· Manage joiner, mover, and leaver identity lifecycle processes and automated account provisioning across connected systems.
· Review access requests, approvals, role assignments, segregation-of-duties conflicts, and least-privilege controls.
· Operate SSO and MFA services and investigate failed, suspicious, or anomalous authentication activity.
· Monitor identity synchronization, resolve provisioning failures, and maintain identity-data consistency.
· Run access-certification campaigns, coordinate with business owners, and escalate overdue reviews.
· Identify and remediate inactive, orphaned, excessive, or high-risk accounts and entitlements.
· Govern privileged access requests, session monitoring, recordings, shared accounts, and just-in-time access.
· Support audits, compliance evidence, IAM/PAM incident investigation, remediation tracking, and periodic operational reporting.