The Principal Engineering Manager will own the end-to-end solution architecture for IGA engagements and lead the engineering bench across the US and Pune. They are responsible for technical solution design, migration strategies, and serving as the senior technical interface to client stakeholders.
About Gruve
Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.
About the Role
Design authority and engineering leader for the IGA/IAM practice. Owns the technical solution across a portfolio of concurrent identity engagements — identity model, governance architecture and integration strategy — and leads the engineering bench that builds it. This is a hands-on-enough leadership role: the expectation is to review and correct a role model or a connector design, not just to manage the people who wrote it.
Key Responsibilities
Own end-to-end solution architecture for IGA engagements: identity model, authoritative source strategy, account correlation logic, entitlement catalog design and the target governance operating model.
Act as design authority across the portfolio — review and approve connector designs, lifecycle and provisioning workflows, role models (RBAC/ABAC), SoD rule sets and certification campaign architecture before build starts.
Build and lead engineering bench (engineers across US and Pune): staffing to engagements, technical mentoring, code and configuration quality gates, and career development.
Own migration strategy and execution for legacy-to-modern IGA moves — IdentityIQ to Identity Security Cloud, homegrown or end-of-life platforms to SailPoint, Saviynt or any similar solution— including coexistence, data migration and cutover sequencing.
Design joiner-mover-leaver automation against HR authoritative sources (Workday, SuccessFactors, SAP HCM), including birthright access, contractor and non-employee lifecycle, and emergency deprovisioning paths.
Serve as senior technical interface to client IAM Directors, Enterprise Architects and CISO organizations; chair design authority boards and architecture review sessions.
Support presales and practice growth: solution shaping, level-of-effort estimation, technical SOW scope, RFP and RFI responses, and proof-of-concept leadership.
Own delivery governance across engagements — technical risk register, dependency management, technical debt tracking, and go/no-go recommendations at each gate.
Build and curate practice IP: reference architectures, reusable connectors, accelerators, estimation models and design pattern libraries.
Maintain vendor technical relationships (SailPoint, Saviynt, Okta, Microsoft) and drive the team certification and partner-tier plan.
PAM adjacency — CyberArk, Delinea or BeyondTrust integration into an IGA program.
Identity Threat Detection and Response (ITDR) or Identity Security Posture Management (ISPM) exposure.
Non-human, machine and workload identity governance; secrets and service-account lifecycle.
M&A identity integration, divestiture separation, or multi-tenant/multi-forest consolidation experience.
Regulated-industry program experience — financial services, healthcare or public sector.
Preferred Qualifications
8+ years in IAM/IGA, including 4+ years leading engineering or architecture teams in a professional services, SI or MSP environment.
Deep hands-on delivery experience with at least two of: SailPoint IdentityIQ / Identity Security Cloud, Saviynt EIC, Okta Identity Governance, Microsoft Entra ID Governance.
Demonstrable ownership of full identity lifecycle design: JML processes, birthright and role-based provisioning, access request and approval, delegated administration, deprovisioning and orphan-account handling.
Access governance depth: certification and recertification program design, segregation-of-duties and toxic-combination modeling, role mining and RBAC/ABAC design, entitlement risk rating.
Integration breadth across directories and enterprise applications — Active Directory, Entra ID, LDAP, Workday, SAP, ServiceNow, Salesforce, database and mainframe/RACF targets.
Working cybersecurity context: least privilege and zero standing privilege, privileged access adjacency, identity attack paths, and the audit drivers behind governance programs (SOX ITGC, HIPAA, PCI DSS, GDPR, NIST 800-53, ISO 27001).
Client-facing gravitas at Director and CISO level; disciplined estimation, scoping and written communication.
Salary Range
$200k - $230k USD
This is a full-time opportunity with Gruve.
Why Gruve
At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.
Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”