IAM Engineer - PAM & PKI in London

IAM Engineer - PAM & PKI in London

London Full-Time 60000 - 80000 £ / year (est.) No working from home possible
Universal Music Group UK

At a Glance

  • Tasks: Design and implement security solutions to protect privileged access and manage certificates.
  • Company: Join Universal Music Group, the leading music entertainment company shaping culture.
  • Benefits: Enjoy competitive salary, private medical insurance, and generous annual leave.
  • Other info: Diverse and inclusive workplace committed to supporting all talents.
  • Why this job: Be part of a passionate team making a real impact in the music industry.
  • Qualifications: 5+ years in Identity & Access Management with strong CyberArk and PKI experience.

The predicted salary is between 60000 - 80000 £ per year.

Music is Universal. It’s the passionate and dedicated team at Universal Music who help make us the world’s leading music company. From A&R to finance, legal to digital, sales to marketing, Universal Music is the place to grow and develop your career within a truly commercial and innovative business that leads in everything it does. Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of gender, race, disability, sexual orientation, religion, belief, age, marital status, background, pregnancy, or caring responsibilities. We also recognise the importance of diversity of thought within our teams and are fully committed to embracing the talents of people with autism, dyslexia, ADHD, and other forms of neurocognitive variation. We will always seek to make appropriate adjustments to recruitment, workplaces, and work processes to be fully inclusive to people with different needs and working styles.

Job Summary: We are currently seeking an Identity & Access Management Engineer with specialization in CyberArk and Public Key Infrastructure (PKI) to join UMG’s global Tech Security & Identity organization. Reporting to the Manager, PAM & PKI this is a hands‑on engineering role responsible for designing, implementing, and operating enterprise‑grade privileged access and certificate‑based security capabilities across a global, hybrid environment. This engineer will play a critical role in securing privileged user access, service accounts, application credentials, and machine identities through CyberArk, while also engineering and operating global PKI services that secure and establish trust across infrastructure, applications, automated workloads, and all of UMG’s public facing websites. The role emphasizes deep technical execution, automation, and operational excellence, partnering closely with infrastructure, security, and application teams to reduce risk and strengthen identity security at scale.

Job Functions:

  • Design, engineer, deploy, and operate Privileged Access Management solutions using CyberArk, 1Password, Hashicorp Vault, and other privileged tooling across the enterprise.
  • Administer and enhance CyberArk components including Vault, CPM, PVWA, PSM, and related integrations.
  • Implement and manage privileged access controls for users, service accounts, application credentials, and non-human identities.
  • Engineer and operate enterprise PKI services, including certificate issuance, renewal, revocation, and lifecycle management.
  • Administer and enhance PKI platforms such as Microsoft AD Certificate Services (ADCS), DigiCert, and Keyfactor certificate lifecycle management tooling.
  • Manage and support public and private certificates used for infrastructure, applications, and secure service-to-service communication.
  • Integrate CyberArk and PKI capabilities into applications, platforms, and cloud environments to enable secure privileged and machine‑based access.
  • Develop and maintain automation for CyberArk and PKI workflows using scripting and API‑based integrations (e.g., PowerShell, Python).
  • Partner with infrastructure, cloud, and application teams to onboard systems into CyberArk and PKI services and remediate security gaps.
  • Troubleshoot and resolve complex CyberArk‑and PKI‑related issues, including credential failures, certificate outages, and access disruptions.
  • Ensure PAM and PKI services meet availability, resiliency, and operational performance requirements in a global environment.
  • Support audit, compliance, and security review activities related to privileged access and cryptographic controls.
  • Maintain technical documentation, configuration standards, and operational runbooks to support scalable operations.
  • Continuously improve privileged access and PKI maturity through automation, platform enhancements, and process optimization.

Job Requirements:

Essential Qualifications:

  • 5+ years of hands‑on experience in Identity & Access Management or Security Engineering roles, with strong focus on CyberArk and PKI.
  • Demonstrated enterprise experience implementing and operating CyberArk PAM solutions.
  • Strong hands‑on experience with PKI concepts and technologies, including certificate lifecycle management, trust models, and cryptographic standards.
  • Experience administering Microsoft AD Certificate Services (ADCS) and managing public SSL/TLS certificates.
  • Solid understanding of privileged access concepts including credential vaulting, session management, and least privilege.
  • Proficiency in scripting and automation using tools such as PowerShell or Python.
  • Experience integrating CyberArk and PKI solutions with Active Directory, cloud platforms (Azure and/or AWS), and enterprise applications.
  • Ability to independently own complex technical implementations while collaborating across a global organization.
  • Strong troubleshooting, documentation, and communication skills.

