IAM Engineer - PAM & PKI in London

IAM Engineer - PAM & PKI in London

London Full-Time 60000 - 80000 £ / year (est.) No home office possible
Universal Music

At a Glance

  • Tasks: Design and implement cutting-edge security solutions for privileged access management and public key infrastructure.
  • Company: Join Universal Music Group, the world's leading music company with a vibrant culture.
  • Benefits: Enjoy competitive salary, private medical insurance, and generous annual leave.
  • Other info: Diverse and inclusive workplace committed to supporting all talents.
  • Why this job: Make a real impact in securing identities while working in a dynamic, creative environment.
  • Qualifications: 5+ years in IAM or Security Engineering, with strong CyberArk and PKI experience.

The predicted salary is between 60000 - 80000 £ per year.

Music is Universal

It’s the passionate and dedicated team at Universal Music who help make us the world’s leading music company. From A&R to finance, legal to digital, sales to marketing, Universal Music is the place to grow and develop your career within a truly commercial and innovative business that leads in everything it does.

Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of gender, race, disability, sexual orientation, religion, belief, age, marital status, background, pregnancy, or caring responsibilities. We also recognise the importance of diversity of thought within our teams and are fully committed to embracing the talents of people with autism, dyslexia, ADHD, and other forms of neurocognitive variation.

We will always seek to make appropriate adjustments to recruitment, workplaces, and work processes to be fully inclusive to people with different needs and working styles. If you need us to make any reasonable adjustments for you from application onwards, including alternatives to the online form or to disclose a neurocognitive condition, please email UniversalMusicCareers@umusic.com.

Job Summary

We are currently seeking an Identity & Access Management Engineer with deep specialization in Privileged Access Management (PAM) and Public Key Infrastructure (PKI) to join UMG’s global Tech Security & Identity organization. Reporting to the VP, Tech Security & Identity, this role is a hands-on engineering position focused on designing, implementing, and operating enterprise-grade PAM and PKI capabilities across a complex, global environment.

This engineer will play a critical role in securing privileged identities, service accounts, machine identities, and cryptographic trust across on-premises and cloud platforms. The position emphasizes technical execution, automation, and operational excellence, partnering closely with infrastructure, security, and application teams to reduce risk, improve resilience, and scale identity security services. The ideal candidate brings strong CyberArk and PKI experience, an automation-first mindset, and the ability to operate effectively in a regulated, highly distributed enterprise.

Job Functions

  • Design, engineer, deploy, and operate Privileged Access Management solutions, with primary responsibility for CyberArk platforms including Vault, CPM, PVWA, PSM, and related integrations.

  • Implement and manage PAM controls for human and non-human identities, including privileged users, service accounts, application credentials, and secrets.

  • Engineer and support enterprise PKI services, including certificate issuance, renewal, revocation, and lifecycle automation across infrastructure, applications, and end-user devices.

  • Administer and enhance PKI platforms and services such as Microsoft AD Certificate Services (ADCS), public certificate authorities, and certificate lifecycle management tools.

  • Develop and maintain automation for PAM and PKI workflows using scripting and infrastructure-as-code approaches (PowerShell, Python, Terraform, APIs).

  • Partner with application, cloud, and infrastructure teams to integrate PAM and PKI capabilities into platforms, CI/CD pipelines, and operational processes.

  • Define and enforce privileged access policies, credential management standards, and cryptographic controls aligned to security, audit, and compliance requirements.

  • Troubleshoot and resolve complex PAM and PKI incidents, including certificate outages, access failures, and privileged session issues.

  • Contribute to operational readiness, monitoring, and audit support activities related to PAM and PKI controls (e.g., SOX, ISO 27001, internal audits).

  • Maintain technical documentation, runbooks, and configuration standards to support scalable and repeatable operations.

  • Continuously evaluate opportunities to improve security posture, resilience, and efficiency through automation, tooling enhancements, and process optimization.

Job Requirements

Essential Qualifications

  • 5+ years of hands-on experience in Identity & Access Management or Security Engineering roles, with strong focus on Privileged Access Management and/or PKI.

  • Demonstrated experience engineering and operating CyberArk PAM solutions in an enterprise environment.

  • Strong hands-on experience with PKI concepts and technologies, including certificate lifecycle management, trust models, and cryptographic standards.

  • Experience administering Microsoft AD Certificate Services (ADCS) and managing public SSL/TLS certificates.

  • Proficiency in scripting and automation using tools such as PowerShell and Python; experience with infrastructure-as-code or API-based integrations preferred.

  • Solid understanding of identity, authentication, and access control concepts, particularly as they relate to privileged and machine identities.

  • Experience working in hybrid and cloud environments (Azure and/or AWS) integrating PAM and PKI controls.

