Job Title -AVP IAM Solutions Architect
Organizational Context
With over 200 brands sold in more than 180 countries, we're the world's leading premium drinks company. Every day, over 27,000 dedicated people come together at Diageo to create the magic behind our much-loved brands. From iconic names to innovative newcomers - the brands we're building are rooted in culture and local communities. Our ambition is to be one of the best performing, most trusted and most respected consumer products companies in the world. Diageo Digital & Technology (D&T) is a multi-functional global shared services function built to drive effectiveness and efficiency across our core operations and achieve our efficiency goals. We fuel growth for our markets through a focus on new capabilities, consistent, common, and available analytics, and data, and equipping our markets and functions through integrated solutions.
Want more jobs like this?
Get jobs in Bangalore, India delivered to your inbox every week.
About the Function:
Our Digital and Technology (D&T) team are innovators, delivering ground-breaking solutions that will help shape the future of our iconic brands. Technology touches every part of our business, from the sourcing of sustainable ingredients to marketing and development of our online platforms. We utilise data insights to build competitive advantage, supporting our people to deliver value faster.
Our D&T team includes some of the most dedicated digital professionals in the industry. Every day, we come together to push boundaries and innovate, shaping the digital solutions of tomorrow. Whatever your passion, we'll help you become the best you can be, creating career-defining work and delivering breakthrough thinking.
Role Description:
We are seeking a highly experienced and skilled Identity and Access Management (IAM) Solution Architect to lead the design and implementation of IAM solutions across the enterprise. The ideal candidate will have deep expertise in Saviynt, Microsoft Entra, CyberArk PAM, CIAM, B2B/B2C identity management, OAuth, and Active Directory.
The "IAM Solution Architect" role will be responsible for securing access to applications, systems, and services for both internal and external users, ensuring compliance, security, and a seamless user experience. This role will focus on shaping the future of IAM technology architecture and embedding new and existing products, processes, and standards for all aspects of Identity Management across Diageo. You'll play a pivotal role in shaping the future of Identity Management across Diageo, including third-party partners, customers, and consumers.
There is a significant annual budget investment to enable delivery of the IAM Roadmap of D&T which supports the delivery of the Diageo Ambition, including multiple aspects of Zero Trust philosophy.
Key Responsibilities:
- Solution Design & Architecture:
- Collaborate with partners to understand business needs and ensure to Design and implement IAM solutions, ensuring alignment with business objectives, security policies, and regulatory requirements.
- Evaluate existing technologies and recommend appropriate IAM technologies (e.g., Saviynt, CyberArk, MS Entra) based on organizational needs and budget constraints.
- Develop comprehensive IAM strategies and standard methodologies for IAM platforms (Saviynt, MS Entra, CyberArk) for user authentication, role-based access control (RBAC), privileged access management (PAM), and customer identity management (CIAM).
- Create and lead identity and access management roadmaps that align with business objectives and technology needs.
- Implementation and Integration with Optimization:
- Lead the technical implementation of IAM solutions, including integration with existing systems, applications, and directories demonstrating Saviynt, MS Entra, CyberArk PAM, and CIAM platforms.
- Architect and configure Saviynt for identity governance and administration (IGA), automating the user lifecycle, role-based access policies, and compliance reporting.
- Maintain and enhance seamless OAuth and SSO solutions for secure access across cloud, on-premises, and hybrid environments.
- Implement and handle CyberArk PAM solutions for privileged access management, ensuring robust protection of critical systems and sensitive data.
- Implement CIAM solutions that deliver secure and frictionless authentication experiences for customers and partners (B2C and B2B), including registration, login, and profile management.
- Review, define & implement access control policies, user lifecycle management processes & regular access reviews to maintain data security under access governance.
- Continuously optimize IAM solution performance and user experience, demonstrating automation and monitoring tools to reduce manual intervention.
- Automate IAM processes, including user provisioning, deprovisioning, role assignments, and access certifications to improve efficiency and reduce manual overhead.
- Security, Compliance & Best Practices:
- Ensure IAM solutions are designed and implemented to meet security, privacy, and compliance standards, including GDPR, SOX, HIPAA, and other regulatory requirements.
