At a Glance
- Tasks: Engineer and maintain IAM tools, focusing on automation and AI-driven optimisation.
- Company: Join Universal Music Group, the world's leading music company with a vibrant culture.
- Benefits: Enjoy competitive salary, diverse work environment, and opportunities for career growth.
- Other info: Inclusive workplace committed to diversity and supporting neurodiverse talents.
- Why this job: Be part of a passionate team shaping the future of music technology.
- Qualifications: 5+ years in IAM engineering with strong technical skills and automation experience.
The predicted salary is between 60000 - 80000 £ per year.
Music is Universal. It’s the passionate and dedicated team at Universal Music who help make us the world’s leading music company. From A&R to finance, legal to digital, sales to marketing, Universal Music is the place to grow and develop your career within a truly commercial and innovative business that leads in everything it does. Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of gender, race, disability, sexual orientation, religion, belief, age, marital status, background, pregnancy, or caring responsibilities. We also recognise the importance of diversity of thought within our teams and are fully committed to embracing the talents of people with autism, dyslexia, ADHD, and other forms of neurocognitive variation. We will always seek to make appropriate adjustments to recruitment, workplaces, and work processes to be fully inclusive to people with different needs and working styles. If you need us to make any reasonable adjustments for you from application onwards, including alternatives to the online form or to disclose a neurocognitive condition, please email UniversalMusicCareers@umusic.com.
Job Summary: We are UMG, the Universal Music Group. We are the world’s leading music company. In everything we do, we are committed to artistry, innovation and entrepreneurship. We own and operate a broad array of businesses engaged in recorded music, music publishing, merchandising, and audiovisual content in more than 60 countries. We identify and develop recording artists and songwriters, and we produce, distribute and promote the most critically acclaimed and commercially successful music to delight and entertain fans around the world. We are currently seeking an IAM Engineer to join our global Tech Security team. The ideal candidate will have hands‑on experience across the entire Identity & Access Management (IAM) stack, with a strong focus on engineering, automation, and AI‑driven optimization of identity services. This includes delivering and maintaining enterprise‑grade solutions across Privileged Access Management (PAM), Identity Governance and Administration (IGA), Public Key Infrastructure (PKI), Directory Services, Federation, and more. This role requires a combination of strong technical skills, an automation‑first mindset, and the ability to work effectively with business stakeholders, infrastructure partners, and application teams.
Job Functions:
- Engineer, deploy, and maintain IAM tools across the enterprise including CyberArk, Ping DaVinci, Microsoft EntraID (formerly Azure AD), HashiCorp Vault, Digicert, and Saviynt.
- Lead and support the implementation and enhancement of IAM services including: SSO/Federation (SAML, OIDC, WS‑Fed) – MFA/Passwordless – Privileged Access Management (PAM) – Identity Governance (IGA) – PKI and certificate lifecycle automation – Directory services (AD, EntraID).
- Build automation scripts and integrations for IAM workflows using tools such as PowerShell, Python, or Terraform.
- Design and implement access controls and policies that align with security and compliance standards (SOX, GDPR, etc.).
- Evaluate and deploy AI‑powered tools and methodologies to improve identity lifecycle efficiency, risk detection, and operational decision‑making.
- Participate in lifecycle management processes for accounts, credentials, roles, and policies across systems and applications.
- Collaborate with InfoSec, Infrastructure, and App teams to ensure secure identity architecture for on‑prem and cloud environments.
- Maintain high‑quality documentation and architectural diagrams.
- Monitor and report metrics on IAM system performance, adoption, and audit readiness.
Job Requirements:
Essential Qualifications:- 5+ years of hands‑on experience in IAM engineering roles.
- Deep technical expertise in one or more of the following: CyberArk, Ping Identity, Microsoft EntraID, Saviynt, HashiCorp Vault, Digicert, Onfido.
