Talent Apply
Log in
All jobs
UM

Sr. Identity Access Management Architect

Universal Music
Nashville, Tennessee
On-site

About this role

About the Role UMG is seeking an experienced Sr. Identity Access Management Architect to lead architectural design, strategic planning, and delivery across the Identity & Access Management landscape. The role shapes UMG’s global identity ecosystem across Access Management, IGA, PAM, Directory Services, and PKI in on-premises and multi-cloud environments. This hands-on leadership role requires deep technical expertise, a strategic mindset, and the ability to influence cross-functional and executive stakeholders.

What You'll Do

  • Architect and design enterprise-wide IAM solutions aligned with business goals, security policies, and compliance requirements.
  • Provide leadership and oversight for strategic IAM functions including PAM, IGA, SSO, MFA, Federation, PKI, Directory Services, and Secrets Management.
  • Define technical direction for IAM tools and develop overall strategic framework for implementation across the company with an emphasis on standard configurations.
  • Lead architecture planning and lifecycle designs for all personas including employees, partners, customers, and non-human identities.
  • Establish the target-state identity architecture and effectively communicate and guide engineers to implementing that vision.
  • Develop secure and scalable authentication, authorization, and account provisioning workflows.
  • Partner with engineering teams to integrate identity services into applications and infrastructure using APIs and automation pipelines.
  • Evaluate complex business requirements and effectively guide cross-functional teams to implement secure identity frameworks.
  • Create and maintain architectural documentation, standards, and design patterns for IAM services.
  • Contribute to solution development and code when needed, and review designs to ensure compliance with architecture and security standards.
  • Engage with internal and external stakeholders to communicate strategy, resolve roadblocks, and champion IAM modernization initiatives.

What We're Looking For

  • 10+ years of experience in IAM or Security Architecture roles, with demonstrated success in designing enterprise-scale IAM platforms.
  • Strong expertise with IAM protocols (SAML, OAuth2, OIDC, SCIM, LDAP, Kerberos, FIDO) and modern cloud identity models.
  • Extensive hands-on experience with products like CyberArk, PingOne, Ping Davinci, EntraID, Saviynt, HashiCorp Vault, Digicert, Onfido, and Active Directory.
  • Expert-level understanding of Authentication, Authorization, Directory Services, PKI, MFA, Federation, and PAM.
  • Experience designing secure APIs and automating operational functions.
  • Proven ability to lead architectural governance and collaborate across security, infrastructure, application, and compliance teams.
  • Track record of implementing secure, scalable identity solutions in multi-cloud and hybrid environments.
  • Excellent communication and leadership skills with the ability to influence at all levels of the organization.
  • Experience working in Agile environments with cross-functional engineering teams.

Nice to Have

  • Bachelor’s or Master’s Degree in Computer Science, Engineering, or related technical discipline.
  • Professional certifications such as CISSP, CISM, Microsoft Certified: Identity and Access Administrator, or TOGAF.
  • Background in risk-based authentication, adaptive access, and identity analytics.
  • Experience in media, entertainment, or global enterprises.
  • Experience in cloud application development and maintenance.
  • Strong understanding of cloud security, container security, and zero trust architecture.
  • Experience deploying passwordless technology in a hybrid environment.
  • Knowledge of IAM-related compliance frameworks such as SOX, GDPR, NIST, ISO 27001.

Compensation & Benefits

  • Comprehensive medical, dental, and vision coverage, including 100% outpatient in-network mental health services.
  • Fertility coverage for eligible medical plan participants.
  • Wellbeing reimbursements for fitness, spa, meals, travel, and more (up to $720/year).
  • Student Loan Repayment Assistance and Tuition Reimbursement.
  • 401(k) with 100% immediate vesting on the first 5% of contributions, plus additional company contribution.
  • Flexible PTO for exempt employees; 3 weeks PTO for non-exempt employees.
  • 2 weeks paid Winter Break and 10 company holidays (including Juneteenth and Wellbeing Day).
  • Summer Fridays (between Memorial Day and Labor Day).
  • Generous paid parental leave for every type of parent.
  • See full overview of benefits on the Perks Playlist page of the career site.

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →