Senior Specialist - Identity & Access Management (PAM))

Posted 20 Days Ago
Be an Early Applicant
Bangalore, Bengaluru Urban, Karnataka, IND
In-Office
Senior level
Manufacturing
The Role
Owns engineering, administration, governance, and continuous improvement of Saviynt CPAM for enterprise privileged access management. Responsibilities include configuring workflows and policies, onboarding privileged accounts, managing credential vaulting and rotation, monitoring sessions, integrating with Saviynt IGA, automating operations, supporting audits, and improving least-privilege controls. The role collaborates with security, infrastructure, cloud, application, database, vendor, and audit teams to maintain a secure, reliable, and compliant PAM service.
Summary Generated by Built In

Job Description :

About us: 

With over 200 brands sold in nearly 180 countries, Diageo is home to some of the world’s most iconic drinks. From Johnnie Walker and Guinness to Tanqueray, Smirnoff and Don Julio, we craft brands chosen for life’s moments — from everyday connections to landmark celebrations.  

Bring your talent, curiosity and ambition, and strive for your personal best alongside people who challenge, support and learn from each other. Together, as one outstanding team, we keep learning, improving and raising the bar for our brands, our business and each other.  

Join us and play your part in making life’s moments mean a little more 

  

About the Function: 

Digital & Technology (D&T) is transforming how Diageo works, from how we source ingredients to how we connect with customers and consumers around the world. 

This is where data, technology and creativity come together to solve real business challenges and unlock new opportunities. Whether it’s building platforms, using data to drive decisions or shaping digital experiences, the work here has tangible impact across every part of our business. 

You’ll be part of a team that’s constantly learning, experimenting and pushing boundaries, with the freedom to explore new ideas and the support to turn them into reality. 

About the role  

The IAM Senior Specialist is responsible for engineering, administration, governance, and continuous improvement of the Saviynt CPAM privileged access management platform. The role owns CPAM configuration, privileged account onboarding, credential vaulting, session monitoring, credential rotation, request and approval workflows, and operational control effectiveness across server, cloud, database, application, and high-risk identity environments.

The role is CPAM-first and requires a strong Identity & Access Management and cyber security mindset. Knowledge of Microsoft Entra Privileged Identity Management (PIM), Azure RBAC, Conditional Access, MFA, Identity Protection, and wider Microsoft Entra security controls is advantageous, but the primary accountability is Saviynt CPAM and privileged access governance.

Context and Scope
Within Digital & Technology, the Identity & Access Management function secures access to business-critical systems, directories, privileged accounts, administrative roles, service accounts, and digital identities across the enterprise. The organisation already uses Saviynt IGA capabilities for identity lifecycle management of privileged access, and this role will strengthen the CPAM layer that controls, monitors, governs, and evidences privileged access activity.

The role partners with security, infrastructure, cloud, database, application, HR, audit, managed service providers, and vendor teams to design, implement, support, and improve privileged access services that are secure, scalable, resilient, and audit ready.

Key Accountabilities
1. Saviynt CPAM Product Engineering and Administration
·        Manage day-to-day administration, configuration, support, and optimisation of Saviynt CPAM as the enterprise privileged access management solution.

·        Configure and maintain CPAM request workflows, approval workflows, privileged roles, access policies, technical rules, email templates, entitlement structures, and operational jobs.

·        Configure and support core PAM capabilities including credential vaulting, password checkout/check-in, credential rotation, session monitoring, session recording, and privileged access policy enforcement.

·        Support onboarding and maintenance of privileged accounts across Windows/Linux servers, databases, cloud platforms, applications, service accounts, emergency accounts, and other high-risk access scenarios.

·        Support upgrades, patching, release validation, defect resolution, performance tuning, and product enhancement activities to maintain CPAM reliability and security.

2. Privileged Access Lifecycle and Saviynt IGA Integration
·        Integrate Saviynt CPAM with Saviynt IGA capabilities to enable end-to-end privileged access lifecycle management from request, approval, provisioning, monitoring, certification, and revocation.

·        Design and maintain privileged access models aligned to least privilege, Zero Trust, segregation of duties, ownership, business justification, and audit requirements.

·        Configure Just-In-Time (JIT), time-bound, emergency, and eligible vs active access models to reduce standing privileges and improve control maturity.

·        Define access request patterns, approval chains, privileged role structures, entitlement ownership, recertification requirements, and policy attestation processes.

·        Support joiner, mover, leaver, and role-change scenarios for privileged access in coordination with Saviynt IGA lifecycle processes.

3. PAM Security Controls, Risk and Compliance
·        Implement and enforce privileged access controls for administrative, shared, local administrator, service, emergency, and high-risk accounts.

·        Drive control improvements across credential rotation, session visibility, break-glass access, orphaned privileged accounts, dormant privileged access, and privileged access exceptions.

·        Produce operational and compliance evidence, dashboards, risk insights, and audit artefacts for internal audit, external audit, cyber assurance, and security governance activities.

