Logo
Universal Music Group

Identity and Access Management - Nashville, 37201

Universal Music Group, Nashville

Save Job

Identity and Access Management - Nashville, 37201, United States of America

We are currently seeking an IAM Engineer to join our global Tech Security team. The ideal candidate will have hands-on experience across the entire Identity & Access Management (IAM) stack, with a strong focus on engineering, automation, and AI-driven optimization of identity services. This includes delivering and maintaining enterprise-grade solutions across Privileged Access Management (PAM), Identity Governance and Administration (IGA), Public Key Infrastructure( PKI), Directory Services, Federation, and more.    
   
This role requires a combination of strong technical skills, an automation-first mindset, and the ability to work effectively with business stakeholders, infrastructure partners, and application teams.    

Job Functions:  

  • Engineer, deploy, and maintain IAM tools across the enterprise including CyberArk, Ping DaVinci, Microsoft EntraID (formerly Azure AD), HashiCorp Vault, Digicert , and Saviynt.  

  • Lead and support the implementation and enhancement of IAM services including:   
      - SSO/Federation (SAML, OIDC, WS-Fed)   
      - MFA/ Passwordless    
      - Privileged Access Management (PAM)   
      - Identity Governance (IGA)   
      - PKI and certificate lifecycle automation   
      - Directory services (AD, EntraID )   

  • Build automation scripts and integrations for IAM workflows using tools such as PowerShell, Python, or Terraform.  

  • Design and implement access controls and policies that align with security and compliance standards (SOX, GDPR, etc.).  

  • Evaluate and deploy AI-powered tools and methodologies to improve identity lifecycle efficiency, risk detection, and operational decision-making.  

  • Participate in lifecycle management processes for accounts, credentials, roles, and policies across systems and applications .  

  • Collaborate with InfoSec, Infrastructure, and App teams to ensure secure identity architecture for on-prem and cloud environments.  

  • Maintain high-quality documentation and architectural diagrams.   

  • Monitor and report metrics on IAM system performance, adoption, and audit readiness.   

J ob Requirements:  

Essential Qualifications  

  • 5+ years of hands-on experience in IAM engineering roles    

  • Deep technical expertise in one or more of the following: CyberArk, Ping Identity, Microsoft EntraID , Saviynt, HashiCorp Vault, Digicert , Onfido    

  • Solid understanding of IAM protocols and standards: SAML, OIDC, OAuth2, LDAP, Kerberos, SCIM, JIT    

  • Experience with automation tools and scripting (e.g., PowerShell, Python, Terraform)    

  • Familiarity with cloud platforms (Azure, AWS, GCP) and IAM integrations    

  • Strong understanding of IAM-related compliance frameworks and controls (e.g., SOX, ISO 27001, NIST)    

  • Proven ability to work independently and cross-functionally in a global team    

  • Strong troubleshooting, documentation, and communication skills    

D e s i rable   

  • Bachelor’s Degree in Computer Science , Engineering, or a related technical field   

  • Professional certifications such as: CISSP, Security+, Microsoft Certified: Identity and Access Administrator, CyberArk Defender, Ping Identity Certified Professional   

  • Experience with AI/ML integration into IAM workflows or security analytics   

  • Experience supporting IAM functions in media or entertainment industry environments   

  • Experience working on a global team covering multiple timezones