Confidential mandate

People-System Identity and Access Control Director — Global Capability Centre

Planned Hiring / New

People-System Identity and Access Control Director mandate in Bengaluru, India · Multisector Global Capability Centres

A Bengaluru capability centre commissions a four-month engagement to control worker identity, privileged access and joiner-mover-leaver evidence across rapidly scaling regional people platforms and facilities.

The mandate

Rapid hiring has created duplicate worker identities, pre-hire access, delayed termination and broad administrator roles across recruiting, core HR, payroll, learning, scheduling and building systems. Contractors may change suppliers without changing assignments, while global transfers generate new identifiers. Security tickets close, but People Operations cannot prove that access follows one authoritative worker state and legitimate purpose.

The engagement deliverable is a Workforce Identity and Access Control Architecture. It will define authoritative identity, worker type, lifecycle state, role catalogue, segregation, privilege elevation, service accounts, emergency access, recertification, termination, evidence retention and cross-system reconciliation. The design must cover employees, interns, agency workers, vendors, alumni and candidates without collapsing legally different relationships.

Milestone one at week three accepts identity populations and consequence-ranked access breaks. Week seven closes lifecycle and role-control design; week twelve completes four system journeys and privileged-access reperformance. At week seventeen, accepted artefacts, exception disposition, operating procedures, trained client owners and an unseen supplier-transfer rehearsal complete delivery.

Acceptance requires People Operations to trace twelve unfamiliar worker changes from authoritative approval through every affected system, Security to reperform privileged-role and orphan-account tests, and Payroll to validate segregation. The GCC People Leader signs only after client teams revoke a simulated urgent departure and preserve required evidence without consultant-held queries or administrator credentials.

The client will provide system inventories, worker and supplier records, identity mappings, role catalogues, access logs, workflow rules, security standards, incidents, audit findings, contracts and named owners. The consultant does not administer production access, investigate users, choose platforms, make employment decisions, redesign payroll, provide legal advice or certify cybersecurity.

Why this is external work

Security owns digital access and People owns worker status, but rapid GCC scaling has exposed mismatched identities and lifecycle definitions between them. Independent architecture can create a controlled state transition and evidence model without handling credentials, investigating individuals or taking employment and cybersecurity decisions.

What you will own

  • Reconcile employee, candidate, intern, agency, vendor and alumni identities across interconnected people, security and access systems.
  • Define authoritative lifecycle states for pre-hire, active, leave, transfer, supplier change, notice, exit and rehire.
  • Map role access, segregation conflicts, privileged administration, emergency elevation and service-account ownership.
  • Govern joiner, mover and leaver triggers, approvals, provisioning, revocation, reconciliation and retained evidence.
  • Test duplicate identities, orphan accounts, delayed feeds, global transfers and contractor supplier substitutions.
  • Design recertification by data sensitivity, decision consequence, privilege, role change and accountable manager.
  • Deliver governed identity maps, access catalogue, control procedures, test cases and a prioritised remediation backlog with accountable owners.

Candidate qualifications

  • Designed workforce identity controls across cloud-based HR, payroll, learning, scheduling and physical-access platforms.
  • Reconciled employees and contingent workers through complex transfers, supplier changes, leave, exit and rehire events.
  • Governed privileged roles, segregation conflicts, emergency access, recertification and orphan-account detection.
  • Connected authoritative People states with security provisioning without administering access or making employment decisions.
  • Worked across privacy, cybersecurity, payroll, vendors and internal controls in a rapidly scaling capability centre.
  • Transferred production-ready control ownership through repeated urgent-exit and complex worker-transition rehearsals independently.

Non-negotiables

  • Can lead Bengaluru access laboratories and both controlled lifecycle rehearsals within four months.
  • Brings workforce identity control across multiple HR systems; general cyber-access architecture is insufficient.
  • Will disclose relationships with identity providers, HR platforms, staffing suppliers and security assessors.
  • Will not hold credentials, administer production access, investigate users, make employment decisions or certify security.
  1. 49 words maximum. Describe a worker transition that created valid records but inappropriate retained access.
  2. 49 words maximum. How did you define one authoritative identity across employee and contractor systems?
  3. 49 words maximum. Which supplier-change event would you use to test client control ownership?

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.