Identity Access Management (IAM) Engineer – Identity Governance and Administration

Reposted 2 Days Ago
Be an Early Applicant
Nashville, TN, USA
In-Office
101K-145K Annually
Senior level
Music • News + Entertainment
The Role
The IAM Engineer will design, implement, and operate Identity Governance & Administration solutions, manage identity lifecycle processes, and ensure access governance controls align with security policies.
Summary Generated by Built In

We are UMG, the Universal Music Group. We are the world’s leading music company. In everything we do, we are committed to artistry, innovation and entrepreneurship. We own and operate a broad array of businesses engaged in recorded music, music publishing, merchandising, and audiovisual content in more than 60 countries. We identify and develop recording artists and songwriters, and we produce, distribute and promote the most critically acclaimed and commercially successful music to delight and entertain fans around the world.
 

Job Summary 

We are currently seeking an Identity & Access Management Engineer with specialization in Identity Governance & Administration (IGA) to join UMG’s global Tech Security & Identity organization. Reporting to the VP, Tech Security & Identity, this is a hands-on engineering role responsible for designing, implementing, and operating enterprise IGA capabilities across a complex, global environment. 

This engineer will play a critical role in governing digital identities, access entitlements, and lifecycle processes for employees, contractors, and non-employee populations. The role emphasizes strong engineering execution, automation, and operational discipline, partnering closely with security, HR, infrastructure, and application teams to ensure access is provisioned appropriately, reviewed regularly, and removed in a timely manner. The ideal candidate brings deep experience with modern IGA platforms, strong understanding of access governance controls, and the ability to operate at scale in a regulated enterprise. 

Job Functions 

Design, engineer, deploy, and operate Identity Governance & Administration (IGA) solutions across the enterprise. 

Implement and manage identity lifecycle processes including joiner, mover, and leaver (JML) workflows for employees and non-employee identities. 

Engineer and maintain access request, approval, and provisioning workflows integrated with HR systems, directories, and enterprise applications. 

Design and operate access governance controls including role models, entitlement catalogs, access certifications, and periodic access reviews. 

Partner with application owners and platform teams to onboard applications into IGA and remediate access governance gaps. 

Develop and maintain automation and integrations for IGA workflows using scripting, APIs, and infrastructure-as-code approaches (e.g., PowerShell, Python). 

Support segregation of duties (SoD) controls, access policy enforcement, and audit readiness activities. 

Troubleshoot and resolve complex identity lifecycle, provisioning, and access-related issues across integrated systems. 

Collaborate with Security, HR, Compliance, and Infrastructure teams to ensure identity governance controls align with security policies and regulatory requirements. 

Maintain technical documentation, configuration standards, and operational runbooks to support scalable and repeatable IGA operations. 

Continuously identify opportunities to improve access governance maturity, reduce manual effort, and enhance user experience through automation and platform enhancements. 

Job Requirements 

Essential Qualifications 

5+ years of hands-on experience in Identity & Access Management or Security Engineering roles, with a strong focus on Identity Governance & Administration. 

Demonstrated experience implementing and operating enterprise IGA platforms (e.g., Saviynt, SailPoint, or equivalent). 

Strong understanding of identity lifecycle management, access provisioning, role-based access control (RBAC), and entitlement governance. 

Hands-on experience designing and supporting access certification campaigns and remediation processes. 

Experience integrating IGA solutions with HR systems, Active Directory / Entra ID, and enterprise applications. 

Proficiency in scripting and automation using tools such as PowerShell or Python. 

Experience working in hybrid and cloud environments (Azure and/or AWS) with IAM integrations. 

Ability to independently own complex technical deliverables while collaborating effectively within a global organization. 

Strong troubleshooting, documentation, and communication skills. 

Desirable Qualifications 

Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical discipline. 

Experience with advanced IGA capabilities such as role mining, access analytics, or policy-based provisioning. 

Familiarity with compliance and audit frameworks such as SOX, ISO 27001, NIST, or similar. 

Professional certifications such as Saviynt Certified Professional, SailPoint Certified IdentityIQ Engineer, Security+, or CISSP. 

Experience operating IAM or identity governance platforms within a large, global, or highly regulated enterprise environment. 

Perks Playlist:

Join an entrepreneurial, global organization where authenticity, boldness, creativity, connection, drive, and insight aren’t just values—they’re how we work every day. Here are some of the ways we support you along the way (and just a few of the benefits we offer):

  • Comprehensive medical, dental, and vision coverage

  • Including 100% coverage for out-patient in-network mental health services

  • Fertility coverage for eligible medical plan participants

  • Wellbeing reimbursements for fitness classes, spa treatments, meal services, travel, and so much more (up to $720/year)

  • Student Loan Repayment Assistance and Tuition Reimbursement

  • 401(k) with 100% immediate vesting on the first 5% of your contributions, plus an additional UMG contribution

A variety of ways to prioritize much-needed time away from work including:

  • Flexible Paid Time Off (PTO) for exempt employees

  • 3-weeks PTO for non-exempt employees

  • 2-weeks paid Winter Break

  • 10 Company Holidays (including Juneteenth and Wellbeing Day)

  • Summer Fridays (between Memorial Day and Labor Day)

  • Generous paid parental leave for every type of parent

Check out our full overview of benefits on the Perks Playlist page of the career site.

