About this role
Job title: Identity Access Management (IAM) Engineer – Identity Governance and Administration
About the Role We are seeking an Identity & Access Management (IAM) Engineer with a specialization in Identity Governance & Administration (IGA) to join UMG’s global Tech Security & Identity organization. This hands-on role designs, implements, and operates enterprise IGA capabilities across a complex, global environment, governing digital identities, access entitlements, and lifecycle processes for employees, contractors, and non-employee populations.
What You'll Do
- Design, engineer, deploy, and operate Identity Governance & Administration (IGA) solutions across the enterprise.
- Implement and manage identity lifecycle (joiner, mover, leaver) workflows for employees and non-employee identities.
- Engineer and maintain access request, approval, and provisioning workflows integrated with HR systems, directories, and enterprise applications.
- Design and operate access governance controls including role models, entitlement catalogs, access certifications, and periodic access reviews.
- Onboard applications into IGA, remediate gaps; develop automations/integrations using scripting, APIs, and IaC (PowerShell, Python).
- Support SoD controls, policy enforcement, and audit readiness. Troubleshoot complex lifecycle provisioning issues.
- Collaborate with Security, HR, Compliance, and Infrastructure; maintain documentation and runbooks; identify opportunities to improve automation and maturity.
What We're Looking For
- 5+ years of hands-on experience in Identity & Access Management or Security Engineering with focus on IGA.
- Experience implementing and operating enterprise IGA platforms (Saviynt, SailPoint, or equivalent).
- Strong understanding of identity lifecycle management, RBAC, and entitlement governance.
- Hands-on experience designing and supporting access certification campaigns and remediation.
- Experience integrating IGA with HR systems, Active Directory / Entra ID, and enterprise applications.
- Proficiency in scripting/automation using PowerShell or Python.
- Experience in hybrid/cloud environments (Azure and/or AWS) with IAM integrations.
- Ability to independently own complex technical deliverables; strong troubleshooting, documentation, and communication skills.
Nice to Have
- Bachelor’s degree in Computer Science, Information Security, Engineering, or related technical discipline.
- Experience with advanced IGA capabilities such as role mining, access analytics, or policy-based provisioning.
- Familiarity with compliance and audit frameworks such as SOX, ISO 27001, NIST, or similar.
- Professional certifications such as Saviynt Certified Professional, SailPoint Certified IdentityIQ Engineer, Security+, or CISSP.
- Experience operating IAM or identity governance platforms within a large, global, or highly regulated enterprise environment.
Compensation & Benefits
- Comprehensive medical, dental, and vision coverage.
- 100% coverage for outpatient in-network mental health services.