Principal Engineering Manager

Gruve
$200,000 - $230,000

About The Position

Gruve is seeking a Principal Engineering Manager to serve as the design authority and engineering leader for their IGA/IAM practice. This role involves owning the technical solution across multiple identity engagements, including identity model, governance architecture, and integration strategy. The position requires a hands-on approach, with expectations to review and correct technical designs rather than solely managing personnel. The ideal candidate will lead the engineering bench responsible for building these solutions.

Requirements

  • CISSP, CIMP/IDPro, or vendor architect-level certification (SailPoint Certified Architect, Saviynt L400, Okta Certified Consultant).
  • PAM adjacency — CyberArk, Delinea or BeyondTrust integration into an IGA program.
  • Identity Threat Detection and Response (ITDR) or Identity Security Posture Management (ISPM) exposure.
  • Non-human, machine and workload identity governance; secrets and service-account lifecycle.
  • M&A identity integration, divestiture separation, or multi-tenant/multi-forest consolidation experience.
  • Regulated-industry program experience — financial services, healthcare or public sector.

Nice To Haves

  • 8+ years in IAM/IGA, including 4+ years leading engineering or architecture teams in a professional services, SI or MSP environment.
  • Deep hands-on delivery experience with at least two of: SailPoint IdentityIQ / Identity Security Cloud, Saviynt EIC, Okta Identity Governance, Microsoft Entra ID Governance.
  • Demonstrable ownership of full identity lifecycle design: JML processes, birthright and role-based provisioning, access request and approval, delegated administration, deprovisioning and orphan-account handling.
  • Access governance depth: certification and recertification program design, segregation-of-duties and toxic-combination modeling, role mining and RBAC/ABAC design, entitlement risk rating.
  • Standards fluency: SCIM 2.0, SAML 2.0, OAuth 2.0 / OIDC, LDAP, JWT, and legacy SPML-era integration patterns.
  • Integration breadth across directories and enterprise applications — Active Directory, Entra ID, LDAP, Workday, SAP, ServiceNow, Salesforce, database and mainframe/RACF targets.
  • Working cybersecurity context: least privilege and zero standing privilege, privileged access adjacency, identity attack paths, and the audit drivers behind governance programs (SOX ITGC, HIPAA, PCI DSS, GDPR, NIST 800-53, ISO 27001).
  • Client-facing gravitas at Director and CISO level; disciplined estimation, scoping and written communication.

Responsibilities

  • Own end-to-end solution architecture for IGA engagements: identity model, authoritative source strategy, account correlation logic, entitlement catalog design and the target governance operating model.
  • Act as design authority across the portfolio — review and approve connector designs, lifecycle and provisioning workflows, role models (RBAC/ABAC), SoD rule sets and certification campaign architecture before build starts.
  • Build and lead engineering bench (engineers across US and Pune): staffing to engagements, technical mentoring, code and configuration quality gates, and career development.
  • Own migration strategy and execution for legacy-to-modern IGA moves — IdentityIQ to Identity Security Cloud, homegrown or end-of-life platforms to SailPoint, Saviynt or any similar solution— including coexistence, data migration and cutover sequencing.
  • Design joiner-mover-leaver automation against HR authoritative sources (Workday, SuccessFactors, SAP HCM), including birthright access, contractor and non-employee lifecycle, and emergency deprovisioning paths.
  • Serve as senior technical interface to client IAM Directors, Enterprise Architects and CISO organizations; chair design authority boards and architecture review sessions.
  • Support presales and practice growth: solution shaping, level-of-effort estimation, technical SOW scope, RFP and RFI responses, and proof-of-concept leadership.
  • Own delivery governance across engagements — technical risk register, dependency management, technical debt tracking, and go/no-go recommendations at each gate.
  • Build and curate practice IP: reference architectures, reusable connectors, accelerators, estimation models and design pattern libraries.
  • Maintain vendor technical relationships (SailPoint, Saviynt, Okta, Microsoft) and drive the team certification and partner-tier plan.

Benefits

  • Full-time opportunity
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service