Disclaimer: This job description only provides an overview of job responsibilities that are subject to change.
Universal Music Group is an Equal Opportunity Employer

We are an E-Verify employer in Alabama, Arizona, Georgia, Mississippi, North Carolina, South Carolina, Tennessee, and Utah.

Please note, UMG is not enrolled in E-Verify in California and New York, and cannot support employment of candidates whose employer must enroll in E-Verify, for example candidates on STEM-OPT.

For more information, please click on the following links.

E-Verify Participation Poster: English / Spanish

E-Verify Right to Work Poster: English | Spanish


Job Category:
Technology

Salary Range:

$101,340 - $145,205

The actual base salary offered depends on a variety of factors, which may include, as applicable, the qualifications of the individual applicant for the position, years of relevant experience, specific and unique skills, level of education attained, certifications or other professional licenses held, and the location in which the applicant lives and/or from which they will be performing the job.  All candidates are encouraged to apply.

Skills Required

  • 5+ years of hands-on experience in Identity & Access Management or Security Engineering roles
  • Experience implementing and operating enterprise IGA platforms
  • Strong understanding of identity lifecycle management and access provisioning
  • Hands-on experience designing access certification campaigns
  • Experience integrating IGA solutions with HR systems and Active Directory
  • Proficiency in scripting and automation using PowerShell or Python
  • Experience working in hybrid and cloud environments (Azure and/or AWS)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Santa Monica, CA
9,189 Employees

What We Do

Universal Music Group (UMG) is the world leader in music-based entertainment, with a broad array of businesses engaged in recorded music, music publishing, merchandising and audiovisual content in more than 60 countries. Featuring the most comprehensive catalog of recordings and songs across every musical genre, UMG identifies and develops artists and produces and distributes the most critically acclaimed and commercially successful music in the world. Committed to artistry, innovation and entrepreneurship, UMG fosters the development of services, platforms and business models in order to broaden artistic and commercial opportunities for our artists and create new experiences for fans. Universal Music Group's labels include A&M Records, Astralwerks, Blue Note Records, Capitol Christian Music Group, Capitol Records, Capitol Records Nashville, Caroline, Decca, Def Jam Recordings, Deutsche Grammophon, Disa, Emarcy, EMI Records Nashville, Fonovisa, Geffen Records, Harvest, Interscope Records, Island Records, Machete Music, MCA Nashville, Mercury Nashville, Mercury Records, Motown Records, Polydor Records, Republic Records, Universal Music Latino, Verve Label Group, Virgin Records, Virgin EMI Records, as well as a multitude of record labels owned or distributed by its record company subsidiaries around the world. UMG's catalog is marketed through two distinct divisions, Universal Music Enterprises (in the U.S.) and Universal Strategic Marketing (outside the U.S.). UMG also includes Universal Music Publishing Group, one of the industry's premier music publishing operations worldwide and Bravado, the leading provider of consumer, lifestyle and branding services to recording artists and entertainment brands around the world. Universal Music Group is a Vivendi company.

Why Work With Us

UMG's IT department delivers technology solutions and services that unlock business value and facilitate growth through strategic investment and operational efficiency. Our team is collaborative, dedicated and passionate about the work we do. Here you can work in a dynamic and flexible environment with evolving opportunities to grow!

Similar Jobs

HiBob Logo HiBob

Senior Product Manager

HR Tech • Information Technology • Professional Services • Sales • Software
Remote or Hybrid
United States
1350 Employees
160K-215K Annually

Optum Logo Optum

CNA - McKenzie

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
McKenzie, TN, USA
160000 Employees
14-25 Hourly

Optum Logo Optum

RN - Per Diem - PPV

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Dyersburg, TN, USA
160000 Employees
31-82 Hourly

Magna International Logo Magna International

EH&S Specialist

Automotive • Hardware • Robotics • Software • Transportation • Manufacturing
Hybrid
Ethridge, TN, USA
171000 Employees

Similar Companies Hiring

Bose Thumbnail
Automotive • eCommerce • Hardware • Music • Retail • Software • Wearables
Framingham, MA
2900 Employees
Sandbox VR Thumbnail
Events • Gaming • News + Entertainment • Retail • Virtual Reality
Tsim Sha Tsui East, Kowloon
650 Employees
Hedra Thumbnail
Software • News + Entertainment • Marketing Tech • Generative AI • Enterprise Web • Digital Media • Consumer Web
San Francisco, CA
14 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account