About the RoleOwns the engineering platform beneath every IGA/IAM engagement: environments, pipelines, infrastructure-as-code, and the secure operation of identity platforms in client and Gruve-hosted estates. Also owns the identity of the delivery chain itself - the service accounts, workload identities, secrets and certificates that identity platforms run on and that auditors ask about first.
Key Responsibilities- Own environment strategy across the portfolio: development, test, UAT and production estates for IGA platforms, including refresh cadence, data masking and anonymization of production identity data in lower environments.
- Build and govern CI/CD for identity artifacts - configuration-as-code promotion, object versioning and packaging for SailPoint, Saviynt, and Okta, automated deployment, drift detection and rollback.
- Own infrastructure-as-code (Terraform, Ansible) for identity platform infrastructure and containerized deployment on Kubernetes (EKS/AKS/GKE).
- Own secrets and non-human identity management across the practice: vaulting, workload identity federation, service-account and API-key lifecycle, and certificate and PKI lifecycle for connector and federation endpoints.
- Design and validate platform reliability for identity workloads: HA and DR architecture, RPO/RTO validation, and capacity and performance tuning for aggregation cycles, certification campaigns and peak provisioning load.
- Secure the delivery chain: SAST/DAST and dependency scanning in the pipeline, SBOM generation, artifact signing, and least-privilege pipeline and repository access.
- Stand up observability for identity platforms - provisioning failure rates, aggregation SLA, connector health, task and workflow queue depth - and route identity audit logs into the client SIEM.
- Lead the DevOps and platform engineering team across US and Pune; set engineering standards, chair change advisory for platform changes, and own audit evidence for client and internal audit.
- Partner with the Principal Engineering Manager on architecture decisions with platform impact, and support presales for hosting, managed-service and platform-modernization scope.
- Own platform upgrade and patch strategy across client estates, including vendor release tracking, regression risk assessment and coordinated upgrade windows.
Basic Qualifications- CKA/CKAD, HashiCorp Terraform Associate, or Azure/AWS Solutions Architect certification.
- CISSP or CCSP.
- SRE practice - SLI/SLO definition, error budgets, chaos and DR testing.
- Zero Trust architecture, ZTNA and micro segmentation experience.
- Experience running a hosted or managed identity service with contractual SLAs.
Preferred Qualifications- 10-15+ years in infrastructure, platform or DevOps engineering, including 5+ years leading teams and 4+ years supporting IAM/IGA or comparable security platforms.
- Deep CI/CD ownership (Azure DevOps, GitHub Actions or Jenkins) and infrastructure-as-code (Terraform, Ansible) at enterprise scale.
- Kubernetes depth and strong cloud platform experience on Azure and/or AWS or GCP, including cloud IAM models and workload identity federation.
- Hands-on operation of identity platforms - deployment, upgrade, patching, HA/DR and performance tuning for SailPoint, Saviynt, Okta or Entra ID.
- Secrets management and machine/workload identity: HashiCorp Vault or cloud KMS, service-account governance, and PKI and certificate lifecycle management.
- Security controls and audit evidence: CIS benchmarks, system hardening, vulnerability and patch management, and mapping platform controls to NIST 800-53, SOC 2, ISO 27001 or SOX ITGC.
- Understanding of the identity domain the platform serves - provisioning, aggregation, certification and federation - sufficient to design environments and pipelines that fit how IGA actually behaves.
- Director-level client interface and experience managing distributed US/India teams across time zones.
Salary Range$200k - $230k USD
This is a full-time opportunity with Gruve.