- Solid understanding of IAM protocols and standards: SAML, OIDC, OAuth2, LDAP, Kerberos, SCIM, JIT.
- Experience with automation tools and scripting (e.g., PowerShell, Python, Terraform).
- Familiarity with cloud platforms (Azure, AWS, GCP) and IAM integrations.
- Strong understanding of IAM‑related compliance frameworks and controls (e.g., SOX, ISO 27001, NIST).
- Proven ability to work independently and cross‑functionally in a global team.
- Strong troubleshooting, documentation, and communication skills.
- Bachelor’s Degree in Computer Science, Engineering, or a related technical field.
- Professional certifications such as: CISSP, Security+, Microsoft Certified: Identity and Access Administrator, CyberArk Defender, Ping Identity Certified Professional.
- Experience with AI/ML integration into IAM workflows or security analytics.
- Experience supporting IAM functions in media or entertainment industry environments.
- Experience working on a global team covering multiple timezones.
Just So You Know… The company presents this job description as a guide to the major areas and duties for which the jobholder is accountable. However, the business operates in an environment that demands change and the jobholder’s specific responsibilities and activities will vary and develop. Therefore, the job description should be seen as indicative and not as a permanent, definitive, and exhaustive statement.
IAM Engineer employer: Dormont Manufacturing Co
At Universal Music, we pride ourselves on being an inclusive and innovative employer, offering IAM Engineers the opportunity to thrive in a dynamic environment that champions creativity and diversity. Our commitment to employee growth is reflected in our supportive work culture, where collaboration and continuous learning are encouraged, alongside competitive benefits tailored to enhance your career in the vibrant music industry. Join us in a location that not only celebrates music but also fosters a sense of belonging and purpose for all team members.
StudySmarter Expert Advice🤫
We think this is how you could land IAM Engineer
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, especially those already at Universal Music. A friendly chat can open doors and give you insider info on what they're really looking for.
✨Tip Number 2
Show off your skills! If you’ve got a portfolio or projects that highlight your IAM expertise, don’t be shy. Bring them up during interviews to demonstrate your hands-on experience and problem-solving abilities.
✨Tip Number 3
Prepare for the tech talk! Brush up on IAM protocols and tools mentioned in the job description. Being able to discuss CyberArk, Microsoft EntraID, and automation scripts confidently will set you apart from the crowd.
✨Tip Number 4
Apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you’re genuinely interested in being part of the Universal Music family.
We think you need these skills to ace IAM Engineer
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the IAM Engineer role. Highlight your hands-on experience with IAM tools and any relevant projects you've worked on. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about IAM and how you can contribute to our Tech Security team. Be genuine and let your personality come through.
Showcase Your Technical Skills:Don’t hold back on showcasing your technical expertise! Mention specific tools like CyberArk, Microsoft EntraID, or any automation scripts you've built. We love seeing candidates who are hands-on and ready to dive into the tech.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets to us without any hiccups. Plus, it shows you're keen on joining the Universal Music family!
How to prepare for a job interview at Dormont Manufacturing Co
✨Know Your IAM Stuff
Make sure you brush up on your knowledge of IAM protocols and tools like CyberArk, Ping Identity, and Microsoft EntraID. Be ready to discuss your hands-on experience and how you've used these technologies in real-world scenarios.
✨Show Off Your Automation Skills
Since this role focuses on automation, prepare to talk about your experience with scripting languages like PowerShell or Python. Bring examples of how you've built automation scripts or integrated IAM workflows to improve efficiency.
✨Understand the Business Side
It's not just about tech! Be prepared to discuss how IAM impacts business operations and compliance. Familiarise yourself with frameworks like SOX and GDPR, and think about how you've aligned IAM practices with business needs in the past.
✨Be Ready for Collaboration Questions
This role requires working with various teams, so expect questions about your collaboration skills. Think of examples where you've successfully worked cross-functionally, especially in a global team setting, and be ready to share those stories.