About the RoleGruve is looking to hire a Senior Software Engineer with Hands-on builder on IGA/IAM engagements. Develops the connectors, lifecycle workflows, rules and integrations that turn an approved identity design into working platform behavior - and stands behind them through UAT, cutover and hypercare.
Key Responsibilities- Build and extend IGA connectors for target applications - out-of-box, configured and fully custom - across SCIM, REST, SOAP, JDBC, LDAP, PowerShell and flat-file integration patterns.
- Develop identity lifecycle logic: joiner-mover-leaver workflows, provisioning and deprovisioning policies, birthright access rules, and platform rules (BeanShell/Java in IdentityIQ, Saviynt configuration and jobs, Okta Workflows, PowerShell and Microsoft Graph for Entra ID).
- Implement access request catalogs, approval and escalation workflows, and access certification campaigns including reviewer models and closed-loop revocation.
- Build aggregation, correlation and entitlement normalization logic; develop data-quality and role-mining support pipelines against messy source data.
- Integrate the platform with ServiceNow ITSM for ticketed fulfilment and with HR systems (Workday, SuccessFactors) as authoritative identity sources.
- Configure federation and authentication integrations: SAML and OIDC application onboarding, MFA and adaptive access policy implementation, directory integration.
- Write unit and integration tests, participate in peer code review, and maintain deployment artifacts through the practice CI/CD pipeline.
- Support UAT execution, defect triage and root-cause analysis; own assigned defects through closure during cutover and hypercare windows.
- Produce build documentation, configuration records and knowledge-transfer material to a standard the client can operate against post-go-live.
- Contribute reusable connectors and accelerators back into the practice IP library.
Basic Qualifications- Vendor certification - SailPoint Certified Engineer, Saviynt L200/L300, Okta Certified Developer, or industry equivalent.
- Cloud identity services on Azure, AWS or GCP; Kubernetes and containerized deployment basics.
- Exposure to PAM integration (CyberArk, Delinea) or ITDR/ISPM tooling.
- Specialized target experience - SAP GRC, mainframe/RACF, Epic or Cerner in healthcare, or core banking platforms.
- Experience on a legacy-to-modern IGA migration.
- Regulated-environment platform delivery - FedRAMP, HITRUST or PCI-scoped estates.
Preferred Qualifications- 6-8+ years of software engineering, with at least 4 years building on IGA/IAM platforms.
- Hands-on connector and workflow development on at least one of SailPoint IdentityIQ / ISC, Saviynt EIC, Okta, or Microsoft Entra ID.
- Strong Java (including BeanShell), .NET, and/or Python and PowerShell; solid SQL against identity and entitlement data.
- REST and SOAP API integration; SCIM 2.0 provisioning; LDAP and Active Directory schema fluency.
- Practical understanding of core IGA concepts - identity lifecycle, entitlements, roles, aggregation and correlation, access requests, certification, orphan and dormant accounts.
- Federation fundamentals: SAML 2.0 and OAuth 2.0 / OIDC flows, token handling, application onboarding.
- Secure engineering hygiene - secrets and credential handling, secure coding against OWASP Top 10, TLS and certificate basics, and an understanding of why an over-permissioned connector is a security finding.
- Git-based workflow and active participation in CI/CD-driven delivery.
- Clear written English for design notes, defect records and client-facing documentation.
Salary Range$180k - $200k
This is a full-time opportunity with Gruve.