In Oracle HCM, a security design error does not just create an access support ticket — it creates a data breach, a compliance gap, or a go-live delay. If you understand the role inheritance hierarchy deeply enough to design a multi-country security model without creating orphaned data roles, this is your workstream.
About Rolling Arrays
Rolling Arrays is a private equity-backed, award-winning HR Tech consulting firm — Asia Pacific's premium partner for enterprise HR digital transformation. Headquartered in Singapore and with offices across India, Malaysia, Australia, and Hong Kong, we have delivered more than 200 HR Transformation projects since our founding in 2009, and were recognised as one of Singapore's Top 100 fastest-growing companies in 2025. We specialise in SAP SuccessFactors, Oracle HCM, and Workday across the full delivery spectrum: HR process design and consulting (ALIGN), technology implementation (AUTOMATE), change management and adoption (ADOPT), and managed support services (AMS).
Position Summary
We are seeking a Consultant specialising in Oracle HCM Cloud Application Security and Authorisations. You will design, configure, and test the RBAC framework across Oracle HCM Cloud modules, ensuring that clients HR data is protected by the principle of least privilege and that the security model is sustainable, auditable, and upgrade-safe.
What You Will Do
- Design the RBAC framework — deciding how many custom roles are needed, whether to deep-copy or shallow-copy predefined Oracle roles, whether to use fixed data roles or the Area of Responsibility pattern for HR specialists, and what naming convention will allow security administrators to maintain the system after go-live
- Configure HCM Data Roles — combining job roles with security profiles across every dimension: person, organisation, position, payroll, Legislative Data Group, and document type
- Lead client security design workshops — translating access matrix requirements from HR, IT, and Finance into Oracle's security model, and navigating the reality that requirements from those three groups rarely align on first pass
- Design and execute the security test strategy — building positive and negative test cases and producing the documented test evidence that an auditor will ask for at go-live
- Own the Segregation of Duties analysis — identifying conflicting duty combinations that create audit risk, designing role structures that prevent access conflicts, and producing the SoD compliance matrix for client sign-off
- Configure role provisioning rules — automatic provisioning based on HR data attributes versus manual assignment, and the provisioning lifecycle for workers, contingent workers, and system users
WHY ROLLING ARRAYS
Security at Rolling Arrays is a first-class delivery workstream, not an afterthought assigned to a junior consultant in the final four weeks. You will work on multi-module Oracle HCM programmes across Singapore, Malaysia, Australia, and India — each with different legislative data privacy requirements — and build genuine expertise in Oracle's most complex and consequential configuration domain.
OUR CULTURE CODE
Six values define how we operate every day at Rolling Arrays:
- Thinking Smart — spot patterns, chase smarter solutions, and illuminate the path to greater productivity
- Never Stop Learning — refine and elevate skills constantly; explore the world with a curiosity lens
- Being Nice to Everyone — treat everyone with genuine warmth and respect, regardless of seniority
- Be Super Patient with Customers — exercise patience and proactivity in every client interaction
- Help Your Teammates — share the load, lighten the stress, nurture a truly collaborative team
- Acknowledge Your Mistakes — embrace mistakes as steppingstones; grow from each one
Requirements
WHAT WE'RE LOOKING FOR
- 2-4 years of Oracle HCM Cloud Security configuration experience on live implementation projects — has personally designed and built data roles and security profiles, not observed another consultant do it
- Demonstrated data role design — has combined job roles with security profiles and validated the resulting data access scope through positive and negative testing
- Experience leading or materially contributing to the security workstream for at least one end-to-end Oracle Cloud implementation through to go-live
- Ability to translate a client access matrix into Oracle's security model and explain the design choices in business language to HR leadership
- SoD conflict identification and documentation experience
Preferred Qualifications
- Oracle Fusion Cloud Applications HCM Process Essentials certified — the foundational HCM credential; at Consultant level this is the expected starting point for certification
- Oracle Global Human Resources Cloud Implementation Professional — working toward this certification demonstrates commitment to the domain; security is inseparable from Core HR module depth
- Oracle Risk Management Cloud (Advanced Access Controls) certification or hands-on experience — for systematic SoD risk analysis and continuous monitoring
- Oracle IDCS (Identity Cloud Service) or Oracle Access Governance exposure — for enterprise identity lifecycle management alongside HCM security
Business & Consulting Skills
- Audit-grade documentation — produces security test evidence and SoD matrices that withstand scrutiny from compliance and internal audit teams
- Business translation — explains role inheritance, data security, and access control in language that HR Directors and IT governance teams can act on
- Structured problem-solving — diagnoses security issues methodically rather than through trial and error
- Cross-team collaboration — works effectively with HR, IT, and Finance workstreams whose requirements rarely align on first pass
- Attention to detail — a missed security configuration creates a breach, not just a ticket; precision is non-negotiable
- Professional client interaction — represents RAC credibly in client-facing sessions at working level
CAREER PROGRESSION
Consultant → Senior Consultant → Lead Consultant → Solution Architect → Practice Lead