Identity & Access Management
Identity & Access Management Specialist
Six years spent at the gates of banks, hospitals, airlines, and assembly lines. Deciding who gets in, what they touch, and how to prove every bit of it to an auditor.
Identity work happens in two rooms. In one, you wire OIM connectors, untangle a reconciliation job that has quietly drifted for weeks, and write the script that finally closes the orphan account nobody wanted to own. In the other, you sit across from an auditor and explain, calmly and without flinching, why a privileged role was held for sixty days longer than it should have been.
Most people are comfortable in one room. The technical folks go quiet in front of the auditor; the governance folks can't read the logs. The whole job, the part that actually matters, is being fluent in both.
For six years I have moved between those rooms. Today I am the single point of contact for access management at Wio Bank, a fully digital bank in Abu Dhabi: around 1,400 identities, 90+ applications, the entire joiner-mover-leaver lifecycle, with RBAC and segregation of duties held together by defined workflows and AI-assisted routing that took roughly a quarter of the routine work off my plate.
Before Wio, four years at PwC with a major credit-card issuer taught me the discipline: ISO 27001 cycles, GDPR walkthroughs, monthly reconciliations built on scripts I could reuse, and a clean record through two data-centre cutovers. Now I am formalizing all of it with the Microsoft SC-300 certification.
Four roles, one thread: making access provable. The most recent one is where I live day to day.
Wio is a fully digital bank, which means there is no branch, no paper, and no margin for a wrong grant: access is the perimeter. I own that perimeter end to end. When a new hire starts, when a contractor rolls off, when an app owner asks why someone can approve their own transactions, the question lands on me. Below is what that looks like in practice.
Four years on the IAM operations engagement for one of India's largest credit-card issuers. This is the scale where good habits get formed.
The tools I reach for without thinking, grouped by the job they do.
A cyber-security degree, a foundation in the law behind the controls, and a certification to make the practice official.
Formalizing six years of Entra ID and identity-governance practice.
University of Petroleum and Energy Studies, Dehradun
Asian School of Cyber Laws, Mumbai · legal framework for digital evidence, privacy, and infosec
Identity governance, zero-trust architecture, AI in access management
For new engagements, advisory work, or anything access-shaped. My inbox is open.