itself and its relationship to Acuity. If you suspect any suspicious activity, verify the agency legitimacy by contacting +1 877-584-1411, option# 0.
  • Be Alert for Suspicious Activity: Exercise caution if you receive unsolicited outreach with unusual requests, grammatical errors, requests for personal or financial information, or pressure to act quickly. Always verify the sender before sharing information or clicking links.
  • Report Suspected Fraud: If you receive a suspicious message or believe someone is impersonating Acuity or one of our recruiting partners, please contact +1 877-584-141, option# 0, report the incident to the FTC at ReportFraud.ftc.gov,  or to your state attorney general.


Job Segment: Compliance, Developer, User Experience, Machinist, Test Engineer, Legal, Technology, Manufacturing, Engineering

Apply now »