·        Support access reviews, entitlement recertification, privileged account attestation, and remediation tracking for privileged access domains.

·        Apply cyber security principles to identify privileged access risks, strengthen access governance, and reduce exposure from excessive or persistent privileges.

4. CPAM Onboarding, Integration and Automation
·        Lead or support onboarding of servers, databases, cloud resources, applications, privileged accounts, and non-human identities into Saviynt CPAM.

·        Work with infrastructure, cloud, database, and application teams to define onboarding standards, access models, connectors, policies, session controls, and credential rotation requirements.

·        Support CPAM integrations using REST APIs, connectors, JSON, PowerShell, SQL/KQL, Microsoft Graph API where relevant, and other automation techniques.

·        Identify automation opportunities to reduce manual provisioning effort, improve request turnaround times, strengthen evidence collection, and increase operational consistency.

·        Collaborate with Saviynt and internal engineering teams to assess product gaps, prioritise enhancements, test fixes, and improve the end-to-end PAM service experience.

5. Operational Support and Stakeholder Management
·        Act as the Senior Specialist for Saviynt CPAM-related incidents, service requests, enhancements, troubleshooting, product guidance, and operational governance.

·        Provide technical support for complex CPAM issues across workflow, connector, account onboarding, session management, credential rotation, and access policy areas.

·        Work effectively with global stakeholders across security, infrastructure, cloud, application teams, vendors, managed service partners, and audit teams.

·        Maintain high-quality design documentation, operational runbooks, support procedures, standards, knowledge articles, and evidence packs.

    

Experience/skills required:  

  

·        8+ years of experience in Identity & Access Management, cyber security, privileged access management, infrastructure security, or related enterprise security operations.

·        Deep hands-on expertise in Saviynt CPAM configuration, administration, access workflows, privileged account onboarding, access policies, credential vaulting, session monitoring/recording, credential rotation, reporting, and operational troubleshooting.

·        Strong understanding of PAM concepts including least privilege, JIT access, break-glass access, password checkout/check-in, privileged session management, account discovery, local administrator controls, service account governance, and recertification.

·        Experience integrating CPAM with Saviynt IGA for privileged access lifecycle management, access requests, approvals, certifications, entitlement ownership, and policy controls.

·        Good working knowledge of Active Directory, Windows and Linux server administration concepts, cloud platforms, databases, privileged account types, service accounts, and common administrative access patterns.

·        Hands-on experience with APIs, connectors, JSON, PowerShell, SQL/KQL, Microsoft Graph API where relevant, and automation approaches used in IAM/PAM operations.

·        Strong understanding of Zero Trust, least privilege, segregation of duties, RBAC, identity lifecycle management, audit evidence, and control monitoring.

·        Advantageous: knowledge of Microsoft Entra ID security capabilities including Entra PIM, Azure RBAC, Conditional Access, MFA, Identity Protection, Access Reviews, app registrations, enterprise applications, and privileged cloud role governance.

·        Bachelor’s degree in computer science, Information Security, Engineering, or a related technical discipline; equivalent practical experience may be considered.

·        Proven experience in IAM, PAM, or cyber security engineering with increasing responsibility in a global enterprise environment.

·        Saviynt CPAM and/or Saviynt IGA product experience is strongly preferred. Saviynt product certifications are advantageous.

·        Relevant certifications are advantageous IAM/PAM/security certifications.

Leadership and Personal Attributes

·        Strong identity security and cyber risk mindset, with the ability to challenge access models and identify control gaps in privileged access processes.

·        Strong communication and articulation skills, with the ability to explain PAM risks, controls, and technical concepts to both technical and non-technical stakeholders.

·        Highly collaborative and comfortable working across global teams, cultures, time zones, vendors, and managed service partners.

·        Strong analytical and problem-solving skills, with the ability to translate business and security requirements into secure, scalable CPAM solutions.

·        Self-driven, organised, delivery-focused, and disciplined in documentation, operational governance, audit evidence, and continuous improvement.

Measures of Success

·        Saviynt CPAM service remains stable, secure, supportable, and fit for purpose.

·        Privileged access is governed through robust lifecycle controls, least privilege, strong auditability, timely certifications, and clear ownership.

·        Privileged accounts, server access, database access, cloud access, and emergency access are onboarded into CPAM using consistent standards and documented controls.

·        Standing privileged access is reduced through JIT, time-bound, eligible, and policy-based access models, and stakeholders view CPAM services as responsive, controlled, dependable, and aligned to cyber security priorities.

Working with Us  

Flexibility is key to our success. Talk to us about what flexibility means to you so that you’re supported to manage your wellbeing and balance your priorities from day one.  

We recognise and value performance, offering our people a highly competitive Rewards and Benefits package including:   

  

Our purpose is crafting iconic drinks chosen for life’s moments. And it’s our people, with their different experiences, perspectives and talents, who make that possible.  

