hirly

Umusic

IAM Engineer - SSO

Carnaby Street, London

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Umusic first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.5M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Mid level
Country
GB
Work mode
On-site / unstated
First seen by hirly
27 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Music is Universal

It’s the passionate and dedicated team at Universal Music who help make us the world’s leading music company. From A&R to finance, legal to digital, sales to marketing, Universal Music is the place to grow and develop your career within a truly commercial and innovative business that leads in everything it does.

Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of gender, race, disability, sexual orientation, religion, belief, age, marital status, background, pregnancy, or caring responsibilities. We also recognise the importance of diversity of thought within our teams and are fully committed to embracing the talents of people with autism, dyslexia, ADHD, and other forms of neurocognitive variation.

We will always seek to make appropriate adjustments to recruitment, workplaces, and work processes to be fully inclusive to people with different needs and working styles. If you need us to make any reasonable adjustments for you from application onwards, including alternatives to the online form or to disclose a neurocognitive condition, please email UniversalMusicCareers@umusic.com.

Job Summary

We are currently seeking an Identity & Access Management Engineer with specialization in Access Management to join UMG’s global Tech Security & Identity organization. Reporting to the Manager, Access ManagementVP, Tech Security & Identity, this is a hands-on engineering role responsible for designing, implementing, and operating enterprise access management capabilities across a global, hybrid environment – including workforce, partner, customer, and consumer experiences.

This engineer will play a critical role in securing authentication and authorization for workforce and application access, delivering scalable solutions across Single Sign-On (SSO), federation, and multi-factor authentication (MFA). The role emphasizes strong technical execution, platform reliability, and automation, working closely with application, infrastructure, and security teams to enable secure access while maintaining a strong user experience. The ideal candidate brings deep experience with modern access management platforms and protocols, and the ability to operate access services at enterprise scale.

Job Functions

Design, engineer, deploy, and operate Access Management solutions across the enterprise.

Implement and support Single Sign-On (SSO) and federation services using modern identity protocols.

Engineer and maintain authentication and authorization services including MFA, adaptive access, and conditional access policies.

Integrate applications and platforms with enterprise access management systems across on-premises and cloud environments.

Partner with application owners and platform teams to onboard applications to SSO and enforce consistent authentication standards.

Design and maintain secure federation integrations using protocols such as SAML, OAuth 2.0, and OpenID Connect (OIDC).

Develop and maintain automation and tooling to support access onboarding, configuration, and lifecycle management.

Troubleshoot and resolve complex authentication, authorization, and federation issues impacting users or applications.

Ensure access management services meet availability, performance, and resiliency requirements in a global environment.

Support audit, compliance, and security review activities related to access controls and authentication mechanisms.

Maintain technical documentation, standards, and runbooks for access management platforms and integrations.

Continuously improve access security and user experience through platform enhancements, automation, and adoption of modern authentication patterns.

Job Requirements

Essential Qualifications

5+ years of hands-on experience in Identity & Access Management or Security Engineering roles, with strong focus on Access Management.

Demonstrated experience implementing and operating enterprise access management platforms (e.g., Ping Identity, Okta, Microsoft Entra ID, or equivalent).

Strong understanding of authentication and authorization concepts, including SSO, federation, MFA, and adaptive access.

Hands-on experience with identity protocols and standards such as SAML, OAuth 2.0, OpenID Connect (OIDC), and LDAP.

Experience integrating identity platforms with cloud applications, SaaS platforms, and custom-built applications.

Proficiency in scripting and automation using tools such as PowerShell or Python.

Experience operating access services in hybrid and cloud environments (Azure and/or AWS).

Ability to independently own complex technical implementations while collaborating across a global organization.

Strong troubleshooting, documentation, and communication skills.

Desirable Qualifications

Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical discipline.

Experience with passwordless authentication technologies and modern identity standards.

Familiarity with Zero Trust and conditional access models.

Experience supporting authentication services in high-availability, 24x7 enterprise environments.

Experience with identity verification solutions and technolgies.

Professional certifications such as Ping Identity Certified Professional, Microsoft Certified: Identity and Access Administrator, Security+, or CISSP.

Experience operating IAM platforms within a large, global, or highly regulated enterprise environment.

About UMG UK

We are Universal Music Group UK – the UK’s leading music-based entertainment company. We exist to shape culture through the power of artistry. We help UK artists produce, distribute and promote the most critically acclaimed and commercially successful music to inspire and entertain fans at home and around the world.​

Bonus Tracks: Your Benefits

Group Personal Pension Scheme (between 3% and 9%)

Private Medical Insurance

25 paid days of annual leave

Interest Free Season Ticket Loan

Holiday Purchase scheme

Dental and Travel Insurance options

Cycle to Work Scheme

Salary Sacrifice Cars

Subsidised Gym Membership

Employee Discounts (Reward Gateway)

Just So You Know…

The company presents this job description as a guide to the major areas and duties for which the jobholder is accountable. However, the business operates in an environment that demands change and the jobholder's specific responsibilities and activities will vary and develop. Therefore, the job description should be seen as indicative and not as a permanent, definitive, and exhaustive statement.

Job Category:

Universal Music Group

Original posting on Umusic's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job