We are seeking a skilled Entra ID Identity and Access Management Specialist to strengthen our global IAM program with a focus on automated user lifecycle management. This role will design, implement, and optimize joiners, movers, and leavers (JML) processes, access certifications, and segregation of duties (SoD) controls, using Oracle HCM as the authoritative source of HR records. The position will play a key role in enforcing governance, streamlining provisioning/de-provisioning, and ensuring compliance with global regulatory requirements.
Key Responsibilities
Identity Lifecycle Management (JML):
- Design and implement automated provisioning and de-provisioning workflows in Entra ID, driven by Oracle HCM data.
- Ensure timely and accurate access provisioning for joiners, role adjustments for movers, and complete access removal for leavers.
Access Governance & Compliance:
- Implement access certification campaigns to regularly review and validate user entitlements.
- Enforce segregation of duties (SoD) policies and mitigate conflicts of interest through automated controls.
- Maintain alignment with global compliance standards (e.g., ISO 27001, SOC 2, HIPAA).
Integration & Automation:
- Integrate Oracle HCM with Entra ID and other downstream systems for real-time identity synchronization.
- Use automation tools (e.g., PowerShell, Graph API, Logic Apps) to optimize IAM workflows.
- Collaborate with HR, IT, and business stakeholders to ensure seamless end-to-end user lifecycle management.
Access Control & Security:
- Define and maintain role-based access control (RBAC), conditional access, and least privilege principles.
- Partners with cross functional teams to strengthen identity protections, MFA enforcement, and audit readiness.
Monitoring & Incident Response:
- Track and resolve identity-related anomalies, failed provisioning events, and policy violations.
- Support security incident investigations tied to unauthorized or inappropriate access.
Required Qualifications
- 5+ years of experience in Identity and Access Management (IAM) with strong expertise in Microsoft Entra ID / Azure AD.
- Proven experience with JML lifecycle management, access certifications, and SoD controls.
- Hands-on experience integrating HR systems (preferably Oracle HCM) as the source of truth for IAM processes.
- Strong knowledge of RBAC, SSO, MFA, Conditional Access, and federation protocols (SAML, OIDC, OAuth2).
- Proficiency in automation and scripting (PowerShell, Graph API, or equivalent).
- Understanding of compliance requirements (SOX, GDPR, HIPAA, ISO 27001).
- Strong communication skills with the ability to collaborate across HR, Security, and IT functions.
Preferred Attributes
Microsoft certifications such as SC-300 (Identity and Access Administrator Associate) or SC-100 (Cybersecurity Architect Expert).
Experience with Identity Governance and Administration (IGA) tools like Saviynt.
Knowledge of integrating IAM with Privileged Access Management (CyberArk) or SIEM platforms (CrowdStrike).
Grant Thornton INDUS is the global capability center for Grant Thornton US, the U.S. member firm of Grant Thornton International Ltd., a leading global network of independent audit, tax, and advisory firms. Founded in Chicago in 1924, Grant Thornton US is one of the leading accounting and advisory firms in the U.S., bringing together $4B+ in revenue, 56 U.S. offices, and a multi-national platform spanning 20 countries with 25,000 people. It combines deep expertise, advanced technology, and a collaborative mindset to help clients solve complex challenges and grow with confidence. Since 2012, Grant Thornton INDUS has brought together 3,300+ professionals across Tax, Audit, Advisory, Client Services, Innovation, and Enabling Functions to deliver high-impact solutions for Grant Thornton US and its global network. Recognized as a Great Place To Work® for three consecutive years and among India’s Top 15 Best Workplaces™ in Professional Services 2026, INDUS offers a high-performance culture where people are trusted, supported, and empowered to grow.