We value diversity in its broadest sense and want everyone to feel they can belong, contribute and strive for their personal best. You’ll work alongside people with different backgrounds, experiences and perspectives — challenging, supporting and learning from one another as one outstanding team.  

Together, we’re constantly learning and improving, combining the strength of our people, capabilities and iconic brands to raise the bar, grow and win. Wherever you join us, you’ll have the opportunity to contribute, make an impact and play your part in making life’s moments mean a little more.  

Ready to bring your best? This could be your opportunity.  

If you require a reasonable adjustment, please ensure that you capture this information when you submit your application.  

   

Recruitment Scam Warning 

Protecting candidates is very important to us. All communications regarding your application will come from an email address ending in @diageo.com. In our recruitment process, we'll never ask for money.  

Worker Type :

Regular

Primary Location:

Bangalore Karle Town SEZ

Additional Locations :

Job Posting Start Date :

2026-09-08

Skills Required

  • 8+ years of experience in identity and access management, cybersecurity, privileged access management, infrastructure security, or related enterprise security operations.
  • Deep hands-on expertise configuring and administering Saviynt CPAM, including workflows, privileged account onboarding, access policies, credential vaulting, session monitoring, credential rotation, reporting, and troubleshooting.
  • Strong understanding of PAM concepts, including least privilege, just-in-time access, break-glass access, password checkout/check-in, privileged session management, account discovery, local administrator controls, service account governance, and recertification.
  • Experience integrating Saviynt CPAM with Saviynt IGA for privileged access lifecycle management, requests, approvals, certifications, entitlement ownership, and policy controls.
  • Working knowledge of Active Directory, Windows and Linux administration concepts, cloud platforms, databases, privileged account types, service accounts, and administrative access patterns.
  • Hands-on experience with APIs, connectors, JSON, PowerShell, SQL or KQL, Microsoft Graph API, and IAM/PAM automation.
  • Understanding of Zero Trust, least privilege, segregation of duties, RBAC, identity lifecycle management, audit evidence, and control monitoring.
  • Bachelor's degree in computer science, information security, engineering, or a related technical discipline; equivalent practical experience may be considered.
  • Proven IAM, PAM, or cybersecurity engineering experience with increasing responsibility in a global enterprise environment.
  • Saviynt CPAM and/or Saviynt IGA product experience.
  • Saviynt product certifications.
  • Relevant IAM, PAM, or cybersecurity certifications.
  • Knowledge of Microsoft Entra ID security capabilities, including Entra PIM, Azure RBAC, Conditional Access, MFA, Identity Protection, Access Reviews, app registrations, enterprise applications, and privileged cloud role governance.

Diageo Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Diageo and has not been reviewed or approved by Diageo.

  • Fair & Transparent Compensation — Pay is considered competitive and often described as top-tier, particularly in manufacturing and salaried roles, with many indicating they feel fairly compensated. Compensation is frequently cited as a strong reason to join and stay despite pressures in some parts of the business.
  • Parental & Family Support — Parental leave is widely recognized as a flagship offering, equalized across parents and inclusive of adoption and surrogacy, with benefits and bonuses maintained during leave. This family-friendly approach is highlighted as industry-leading and a standout element of the package.
  • Retirement Support — Pension schemes are described as generous, with notable employer contributions enhancing long‑term financial security. In key markets such as the UK and U.S., offerings like pensions and 401(k) plans are presented as core components of total rewards.

Diageo Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
32,334 Employees

What We Do

Diageo's official LinkedIn account. We're a global leader in premium drinks, across spirits and beer, a business built on the principles and foundations laid by the giants of the industry. With over 200 brands sold in 180 countries, our portfolio has remarkable breadth. From centuries-old names to exciting new entrants, and global giants to local legends, we're building the very best brands out there, and with over 30,000 talented people based in over 135 countries, we're a truly global company. With such diversity, we're able to truly represent our broad consumer base and think differently about the future. To maintain our position as leaders in the alcoholic beverage market, we always invest in the future and are mindful of the impact we have. Because just like the legends of our past, we're here to raise the bar – for people as well as the planet

Similar Jobs

CSC Logo CSC

Fund Accounting - Mumbai

Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Hybrid
2 Locations
8500 Employees

Hewlett Packard Enterprise Logo Hewlett Packard Enterprise

L&D Delivery Specialist

Artificial Intelligence • Cloud • Information Technology • Consulting
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
85422 Employees

Hewlett Packard Enterprise Logo Hewlett Packard Enterprise

Senior Principal SW Engineer

Artificial Intelligence • Cloud • Information Technology • Consulting
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
85422 Employees

Hewlett Packard Enterprise Logo Hewlett Packard Enterprise

Platform Engineer

Artificial Intelligence • Cloud • Information Technology • Consulting
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
85422 Employees

Similar Companies Hiring

Fortune Brands Innovations Thumbnail
Manufacturing
Deerfield, IL
10000 Employees
Rosendin Thumbnail
Other • Manufacturing
San Jose, CA
6219 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account