IAM Engineer - SSO - London, N1C 4AG
IAM Engineer - SSO - London, N1C 4AG, United Kingdom
Job Summary
We are currently seeking an Identity & Access Management Engineer with specialization in Access Management to join UMGs global Tech Security & Identity organization. Reporting to the Manager, Access ManagementVP, Tech Security & Identity, this is a hands-on engineering role responsible for designing, implementing, and operating enterprise access management capabilities across a global, hybrid environment including workforce, partner, customer, and consumer experiences.
This engineer will play a critical role in securing authentication and authorization for workforce and application access, delivering scalable solutions across Single Sign-On (SSO), federation, and multi-factor authentication (MFA). The role emphasizes strong technical execution, platform reliability, and automation, working closely with application, infrastructure, and security teams to enable secure access while maintaining a strong user experience. The ideal candidate brings deep experience with modern access management platforms and protocols, and the ability to operate access services at enterprise scale.
Job Functions
Design, engineer, deploy, and operate Access Management solutions across the enterprise.
Implement and support Single Sign-On (SSO) and federation services using modern identity protocols.
Engineer and maintain authentication and authorization services including MFA, adaptive access, and conditional access policies.
Integrate applications and platforms with enterprise access management systems across on-premises and cloud environments.
Partner with application owners and platform teams to onboard applications to SSO and enforce consistent authentication standards.
Design and maintain secure federation integrations using protocols such as SAML, OAuth 2.0, and OpenID Connect (OIDC).
Develop and maintain automation and tooling to support access onboarding, configuration, and lifecycle management.
Troubleshoot and resolve complex authentication, authorization, and federation issues impacting users or applications.
Ensure access management services meet availability, performance, and resiliency requirements in a global environment.
Support audit, compliance, and security review activities related to access controls and authentication mechanisms.
Maintain technical documentation, standards, and runbooks for access management platforms and integrations.
Continuously improve access security and user experience through platform enhancements, automation, and adoption of modern authentication patterns.
Job Requirements
Essential Qualifications
5+ years of hands-on experience in Identity & Access Management or Security Engineering roles, with strong focus on Access Management.
Demonstrated experience implementing and operating enterprise access management platforms (e.g., Ping Identity, Okta, Microsoft Entra ID, or equivalent).
Strong understanding of authentication and authorization concepts, including SSO, federation, MFA, and adaptive access.
Hands-on experience with identity protocols and standards such as SAML, OAuth 2.0, OpenID Connect (OIDC), and LDAP.
Experience integrating identity platforms with cloud applications, SaaS platforms, and custom-built applications.
Proficiency in scripting and automation using tools such as PowerShell or Python.
Experience operating access services in hybrid and cloud environments (Azure and/or AWS).
Ability to independently own complex technical implementations while collaborating across a global organization.
Strong troubleshooting, documentation, and communication skills.
Desirable Qualifications
Bachelors degree in Computer Science, Information Security, Engineering, or a related technical discipline.
Experience with passwordless authentication technologies and modern identity standards.
Familiarity with Zero Trust and conditional access models.
Experience supporting authentication services in high-availability, 24x7 enterprise environments.
Experience with identity verification solutions and technolgies.
Professional certifications such as Ping Identity Certified Professional, Microsoft Certified: Identity and Access Administrator, Security+, or CISSP.
Experience operating IAM platforms within a large, global, or highly regulated enterprise environment.
About UMG UK
We are Universal Music Group UK the UKs leading music-based entertainment company. We exist to shape culture through the power of artistry. We help UK artists produce, distribute and promote the most critically acclaimed and commercially successful music to inspire and entertain fans at home and around the world.
Bonus Tracks: Your Benefits
Group Personal Pension Scheme (between 3% and 9%)
Private Medical Insurance
25 paid days of annual leave
Interest Free Season Ticket Loan
Holiday Purchase scheme
Dental and Travel Insurance options
Cycle to Work Scheme
Salary Sacrifice Cars
Subsidised Gym Membership
Employee Discounts (Reward Gateway)
Recommended Jobs
Caretaker - Secondary School - Chelsea
Location: Chelsea, West London Start Date: January 2026 Salary: Support staff pay scale A well-maintained secondary school in Chelsea is seeking a Caretaker to support the upkeep, safety, …
ICT Support Analyst - Hardware & Network - Redbridge
ICT Support Analyst – Provide Desktop & Network Support and Hardware Maintenance – Redbridge A technology-focused secondary school in Redbridge is seeking a skilled and proactive ICT Support An…
Computing ECT - Girls’ School, Wandsworth
Computing ECT – Girls’ School, Wandsworth Location: Wandsworth Contract: Full-time, Permanent Salary: Paid to Scale Start: January 2026 An Outstanding girls’ secondary school in Wa…
Facilities Assistant - Well-Resourced Secondary School -...
Facilities Assistant – Well-Resourced Secondary School – Hackney Start Date: As soon as possible Contract: Full-time, Permanent Salary: Paid to scale We are seeking a reliable and proa…
Director, Cybersecurity, Engineering, OT, TC, UKI
At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and…
Unqualified Senior Broker LBS-011
Job Category : Social & Health Care Non-Qualified Location : Southwark Council Hours Per Week : 36.00 Start Date : Immediate Start Start Time :09:00 End Time : 17:00 Salary: £25.90 P…
Corporation Tax Manager
Job Description Leading travel industry | Corporation tax manager | Hybrid contract role. Your new company This client is a leading player in the travel industry with the corporate headquarter…
Part-time Nanny-Housekeeper in Battersea, London, Job ID J1FF3E
This family in London needs a part-time Nanny-Housekeeper to care for their school-aged child and maintain the property. All general Nanny Housekeeping duties are required in this role. This role is …
Drama Teacher | Enfield Independent School
We are seeking a high-calibre Drama Teacher for an Independent school in Enfield. This full-time, permanent position starts ASAP and is an excellent opportunity for a drama specialist to join a vibra…
Assistant Store Manager
Company Description FLANNELS is the luxury fashion destination for men and women, home to an edit of over 200 brands from established international designers to contemporary labels. With an in…