
Identity Access Management (IAM) Engineer – Identity Governance and Administration
Universal Music Group5 months ago
Nashville, TN, USASenior
Base Salary
$101k - $145k/yr
Responsibilities
- Design, engineer, deploy, and operate enterprise Identity Governance and Administration solutions.
- Implement and maintain joiner, mover, and leaver identity lifecycle workflows for employees and non-employee populations.
- Engineer access request, approval, provisioning, role, entitlement, certification, and periodic access review processes.
- Integrate IGA solutions with HR systems, directories, and enterprise applications, including application onboarding.
- Develop automation and integrations using PowerShell, Python, APIs, and infrastructure-as-code approaches.
- Support segregation-of-duties controls, access policy enforcement, audit readiness, troubleshooting, documentation, and operational runbooks.
- Partner with security, HR, compliance, infrastructure, application, and platform teams to improve governance maturity and reduce manual effort.
Requirements
- At least 5 years of hands-on experience in IAM or security engineering, with a strong focus on IGA.
- Hands-on experience implementing and operating enterprise IGA platforms such as Saviynt, SailPoint, or equivalent.
- Strong understanding of identity lifecycle management, access provisioning, role-based access control, and entitlement governance.
- Experience designing and supporting access certification campaigns and remediation processes.
- Experience integrating IGA solutions with HR systems, Active Directory, Entra ID, and enterprise applications.
- Proficiency in scripting and automation using PowerShell or Python.
- Experience working in hybrid and cloud environments with Azure and/or AWS IAM integrations.
- Ability to independently own complex technical deliverables and collaborate within a global organization.
- Strong troubleshooting, documentation, and communication skills.
- Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical discipline is desirable.
- Preferred qualifications include role mining, access analytics, policy-based provisioning, compliance and audit framework familiarity, and certifications such as Saviynt Certified Professional, SailPoint Certified IdentityIQ Engineer, Security+, or CISSP.
- Experience in a large, global, or highly regulated enterprise environment is desirable.
Benefits
- Comprehensive medical, dental, and vision coverage, including full coverage for in-network outpatient mental health services.
- Fertility coverage for eligible medical plan participants.
- Wellbeing reimbursements for fitness classes, spa treatments, meal services, travel, and other activities up to $720 per year.
- Student loan repayment assistance and tuition reimbursement.
- 401(k) with immediate vesting on the first 5% of employee contributions plus an additional UMG contribution.
- Flexible PTO for exempt employees or three weeks of PTO for non-exempt employees.
- Two-week paid winter break, 10 company holidays, and Summer Fridays between Memorial Day and Labor Day.
- Generous paid parental leave for every type of parent.
- The role is part of a global organization; employment eligibility is subject to stated E-Verify limitations in certain states.