As a key member of the UMG Operations Center, the T2 Identity Operations Engineer is responsible for ensuring our Identity Management and Messaging environments, including Active Directory functions at peak efficiency. The position will be a team player working to expand the integration of our identity management solutions with our enterprise applications, support day-to-day administration, reporting, troubleshooting, and operations of our Identity Management environment. In addition to having strong technical skills, you must be comfortable in effectively communicating with business end-users, technical IT teams, business partners, network providers, and business process outsourced vendors, all while being sensitive to a wide diversity of cultural and technical backgrounds in a global business environment.
How you'll CREATE:
• Utilize best practices to ensure that solutions protect information resources against unauthorized use, inappropriate degrees of access, disclosure, damage and/or loss.
• Troubleshoots and manages the resolution of issues related identities, systems, access, accounts, authentication, authorization, entitlements, and permissions.
• Troubleshoots, supports and resolves system incidents, problems and changes, as required.
• Provides ITIL based operational support and acts as a technical resource for the Active Directory infrastructure, including incident, change, and problem management.
• Provides support of on premise and cloud-based equipment and configuration including but not limited to Domain Controllers, SaaS applications such as Azure Active Directory, O365, Duo, CyberArk, YubiKey, Microsoft Identity Management, Splunk, and Active Roles servers.
• Complete the key metric reporting and analysis for the Identity Management environment as required.
• Work to ensure audit tasks related to Identity Management are completed on time, with participation of appropriate parties.
• Participate in security incident response teams as needed
• Utilize industry best practices for appropriate standards, processes, procedures, tools, and documentation.
• Ensure the maintenance, patching, operating, and monitoring of IAM systems is in place and completed on schedule.
• Participate in on-call rotation, and as such, work outside of standard business hours will occasionally be required.
• This position will be shift-based
Bring your VIBE:
• Bachelor's Degree in Computer Science or Engineering or closely related field or comparable education and experience.
• Understanding of Microsoft Teams group/system policies, survivable branch appliances, unified messaging, and federation
• IT Certifications including MCSE Certification specialization in Identity Management, Certified Access Management Specialist (CAMS), and ITIL Foundations certifications desired
• International experience beneficial; multiple language skills a plus
• Solid technical skills in the Identity Management space, including Active Directory.
• Minimum of five years directly related experience in Identity & Access Management (IAM)
• A strong ability for troubleshooting and problem analysis is required, along with the ability to clearly communicate the results of problem analysis to business stakeholders, IT support teams, and network providers to quickly and effectively resolve operational issues.
• Experience troubleshooting, managing, and solving issues related to identities, systems, access, accounts, authentication, authorization, entitlements, and permissions
• Hands on experience of Active Directory operation and support including Active Directory Infrastructure components (FSMO roles), delegated administration, group policies, OU admin & Site replication, ADFS, Exchange operation and support including OWA, SMTP services, and routing / costing
• Technical expertise in the following:
• Component services & areas: multi-domain design, DDNS, DHCP, ActiveSync, Outlook client, Spam filtering, and anti-malware services
• Relevant management & operational tooling: NetIQ Security & Application Manager, QUEST, Splunk, Insight mgt, and Microsoft Administration tools
• Directory Services, Directory Services replication/synchronization, Kerberos, Active Directory compliance for Schema Extensions, DEA (Directory Enabled Applications), SMTP Query management, S-LDAP, AD integration security, federation services and Forest system context management for application services.
• Adept at PowerShell & VB scripting, regular expressions, policy management, etc. Additional experience in one or more scripting languages such as Perl, Python, Chef, Ansible, or JSON is a plus
• Customer service driven/focused with a proactive and positive can-do approach. Demonstrates commitment to the organization's policy framework and practices continuous improvement.
• Hands-on experience and skills with systems such as
O365 and ServiceNow are required. Experience with ServiceNow orchestration into Active Directory & O365, Zoom, Jabber, or Teams is a plus.
• Experience with security protocols such as S-LDAP, SAML, WS-Federation, SCIM, OAuth, and OIDC
• Demonstrated current work experience supporting integrated IAM solutions such as Azure Active Directory, Active Roles, Duo, MIM, and CyberArk
• Demonstrated organizational skills, attention to detail and ability to work both independently and as part of a team.
• Solid written, oral, and interpersonal communications skills
• Competitive Compensation Package including Salary, Benefits and Generous 401k Savings Plan with company matching
• Flexible Paid Time Off plus Paid Holidays, 2 week ''Winter Break'' & Wellness Fridays (year-round)
• Medical, Dental and Vision Insurance
• Student Loan Repayment Assistance & Tuition Reimbursement (after 12 months of service)
• Robust Employee Assistance Program (for you and your loved ones)
• Annual Well-Being Allowance which includes Fitness, Travel, Home Enhancements, Nutrition, and Spa Treatment Reimbursements
Universal Music Group is an Equal Opportunity Employer.
All UMG employees are currently required to be fully vaccinated against COVID-19 or provide proof of a negative PCR or Antigen test before entering any Company offices unless they have been approved for an exemption or unless prohibited by applicable law.
Disclaimer: This job description only provides an overview of job responsibilities that are subject to change.
Jobcode: Reference SBJ-r0eoom-44-201-94-72-42 in your application.