11 Sep
|
Diageo
|
Bengaluru
Job Summary
The IAM Senior Specialist is responsible for engineering, administration, governance, and continuous improvement of the Saviynt CPAM privileged access management platform. The role owns CPAM configuration, privileged account onboarding, credential vaulting, session monitoring, credential rotation, request and approval workflows, and operational control effectiveness across server, cloud, database, application, and high-risk identity environments. The role is CPAM-first and requires a solid Identity & Access Management and cyber security mindset. Knowledge of Microsoft Entra Privileged Identity Management (PIM), Azure RBAC, Conditional Access, MFA, Identity Protection, and wider Microsoft Entra security controls is advantageous, but the primary accountability is Saviynt CPAM and privileged access governance.
Context and Scope Within Digital & Technology, the Identity & Access Management function secures access to business-critical systems, directories, privileged accounts, administrative roles, service accounts, and digital identities across the enterprise. The organisation already uses Saviynt IGA capabilities for identity lifecycle management of privileged access, and this role will strengthen the CPAM layer that controls, monitors, governs, and evidences privileged access activity.
The role partners with security, infrastructure, cloud, database, application, HR, audit, managed service providers, and vendor teams to design, implement, support, and improve privileged access services that are secure, scalable, resilient, and audit ready.
Key Accountabilities
- Saviynt CPAM Product Engineering and Administration: Manage day-to-day administration, configuration, support, and optimisation of Saviynt CPAM as the enterprise privileged access management solution.
- Configure and maintain CPAM request workflows, approval workflows, privileged roles, access policies, technical rules, email templates,
entitlement structures, and operational jobs.
- Configure and support core PAM capabilities including credential vaulting, password checkout/check-in, credential rotation, session monitoring, session recording, and privileged access policy enforcement.
- Support onboarding and maintenance of privileged accounts across Windows/Linux servers, databases, cloud platforms, applications, service accounts, emergency accounts, and other high-risk access scenarios.
- Support upgrades, patching, release validation, defect resolution, performance tuning, and product enhancement activities to maintain CPAM reliability and security.
- Privileged Access Lifecycle and Saviynt IGA Integration: Integrate Saviynt CPAM with Saviynt IGA capabilities to enable end-to-end privileged access lifecycle management from request, approval, provisioning, monitoring, certification, and revocation.
- Design and maintain privileged access models aligned to least privilege, Zero Trust, segregation of duties, ownership, business justification, and audit requirements.
- Configure Just-In-Time (JIT), time-bound, emergency, and eligible vs active access models to reduce standing privileges and improve control maturity.
- Define access request patterns, approval chains, privileged role structures, entitlement ownership, recertification requirements, and policy attestation processes.
- Support joiner, mover, leaver, and role-change scenarios for privileged access in coordination with Saviynt IGA lifecycle processes.
- PAM Security Controls, Risk and Compliance:
Implement and enforce privileged access controls for administrative, shared, local administrator, service, emergency, and high-risk accounts.
- Drive control improvements across credential rotation, session visibility, break-glass access, orphaned privileged accounts, dormant privileged access, and privileged access exceptions.
- Produce operational and compliance evidence, dashboards, risk insights, and audit artefacts for internal audit, external audit, cyber assurance, and security governance activities.
- Support access reviews, entitlement recertification, privileged account attestation, and remediation tracking for privileged access domains.
- Apply cyber security principles to identify privileged access risks, strengthen access governance, and reduce exposure from excessive or persistent privileges.
- CPAM Onboarding, Integration and Automation: Lead or support onboarding of servers, databases, cloud resources, applications, privileged accounts, and non-human identities into Saviynt CPAM.
- Work with infrastructure, cloud, database, and application teams to define onboarding standards, access models, connectors, policies, session controls, and credential rotation requirements.
- Support CPAM integrations using REST APIs, connectors, JSON, PowerShell, SQL/KQL, Microsoft Graph API where relevant, and other automation techniques.
- Identify automation opportunities to reduce manual provisioning effort, improve request turnaround times, strengthen evidence collection, and increase operational consistency.
- Collaborate with Saviynt and internal engineering.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Sr Specialist - Identity & Access Management (PAM)) (Bengaluru)
🏢 Diageo
📍 Bengaluru