Desirable Qualifications:

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical discipline.
  • CyberArk certifications such as CyberArk Defender or equivalent.
  • Experience with certificate management platforms such as Keyfactor or Venafi.
  • Experience integrating PAM or PKI into CI/CD pipelines, DevOps workflows, or secrets management solutions.
  • Familiarity with security and compliance frameworks such as SOX, ISO 27001, or NIST.
  • Experience operating IAM or security platforms within a large, global, or highly regulated enterprise.

About UMG UK: We are Universal Music Group UK – the UK’s leading music‑based entertainment company. We exist to shape culture through the power of artistry. We help UK artists produce, distribute and promote the most critically acclaimed and commercially successful music to inspire and entertain fans at home and around the world.

Bonus Tracks: Your Benefits:

  • Group Personal Pension Scheme (between 3% and 9%)
  • Private Medical Insurance
  • 25 paid days of annual leave
  • Interest Free Season Ticket Loan
  • Holiday Purchase scheme
  • Dental and Travel Insurance options
  • Cycle to Work Scheme
  • Salary Sacrifice Cars
  • Subsidised Gym Membership
  • Employee Discounts (Reward Gateway)

Just So You Know… The company presents this job description as a guide to the major areas and duties for which the jobholder is accountable. However, the business operates in an environment that demands change and the jobholder's specific responsibilities and activities will vary and develop. Therefore, the job description should be seen as indicative and not as a permanent, definitive, and exhaustive statement.

IAM Engineer - PAM & PKI in London employer: Universal Music Group UK

At Universal Music Group UK, we pride ourselves on being an exceptional employer that fosters a vibrant and inclusive work culture. Our IAM Engineer role offers not only competitive benefits such as a Group Personal Pension Scheme and private medical insurance but also ample opportunities for professional growth within the dynamic music industry. Join us in a collaborative environment where your contributions are valued, and diversity of thought is celebrated, making every day at UMG a rewarding experience.

Universal Music Group UK

Contact Details:

Universal Music Group UK Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land IAM Engineer - PAM & PKI in London

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend events, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their values and how they align with your skills, especially in IAM and PKI. This will help you stand out as a candidate who truly gets what they're about.

Tip Number 3

Practice your technical skills! Brush up on CyberArk and PKI concepts, and be ready to demonstrate your expertise during technical interviews. Hands-on experience speaks volumes, so don’t shy away from showcasing your projects.

Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining our team at Universal Music.

We think you need these skills to ace IAM Engineer - PAM & PKI in London

Identity & Access Management
CyberArk
Public Key Infrastructure (PKI)
Privileged Access Management (PAM)
Microsoft AD Certificate Services (ADCS)
Certificate Lifecycle Management
Scripting (PowerShell, Python)

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the IAM Engineer role. Highlight your experience with CyberArk and PKI, and don’t forget to mention any relevant projects or achievements that showcase your skills.

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you’re passionate about this role at Universal Music and how your background makes you a perfect fit for the team.

Showcase Your Technical Skills:Since this role is all about technical expertise, be sure to include specific examples of your hands-on experience with IAM tools, scripting, and automation. We want to see what you can do!

Apply Through Our Website:Don’t forget to apply through our website! It’s the best way to ensure your application gets into the right hands. Plus, we love seeing candidates who take the initiative to follow our process.

How to prepare for a job interview at Universal Music Group UK

Know Your CyberArk Inside Out

Make sure you’re well-versed in CyberArk and its components. Brush up on your knowledge of Vault, CPM, PVWA, and PSM. Be ready to discuss how you've implemented these tools in past roles and any challenges you faced.

Showcase Your PKI Expertise

Prepare to talk about your experience with Public Key Infrastructure. Highlight specific projects where you managed certificate lifecycle processes or integrated PKI solutions. This will demonstrate your hands-on experience and technical depth.

Demonstrate Problem-Solving Skills

Be ready to share examples of complex issues you've resolved related to CyberArk or PKI. Discuss your troubleshooting process and how you collaborated with teams to remediate security gaps. This shows your ability to think critically under pressure.

Emphasise Collaboration and Communication

Since this role involves partnering with various teams, highlight your communication skills. Share experiences where you successfully collaborated across departments to achieve a common goal, especially in a global context.