Identity & Access Management

Piyush Sharma

Identity & Access Management Specialist

Six years spent at the gates of banks, hospitals, airlines, and assembly lines. Deciding who gets in, what they touch, and how to prove every bit of it to an auditor.

Get in touch View experience
6+
Years in IAM
90+
Applications governed
40K+
Identities secured

Profile

A practitioner, not a poster.

Identity work happens in two rooms. In one, you wire OIM connectors, untangle a reconciliation job that has quietly drifted for weeks, and write the script that finally closes the orphan account nobody wanted to own. In the other, you sit across from an auditor and explain, calmly and without flinching, why a privileged role was held for sixty days longer than it should have been.

Most people are comfortable in one room. The technical folks go quiet in front of the auditor; the governance folks can't read the logs. The whole job, the part that actually matters, is being fluent in both.

Comfortable on both sides of the table: building the technical integration, and walking auditors through the controls.

For six years I have moved between those rooms. Today I am the single point of contact for access management at Wio Bank, a fully digital bank in Abu Dhabi: around 1,400 identities, 90+ applications, the entire joiner-mover-leaver lifecycle, with RBAC and segregation of duties held together by defined workflows and AI-assisted routing that took roughly a quarter of the routine work off my plate.

Before Wio, four years at PwC with a major credit-card issuer taught me the discipline: ISO 27001 cycles, GDPR walkthroughs, monthly reconciliations built on scripts I could reuse, and a clean record through two data-centre cutovers. Now I am formalizing all of it with the Microsoft SC-300 certification.


Experience

Where the work happened.

Four roles, one thread: making access provable. The most recent one is where I live day to day.

Senior Product Engineering Consultant, Security

Aug 2024 — Present
StatusNeo · Wio Bank PJSC
Access Management Specialist · Banking · Abu Dhabi, UAE

Wio is a fully digital bank, which means there is no branch, no paper, and no margin for a wrong grant: access is the perimeter. I own that perimeter end to end. When a new hire starts, when a contractor rolls off, when an app owner asks why someone can approve their own transactions, the question lands on me. Below is what that looks like in practice.

  • Single point of contact for access management across the bank: ~1,400 employees and contractors, 90+ applications, the full identity lifecycle and access governance.
  • Run quarterly and yearly access reviews for every critical application, working app owners and reviewers through their findings and closing them before audit deadlines rather than after.
  • Take newly built applications from the dev teams and onboard them into governance before go-live: role catalog, approval workflows, reviewer mappings all in place on day one, not bolted on later.
  • Wrote the bank's access matrix and role catalog from the ground up: 300+ entitlements mapped to business roles, with SoD rules authored across finance, operations, and technology.
  • Built AI-assisted workflows for access requests (approval routing, validation, role mapping), which took ~25% of the routine manual work off the queue.
  • First call when an access incident breaks, working shoulder to shoulder with InfoSec, IT, and audit.
BankingJMLRBACSoDEntra IDArcon PAMAI Workflows

Senior Consultant, Identity & Access Management

Jan 2020 — Aug 2024
PricewaterhouseCoopers · Risk Consulting
Credit Cards · Banking · IAM Operations · Gurugram, IN

Four years on the IAM operations engagement for one of India's largest credit-card issuers. This is the scale where good habits get formed.

  • Ran governance for 40,000+ users across 80+ applications on Oracle Identity Manager.
  • Led quarterly, half-yearly, and annual access certifications with 200+ application and business owners; closed orphan accounts and excessive-access findings flagged in internal audit.
  • Owned monthly reconciliation between HRMS and downstream applications, with reusable scripts that cut the effort by ~40%.
  • Supported ISO 27001, GDPR, SOC, and PCI DSS audits with control evidence, walkthroughs, and remediation tracking.
  • Part of data-centre migration, network segmentation, and DC-DR drills on the IAM stack, with zero access-related incidents during cutover.
OIMOAMISO 27001GDPRPCI DSSServiceNowDC-DR

Project Trainee, Information Security

May — Jul 2019
L&T Electrical & Automation
ISMS · Policy · Awareness · Mumbai, IN
  • Ran InfoSec awareness training for 3,000+ employees across multiple sites.
  • Did risk assessments and asset-inventory reviews; mapped ISMS controls to identified risks.
  • Drafted the System Acquisition and Software Testing Policy.
ISMSPolicyRiskAwareness

Intern, IT Infrastructure

Jun — Jul 2018
Ocrex (Dublin / Mohali)
FinTech · Bank Reconciliation Software
  • Worked on IT infrastructure and BAU tasks at an MNC building AutoRec, automated bank-reconciliation software.
InfraFinTechBAU

Toolkit

The working set.

The tools I reach for without thinking, grouped by the job they do.

Governance & Access Design

  • Joiner-Mover-Leaver
  • RBAC modeling
  • SoD rule design
  • Access certifications
  • Role catalog
  • Entitlement mapping

Platforms

  • Oracle Identity Manager
  • Oracle Access Manager
  • Arcon PAM
  • Microsoft Entra ID
  • Azure AD
  • ServiceNow
  • Jira

Security & Audit

  • ISO 27001
  • GDPR
  • PCI DSS
  • SOC support
  • Internal audits
  • Risk assessment
  • ISMS

Operations

  • Application onboarding
  • Workflow automation
  • Reconciliation scripting
  • KPI dashboards
  • AI-assisted routing
  • Incident triage

Education & Certification

Where it started.

A cyber-security degree, a foundation in the law behind the controls, and a certification to make the practice official.

Microsoft SC-300 — Identity & Access Administrator In preparation

Formalizing six years of Entra ID and identity-governance practice.

2026

B.Tech, Computer Science (Cyber Security & Forensics)

University of Petroleum and Energy Studies, Dehradun

2016 – 2020

Diploma in Cyber Laws

Asian School of Cyber Laws, Mumbai · legal framework for digital evidence, privacy, and infosec

Continued education (self-directed)

Identity governance, zero-trust architecture, AI in access management

Ongoing

Let's talk access.

For new engagements, advisory work, or anything access-shaped. My inbox is open.