About
I’m Paolo Giannone, a cybersecurity professional based in Milan, specialised in identity and access management.
My work centres on identity governance, privileged access and segregation of duties — the controls that decide who can do what inside an organisation, and that prove it to an auditor. I have worked with platforms such as SailPoint IdentityIQ, One Identity Manager and CyberArk, and with the regulatory frameworks that shape this work in regulated sectors: FINMA, FADP/nLPD, DORA and NIS2.
I’m also a developer and I build web products.
Focus areas
Identity governance (IAM/IGA). Joiner–mover–leaver lifecycle, role modelling and access certification on enterprise IGA platforms such as SailPoint IdentityIQ and One Identity Manager.
Privileged access (PAM). Vaulting, session control and just-in-time elevation for privileged accounts and secrets, built around CyberArk.
Segregation of duties & access reviews. SoD risk analysis and remediation, plus periodic access reviews that hold up under audit — in environments shaped by FINMA, FADP/nLPD, DORA and NIS2.
Platforms and frameworks
Platforms: SailPoint IdentityIQ · One Identity Manager · CyberArk
Frameworks: FINMA · FADP/nLPD · DORA · NIS2