About the Role
We are UMG, the Universal Music Group, the world’s leading music company. We are currently seeking an experienced Sr. Identity Access Management Architect to lead architectural design, strategic planning, and delivery across the full Identity & Access Management landscape. The Architect will shape UMG’s global identity ecosystem across Access Management, IGA, PAM, Directory Services, and PKI, driving scalable, secure solutions and leading complex integrations across on‑premises and multi‑cloud environments.
Responsibilities
- Architect and design enterprise‑wide IAM solutions aligned with business goals, security policies, and compliance requirements.
- Provide leadership and oversight for PAM, IGA, SSO, MFA, Federation, PKI, Directory Services, and Secrets Management.
- Define technical direction for IAM tools and develop a strategic framework for implementation companywide, emphasizing standard configurations.
- Lead architecture planning and lifecycle designs for all personas, including employees, partners, customers, and non‑human identities.
- Establish the target‑state identity architecture and guide engineering teams to implement that vision.
- Develop secure, scalable authentication, authorization, and account provisioning workflows.
- Partner with engineering teams to integrate identity services into applications and infrastructure using APIs and automation pipelines.
- Evaluate complex business requirements and guide cross‑functional teams to implement secure identity frameworks.
- Create and maintain architectural documentation, standards, and design patterns for IAM services.
- Contribute to solution development and code when needed, and review designs to ensure compliance with architecture and security standards.
- Engage with internal and external stakeholders to communicate strategy, resolve roadblocks, and champion IAM modernization initiatives.
Qualifications
- 10+ years of experience in IAM or Security Architecture roles, with demonstrated success in designing enterprise‑scale IAM platforms.
- Strong expertise with IAM protocols (SAML, OAuth2, OIDC, SCIM, LDAP, Kerberos, FIDO) and modern cloud identity models.
- Hands‑on experience with products such as CyberArk, PingOne, Ping Davinci, EntraID, Saviynt, HashiCorp Vault, Digicert, Onfido, and Active Directory.
- Expert‑level understanding of Authentication, Authorization, Directory Services, PKI, MFA, Federation, and PAM.
- Experience designing secure APIs and automating operational functions.
- Proven ability to lead architectural governance and collaborate across security, infrastructure, application, and compliance teams.
- Track record of implementing secure, scalable identity solutions in multi‑cloud and hybrid environments.
- Excellent communication and leadership skills with the ability to influence at all levels of the organization.
- Experience working in Agile environments with cross‑functional engineering teams.
Desired Skills
- Bachelor’s or Master’s Degree in Computer Science, Engineering, or related technical discipline.
- Professional certifications such as CISSP, CISM, Microsoft Certified: Identity and Access Administrator, or TOGAF.
- Background in risk‑based authentication, adaptive access, and identity analytics.
- Experience in media, entertainment, or global enterprises.
- Experience in cloud application development and maintenance.
- Strong understanding of cloud security, container security, and zero‑trust architecture.
- Experience deploying passwordless technology in a hybrid environment.
- Knowledge of IAM‑related compliance frameworks such as SOX, GDPR, NIST, ISO27001.
Benefits
- Comprehensive medical, dental, and vision coverage.
- 100% coverage for out‑patient in‑network mental health services.
- Fertility coverage for eligible medical plan participants.
- Wellbeing reimbursements for fitness classes, spa treatments, meal services, travel, and more (up to $720/year).
- Student Loan Repayment Assistance and Tuition Reimbursement.
- 401(k) with 100% immediate vesting on the first 5% of your contributions plus an additional UMG contribution.
- Flexible Paid Time Off (PTO) for exempt employees; 3‑weeks PTO for non‑exempt employees.
- 2‑weeks paid Winter Break.
- 10 Company Holidays (including Juneteenth and Wellbeing Day).
- Summer Fridays (between Memorial Day and Labor Day).
- Generous paid parental leave for every type of parent.
Universal Music Group is an Equal Opportunity Employer. We are an E‑Verify employer in Alabama, Arizona, Georgia, Mississippi, North Carolina, South Carolina, Tennessee, and Utah. Please note, UMG is not enrolled in E‑Verify in California and New York, and cannot support employment of candidates whose employer must enroll in E‑Verify (for example candidates on STEM‑OPT).