- Implement robust multi-factor authentication (MFA), adaptive authentication, and SSO capabilities across both B2B and B2C user environments.
- Design and implement fine-grained access control policies, ensuring the principle of least privilege (PoLP) and separation of duties (SoD).
- Conduct IAM risk assessments, audits, and vulnerability assessments, and provide actionable recommendations for improving security posture.
- B2B/B2C Identity Management:
- Architect and implement scalable B2B and B2C identity solutions, providing secure access for partners, contractors, and customers.
- Enable seamless federation of identities with external systems, applications, and partners using OAuth, SAML, and OpenID Connect.
- Ensure seamless integration of customer identity management (CIAM) for external user registration, consent, authentication, and self-service options.
- Continuous Improvement:
- Stay updated with the latest IAM technologies, industry trends, and security threats to ensure the organization's IAM strategies remain competitive and effective.
- Continuously evaluate IAM systems for opportunities to enhance security, improve user experience, and streamline access management workflows.
- Collaboration & Leadership:
- Provide technical leadership and mentorship to multi-functional teams, including IT security, infrastructure, and application development teams.
- Collaborate with senior leadership to define IAM strategies, roadmaps, and technology investments.
- Lead and handle IAM projects, working closely with partners to gather requirements, define solutions, and ensure successful project delivery.
- Documentation & Reporting:
- Create detailed user documentation, architecture diagrams, and operational procedures for IAM solutions.
- Provide regular reports on the performance and security of IAM systems, including key performance indicators (KPIs), audit results, and incident management.
- Document and communicate IAM policies, standards, and governance frameworks to ensure alignment across the organization.
- Monitor and report on the health, performance, and security of IAM solutions, highlighting areas of improvement and potential risks.
Qualifications and Experience Required
- Bachelor's or Master's degree in computer science, IM&S or similar field.
- 12+ years of experience in Identity and Access Management (IAM), with at least 4 years in a solution architecture or technical leadership role.
- Extensive knowledge of best-of-breed technology platforms to deliver IdAM capabilities - including Saviynt IGA and AAG, CyberArk (PAM), MS Entra/Azure AD, Azure PIM, Customer Identity and Access Management (CIAM) capabilities addressing needs of different persona of identities.
- Hands-on experience with integrating IAM solutions into enterprise IT infrastructure (applications, databases, cloud services, etc.).
- In-depth understanding of IAM protocols (SAML, OAuth, OpenID Connect, LDAP, and APIs.), MFA, SSO, RBAC, and identity federation.
- Solid understanding of security standard methodologies and regulatory requirements (e.g., GDPR, HIPAA, SOC 2, SOX).
- Proven experience managing and optimizing enterprise-level IAM solutions and platforms.
Leadership/ Personal Attributes:
- Outstanding social skills - the ability to translate sophisticated IT matters to those without an IT background and to articulate solutions, including resource-, techno-functional requirements, phasing, and dependencies.
- Strong leadership, collaboration, and communication skills.
- Ability to simplify complex IAM concepts for technical and non-technical partners.
- Analytical and problem-solving approach, with a focus on security, efficiency, and continuous improvement.
- Self-motivated with the ability to handle multiple projects and meet deadlines in a fast-paced environment.
Flexible Working Statement:
Flexibility is key to our success. From part-time and compressed hours to different locations, our people work flexibly in ways to suit them. Talk to us about what flexibility means to you so that you're supported from day one.
Diversity statement:
Our purpose is to celebrate life, every day, everywhere. And creating an inclusive culture, where everyone feels valued and that they can belong, is a crucial part of this.
We embrace diversity in the broadest possible sense. This means that you'll be welcomed and celebrated for who you are just by being you. You'll be part of and help build and champion an inclusive culture that celebrates people of different gender, ethnicity, ability, age, sexual orientation, social class, educational backgrounds, experiences, approaches, and more.
Our ambition is to create the best performing, most trusted and respected consumer products companies in the world. Join us and help transform our business as we take our brands to the next level and build new ones as part of shaping the next generation of celebrations for consumers around the world.
Feel inspired? Then this may be the opportunity for you.
If you require a reasonable adjustment, please ensure that you capture this information when you submit your application.