Skip to main content
Gruve

Principal Engineering Manager

RemoteUnited States only
Published
Role
Engineering Management
Experience
Principal
Employment
Full-time
Company size
Startup
$200k–$230k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Design authority and engineering leader for the IGA/IAM practice. Owns the technical solution across a portfolio of concurrent identity engagements — identity model, governance architecture and integration strategy — and leads the engineering bench that builds it.

Core skills

Identity Governance and Administration (IGA)Identity and Access Management (IAM)

Required skills

CISSPCIMP/IDProSailPoint Certified ArchitectSaviynt L400Okta Certified ConsultantCyberArkDelineaBeyondTrustSCIM 2.0SAML 2.0OAuth 2.0OIDCLDAPJWTSPMLActive DirectoryEntra IDWorkdaySAPServiceNowSalesforceRACF

Optional skills

SailPoint IdentityIQSailPoint Identity Security CloudSaviynt EICOkta Identity GovernanceMicrosoft Entra ID GovernanceITDRISPMRBAC

Required languages

English

What you'll do

  • Own end-to-end solution architecture for IGA engagements: identity model, authoritative source strategy, account correlation logic, entitlement catalog design and the target governance operating model.
  • Act as design authority across the portfolio — review and approve connector designs, lifecycle and provisioning workflows, role models (RBAC/ABAC), SoD rule sets and certification campaign architecture before build starts.
  • Build and lead engineering bench (engineers across US and Pune): staffing to engagements, technical mentoring, code and configuration quality gates, and career development.
  • Own migration strategy and execution for legacy-to-modern IGA moves — IdentityIQ to Identity Security Cloud, homegrown or end-of-life platforms to SailPoint, Saviynt or any similar solution— including coexistence, data migration and cutover sequencing.
  • Design joiner-mover-leaver automation against HR authoritative sources (Workday, SuccessFactors, SAP HCM), including birthright access, contractor and non-employee lifecycle, and emergency deprovisioning paths.

What they require

  • CISSP, CIMP/IDPro, or vendor architect-level certification (SailPoint Certified Architect, Saviynt L400, Okta Certified Consultant).
  • PAM adjacency — CyberArk, Delinea or BeyondTrust integration into an IGA program.
  • Identity Threat Detection and Response (ITDR) or Identity Security Posture Management (ISPM) exposure.
  • Non-human, machine and workload identity governance; secrets and service-account lifecycle.
  • M&A identity integration, divestiture separation, or multi-tenant/multi-forest consolidation experience.
  • Regulated-industry program experience — financial services, healthcare or public sector.
  • 8+ years in IAM/IGA, including 4+ years leading engineering or architecture teams in a professional services, SI or MSP environment.
  • Deep hands-on delivery experience with at least two of: SailPoint IdentityIQ / Identity Security Cloud, Saviynt EIC, Okta Identity Governance, Microsoft Entra ID Governance.
  • Demonstrable ownership of full identity lifecycle design: JML processes, birthright and role-based provisioning, access request and approval, delegated administration, deprovisioning and orphan-account handling.
  • Access governance depth: certification and recertification program design, segregation-of-duties and toxic-combination modeling, role mining and RBAC/ABAC design, entitlement risk rating.
  • Standards fluency: SCIM 2.0, SAML 2.0, OAuth 2.0 / OIDC, LDAP, JWT, and legacy SPML-era integration patterns.
  • Integration breadth across directories and enterprise applications — Active Directory, Entra ID, LDAP, Workday, SAP, ServiceNow, Salesforce, database and mainframe/RACF targets.
  • Working cybersecurity context: least privilege and zero standing privilege, privileged access adjacency, identity attack paths, and the audit drivers behind governance programs (SOX ITGC, HIPAA, PCI DSS, GDPR, NIST 800-53, ISO 27001).
  • Client-facing gravitas at Director and CISO level; disciplined estimation, scoping and written communication.

Benefits

  • Fosters a culture of innovation, collaboration, and continuous learning.
  • Committed to building a diverse and inclusive workplace.
  • Opportunity to make an impact in technology.

Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. It specializes in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models.

IT ServicesStartup
$200k–$230k/yr