Principal Engineering Manager

Gruve

$200K — $230K *
US-AnywhereRemote in United States
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • CISSP, CIMP/IDPro, or equivalent vendor certifications required.
  • Experience with PAM tools like CyberArk, Delinea or BeyondTrust.
  • Knowledge in Identity Threat Detection and Response (ITDR).
  • Expertise in governance for non-human and workload identities.
  • Experience in merger & acquisition identity integration or multi-tenant structures.
  • Regulated industry experience in sectors such as financial services or healthcare.

Responsibilities

  • Own and design end-to-end solution architecture for IGA.
  • Approve connector designs, role models, and certification campaign architecture.
  • Lead and mentor an engineering team across geographical locations.
  • Develop migration strategies for transitioning legacy IGA systems.
  • Automate joiner-mover-leaver processes against HR systems.
  • Interface with client IAM Directors and chair design authority boards.
  • Drive presales efforts including technical responses and proofs-of-concept.
  • Govern delivery across engagements, managing technical risks and dependencies.
  • Curate practice intellectual property like reference architectures and design patterns.
  • Maintain relationships with key vendors in the identity governance space.

Benefits

  • Opportunity for hands-on leadership and technical engagement.
  • Chance to shape and mentor a diverse engineering team.
  • Involvement in strategy and architecture at a high level.
  • Exposure to varied industry sectors for best practice implementation.
  • Opportunities to engage with leading identity management vendors.
  • Growth and development potential within a progressive practice.
Full Job Description
About the Role

Design authority and engineering leader for the IGA/IAM practice. Owns the technical solution across a portfolio of concurrent identity engagements - identity model, governance architecture and integration strategy - and leads the engineering bench that builds it. This is a hands-on-enough leadership role: the expectation is to review and correct a role model or a connector design, not just to manage the people who wrote it.

Key Responsibilities
  • Own end-to-end solution architecture for IGA engagements: identity model, authoritative source strategy, account correlation logic, entitlement catalog design and the target governance operating model.
  • Act as design authority across the portfolio - review and approve connector designs, lifecycle and provisioning workflows, role models (RBAC/ABAC), SoD rule sets and certification campaign architecture before build starts.
  • Build and lead engineering bench (engineers across US and Pune): staffing to engagements, technical mentoring, code and configuration quality gates, and career development.
  • Own migration strategy and execution for legacy-to-modern IGA moves - IdentityIQ to Identity Security Cloud, homegrown or end-of-life platforms to SailPoint, Saviynt or any similar solution- including coexistence, data migration and cutover sequencing.
  • Design joiner-mover-leaver automation against HR authoritative sources (Workday, SuccessFactors, SAP HCM), including birthright access, contractor and non-employee lifecycle, and emergency deprovisioning paths.
  • Serve as senior technical interface to client IAM Directors, Enterprise Architects and CISO organizations; chair design authority boards and architecture review sessions.
  • Support presales and practice growth: solution shaping, level-of-effort estimation, technical SOW scope, RFP and RFI responses, and proof-of-concept leadership.
  • Own delivery governance across engagements - technical risk register, dependency management, technical debt tracking, and go/no-go recommendations at each gate.
  • Build and curate practice IP: reference architectures, reusable connectors, accelerators, estimation models and design pattern libraries.
  • Maintain vendor technical relationships (SailPoint, Saviynt, Okta, Microsoft) and drive the team certification and partner-tier plan.

Basic Qualifications
  • CISSP, CIMP/IDPro, or vendor architect-level certification (SailPoint Certified Architect, Saviynt L400, Okta Certified Consultant).
  • PAM adjacency - CyberArk, Delinea or BeyondTrust integration into an IGA program.
  • Identity Threat Detection and Response (ITDR) or Identity Security Posture Management (ISPM) exposure.
  • Non-human, machine and workload identity governance; secrets and service-account lifecycle.
  • M&A identity integration, divestiture separation, or multi-tenant/multi-forest consolidation experience.
  • Regulated-industry program experience - financial services, healthcare or public sector.

Preferred Qualifications
  • 8+ years in IAM/IGA, including 4+ years leading engineering or architecture teams in a professional services, SI or MSP environment.
  • Deep hands-on delivery experience with at least two of: SailPoint IdentityIQ / Identity Security Cloud, Saviynt EIC, Okta Identity Governance, Microsoft Entra ID Governance.
  • Demonstrable ownership of full identity lifecycle design: JML processes, birthright and role-based provisioning, access request and approval, delegated administration, deprovisioning and orphan-account handling.
  • Access governance depth: certification and recertification program design, segregation-of-duties and toxic-combination modeling, role mining and RBAC/ABAC design, entitlement risk rating.
  • Standards fluency: SCIM 2.0, SAML 2.0, OAuth 2.0 / OIDC, LDAP, JWT, and legacy SPML-era integration patterns.
  • Integration breadth across directories and enterprise applications - Active Directory, Entra ID, LDAP, Workday, SAP, ServiceNow, Salesforce, database and mainframe/RACF targets.
  • Working cybersecurity context: least privilege and zero standing privilege, privileged access adjacency, identity attack paths, and the audit drivers behind governance programs (SOX ITGC, HIPAA, PCI DSS, GDPR, NIST 800-53, ISO 27001).
  • Client-facing gravitas at Director and CISO level; disciplined estimation, scoping and written communication.

Salary Range
$200k - $230k USD
This is a full-time opportunity with Gruve.

Similar Jobs

More Jobs at Gruve

More Information Technology Jobs

Find similar Principal Engineering Manager jobs: