Principal Engineering Manager

Gruve

Redwood City (CA)

On-site

USD 200,000 - 230,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Gruve seeks a design authority and engineering leader for the IGA/IAM practice to own the technical solution across a portfolio of engagements. You’ll shape identity models, governance architecture, and provisioning strategy while actively contributing to designs and code.

This hands-on leadership role requires guiding a diverse engineering bench across US and Pune, reviewing connector designs, and delivering secure, scalable identity solutions for regulated industries.

Qualifications

  • CISSP, CIMP/IDPro, or vendor architect-level certification.
  • PAM integration with CyberArk, Delinea or BeyondTrust.
  • Identity Threat Detection and Response (ITDR) or Identity Security Posture Management (ISPM).
  • Non-human, machine and workload identity governance; secrets and service-account lifecycle.
  • M&A identity integration, divestiture separation, or multi-tenant/multi-forest consolidation.
  • Regulated-industry program experience.

Responsibilities

  • Own end-to-end solution architecture for IGA engagements: identity model, authoritative source strategy, account correlation, entitlement catalog design and governance model.
  • Act as design authority across the portfolio—review and approve connector designs, lifecycle and provisioning workflows, RBAC/ABAC, SoD rules and certification campaigns.
  • Build and lead engineering bench across US and Pune; staffing, mentoring, code quality gates, and career development.
  • Own migration strategy and execution for legacy-to-modern IGA moves.
  • Design joiner-mover-leaver automation against HR sources (Workday, SuccessFactors, SAP HCM).
  • Serve as senior technical interface to client IAM Directors and CISO groups; chair design authority boards.
  • Support presales, effort estimation, SOW scope, RFP/RFI responses, and POC leadership.
  • Own delivery governance: risk register, dependency management, technical debt, go/no-go at gates.
  • Build and curate practice IP: reference architectures, connectors, accelerators, estimation models.

Skills

IAM/IGA leadership
Architecture leadership
Vendor certifications
PAM integration
Identity governance
JML provisioning
Multitenant experience
Regulated industry
Client-facing gravitas

Education

Certification: CISSP / CIMP / IDPro

Tools

SailPoint IdentityIQ
Identity Security Cloud
Saviynt EIC
Okta Identity Governance
Microsoft Entra ID Governance

Job description

About Gruve

Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.

About The Role

Design authority and engineering leader for the IGA/IAM practice. Owns the technical solution across a portfolio of concurrent identity engagements - identity model, governance architecture and integration strategy - and leads the engineering bench that builds it. This is a hands-on-enough leadership role: the expectation is to review and correct a role model or a connector design, not just to manage the people who wrote it.

Key Responsibilities
  • Own end-to-end solution architecture for IGA engagements: identity model, authoritative source strategy, account correlation logic, entitlement catalog design and the target governance operating model.
  • Act as design authority across the portfolio - review and approve connector designs, lifecycle and provisioning workflows, role models (RBAC/ABAC), SoD rule sets and certification campaign architecture before build starts.
  • Build and lead engineering bench (engineers across US and Pune): staffing to engagements, technical mentoring, code and configuration quality gates, and career development.
  • Own migration strategy and execution for legacy-to-modern IGA moves - IdentityIQ to Identity Security Cloud, homegrown or end-of-life platforms to SailPoint, Saviynt or any similar solution - including coexistence, data migration and cutover sequencing.
  • Design joiner-mover-leaver automation against HR authoritative sources (Workday, SuccessFactors, SAP HCM), including birthright access, contractor and non-employee lifecycle, and emergency deprovisioning paths.
  • Serve as senior technical interface to client IAM Directors, Enterprise Architects and CISO organizations; chair design authority boards and architecture review sessions.
  • Support presales and practice growth: solution shaping, level-of-effort estimation, technical SOW scope, RFP and RFI responses, and proof-of-concept leadership.
  • Own delivery governance across engagements - technical risk register, dependency management, technical debt tracking, and go/no-go recommendations at each gate.
  • Build and curate practice IP: reference architectures, reusable connectors, accelerators, estimation models and design pattern libraries.
  • Maintain vendor technical relationships (SailPoint, Saviynt, Okta, Microsoft) and drive the team certification and partner-tier plan.
Basic Qualifications
  • CISSP, CIMP/IDPro, or vendor architect-level certification (SailPoint Certified Architect, Saviynt L400, Okta Certified Consultant).
  • PAM adjacency - CyberArk, Delinea or BeyondTrust integration into an IGA program.
  • Identity Threat Detection and Response (ITDR) or Identity Security Posture Management (ISPM) exposure.
  • Non-human, machine and workload identity governance; secrets and service-account lifecycle.
  • M&A identity integration, divestiture separation, or multi-tenant/multi-forest consolidation experience.
  • Regulated-industry program experience - financial services, healthcare or public sector.
Preferred Qualifications
  • 8+ years in IAM/IGA, including 4+ years leading engineering or architecture teams in a professional services, SI or MSP environment.
  • Deep hands-on delivery experience with at least two of: SailPoint IdentityIQ / Identity Security Cloud, Saviynt EIC, Okta Identity Governance, Microsoft Entra ID Governance.
  • Demonstrable ownership of full identity lifecycle design: JML processes, birthright and role-based provisioning, access request and approval, delegated administration, deprovisioning and orphan-account handling.
  • Access governance depth: certification and recertification program design, segregation-of-duties and toxic-combination modeling, role mining and RBAC/ABAC design, entitlement risk rating.
  • Standards fluency: SCIM 2.0, SAML 2.0, OAuth 2.0 / OIDC, LDAP, JWT, and legacy SPML-era integration patterns.
  • Integration breadth across directories and enterprise applications - Active Directory, Entra ID, LDAP, Workday, SAP, ServiceNow, Salesforce, database and mainframe/RACF targets.
  • Working cybersecurity context: least privilege and zero standing privilege, privileged access adjacency, identity attack paths, and the audit drivers behind governance programs (SOX ITGC, HIPAA, PCI DSS, GDPR, NIST 800-53, ISO 27001).
  • Client-facing gravitas at Director and CISO level; disciplined estimation, scoping and written communication.
Salary Range

$200k - $230k USD

This is a full-time opportunity with Gruve.

Why Gruve

At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.

Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Engineering Manager
Principal Engineering Manager

Gruve • San Francisco (CA)

On-site
USD 200,000 - 230,000
Senior Software Engineer
Senior Software Engineer

Gruve • San Francisco (CA)

On-site
USD 180,000 - 200,000
DevOps Director
DevOps Director

Gruve • San Francisco (CA)

On-site
USD 200,000 - 230,000
Senior Business Analyst
Senior Business Analyst

Gruve • San Francisco (CA)

On-site
USD 150,000 - 170,000
DevOps Director
DevOps Director

Gruve • United States

On-site
USD 200,000 - 230,000
Senior Software Engineer
Senior Software Engineer

Gruve • Redwood City (CA)

On-site
USD 180,000 - 200,000
Senior Business Analyst
Senior Business Analyst

Gruve • United States

On-site
USD 150,000 - 170,000
DevOps Director - Gruve
DevOps Director - Gruve

OpenTalent • United States

On-site
USD 150,000 - 190,000
Senior IAM & IGA Design & Delivery Leader
Senior IAM & IGA Design & Delivery Leader

Gruve • Redwood City (CA)

On-site
USD 200,000 - 230,000
Senior Identity & IGA Analyst – Access Governance
Senior Identity & IGA Analyst – Access Governance

Gruve • United States

On-site
USD 150,000 - 170,000