  • Ability to work independently on complex technical problems while collaborating effectively within a global, cross-functional team.

  • Strong troubleshooting, documentation, and communication skills, with the ability to explain technical issues to non-specialist stakeholders.

Desirable Qualifications

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical discipline.

  • Experience with certificate management platforms such as Keyfactor or Venafi.

  • Experience integrating PAM or PKI into CI/CD pipelines, DevOps tooling, or secrets management solutions.

  • Familiarity with identity and security compliance frameworks such as SOX, ISO 27001, NIST, or similar.

  • Professional certifications such as CyberArk Defender, Microsoft Certified: Identity and Access Administrator, Security+, CISSP, or similar.

  • Experience operating IAM or security services within a large, global, or highly regulated enterprise environment.

About UMG UK

We are Universal Music Group UK – the UK’s leading music-based entertainment company. We exist to shape culture through the power of artistry. We help UK artists produce, distribute and promote the most critically acclaimed and commercially successful music to inspire and entertain fans at home and around the world.

Bonus Tracks: Your Benefits

  • Group Personal Pension Scheme (between 3% and 9%)

  • Private Medical Insurance

  • 25 paid days of annual leave

  • Interest Free Season Ticket Loan

  • Holiday Purchase scheme

  • Dental and Travel Insurance options

  • Cycle to Work Scheme

  • Salary Sacrifice Cars

  • Subsidised Gym Membership

  • Employee Discounts (Reward Gateway)

Just So You Know…

The company presents this job description as a guide to the major areas and duties for which the jobholder is accountable. However, the business operates in an environment that demands change and the jobholder’s specific responsibilities and activities will vary and develop. Therefore, the job description should be seen as indicative and not as a permanent, definitive, and exhaustive statement.

Job Category:

Universal Music Group

IAM Engineer - PAM & PKI in London employer: Universal Music

At Universal Music Group UK, we pride ourselves on fostering a vibrant and inclusive work culture that champions creativity and innovation. As an IAM Engineer focusing on PAM and PKI, you will not only have the opportunity to work with cutting-edge technology in a globally recognised music company but also benefit from a comprehensive range of perks including private medical insurance, generous annual leave, and professional development opportunities. Join us in shaping culture through artistry while enjoying a supportive environment that values diversity and personal growth.
Universal Music

Contact Detail:

Universal Music Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land IAM Engineer - PAM & PKI in London

✨Tip Number 1

Network like a pro! Reach out to folks in the industry, attend events, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their values and how your skills align with their needs. This will help you stand out and show that you're genuinely interested in being part of their team.

✨Tip Number 3

Practice makes perfect! Do mock interviews with friends or use online platforms to get comfortable answering common questions. The more you practice, the more confident you'll feel when it’s time to shine.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are proactive about their job search!

We think you need these skills to ace IAM Engineer - PAM & PKI in London

Privileged Access Management (PAM)
Public Key Infrastructure (PKI)
CyberArk
Microsoft AD Certificate Services (ADCS)
Certificate Lifecycle Management
Scripting (PowerShell, Python)
Infrastructure-as-Code
API-based Integrations
Identity and Access Management (IAM)
Troubleshooting Skills
Documentation Skills
Communication Skills
Cloud Environments (Azure, AWS)
Security Compliance Frameworks (SOX, ISO 27001, NIST)

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the IAM Engineer role. Highlight your experience with PAM and PKI, and don’t forget to mention any relevant projects or achievements that showcase your skills.

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you’re passionate about this role at Universal Music and how your background makes you a perfect fit for the team.

Show Off Your Technical Skills: In your application, be sure to detail your hands-on experience with CyberArk and PKI technologies. We want to see your technical prowess, so don’t hold back on the specifics!

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands and shows us you’re serious about joining our team!

How to prepare for a job interview at Universal Music

✨Know Your Tech Inside Out

Make sure you brush up on your CyberArk and PKI knowledge. Be ready to discuss specific projects where you've implemented PAM solutions or managed certificate lifecycles. The more detailed your examples, the better!

✨Show Off Your Automation Skills

Since this role emphasises automation, prepare to talk about your experience with scripting and infrastructure-as-code. Bring examples of how you've used PowerShell or Python to streamline processes in previous roles.

✨Understand the Bigger Picture

Familiarise yourself with how PAM and PKI fit into the overall security landscape. Be prepared to discuss compliance frameworks like SOX or ISO 27001, and how they relate to the role you're applying for.

✨Be Ready for Problem-Solving Questions

Expect to tackle some technical scenarios during the interview. Think through complex incidents you've resolved in the past, especially those involving access failures or certificate outages, and be ready to explain your thought process.

IAM Engineer - PAM & PKI in London
Universal Music
Location: London

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>