About the RoleDesign authority and engineering leader for the IGA/IAM practice. Owns the technical solution across a portfolio of concurrent identity engagements - identity model, governance architecture and integration strategy - and leads the engineering bench that builds it. This is a hands-on-enough leadership role: the expectation is to review and correct a role model or a connector design, not just to manage the people who wrote it.
Key Responsibilities- Own end-to-end solution architecture for IGA engagements: identity model, authoritative source strategy, account correlation logic, entitlement catalog design and the target governance operating model.
- Act as design authority across the portfolio - review and approve connector designs, lifecycle and provisioning workflows, role models (RBAC/ABAC), SoD rule sets and certification campaign architecture before build starts.
- Build and lead engineering bench (engineers across US and Pune): staffing to engagements, technical mentoring, code and configuration quality gates, and career development.
- Own migration strategy and execution for legacy-to-modern IGA moves - IdentityIQ to Identity Security Cloud, homegrown or end-of-life platforms to SailPoint, Saviynt or any similar solution- including coexistence, data migration and cutover sequencing.
- Design joiner-mover-leaver automation against HR authoritative sources (Workday, SuccessFactors, SAP HCM), including birthright access, contractor and non-employee lifecycle, and emergency deprovisioning paths.
- Serve as senior technical interface to client IAM Directors, Enterprise Architects and CISO organizations; chair design authority boards and architecture review sessions.
- Support presales and practice growth: solution shaping, level-of-effort estimation, technical SOW scope, RFP and RFI responses, and proof-of-concept leadership.
- Own delivery governance across engagements - technical risk register, dependency management, technical debt tracking, and go/no-go recommendations at each gate.
- Build and curate practice IP: reference architectures, reusable connectors, accelerators, estimation models and design pattern libraries.
- Maintain vendor technical relationships (SailPoint, Saviynt, Okta, Microsoft) and drive the team certification and partner-tier plan.
Basic Qualifications- CISSP, CIMP/IDPro, or vendor architect-level certification (SailPoint Certified Architect, Saviynt L400, Okta Certified Consultant).
- PAM adjacency - CyberArk, Delinea or BeyondTrust integration into an IGA program.
- Identity Threat Detection and Response (ITDR) or Identity Security Posture Management (ISPM) exposure.
- Non-human, machine and workload identity governance; secrets and service-account lifecycle.
- M&A identity integration, divestiture separation, or multi-tenant/multi-forest consolidation experience.
- Regulated-industry program experience - financial services, healthcare or public sector.
Preferred Qualifications- 8+ years in IAM/IGA, including 4+ years leading engineering or architecture teams in a professional services, SI or MSP environment.
- Deep hands-on delivery experience with at least two of: SailPoint IdentityIQ / Identity Security Cloud, Saviynt EIC, Okta Identity Governance, Microsoft Entra ID Governance.
- Demonstrable ownership of full identity lifecycle design: JML processes, birthright and role-based provisioning, access request and approval, delegated administration, deprovisioning and orphan-account handling.
- Access governance depth: certification and recertification program design, segregation-of-duties and toxic-combination modeling, role mining and RBAC/ABAC design, entitlement risk rating.
- Standards fluency: SCIM 2.0, SAML 2.0, OAuth 2.0 / OIDC, LDAP, JWT, and legacy SPML-era integration patterns.
- Integration breadth across directories and enterprise applications - Active Directory, Entra ID, LDAP, Workday, SAP, ServiceNow, Salesforce, database and mainframe/RACF targets.
- Working cybersecurity context: least privilege and zero standing privilege, privileged access adjacency, identity attack paths, and the audit drivers behind governance programs (SOX ITGC, HIPAA, PCI DSS, GDPR, NIST 800-53, ISO 27001).
- Client-facing gravitas at Director and CISO level; disciplined estimation, scoping and written communication.
Salary Range$200k - $230k USD
This is a full-time opportunity with Gruve.