Senior Software Engineer

Gruve
$180,000 - $200,000

About The Position

Gruve is looking to hire a Senior Software Engineer with Hands-on builder on IGA/IAM engagements. Develops the connectors, lifecycle workflows, rules and integrations that turn an approved identity design into working platform behavior — and stands behind them through UAT, cutover and hypercare.

Requirements

  • Vendor certification — SailPoint Certified Engineer, Saviynt L200/L300, Okta Certified Developer, or industry equivalent.
  • Cloud identity services on Azure, AWS or GCP; Kubernetes and containerized deployment basics.
  • Exposure to PAM integration (CyberArk, Delinea) or ITDR/ISPM tooling.
  • Specialized target experience — SAP GRC, mainframe/RACF, Epic or Cerner in healthcare, or core banking platforms.
  • Experience on a legacy-to-modern IGA migration.
  • Regulated-environment platform delivery — FedRAMP, HITRUST or PCI-scoped estates.
  • 6–8+ years of software engineering, with at least 4 years building on IGA/IAM platforms.
  • Hands-on connector and workflow development on at least one of SailPoint IdentityIQ / ISC, Saviynt EIC, Okta, or Microsoft Entra ID.
  • Strong Java (including BeanShell), .NET, and/or Python and PowerShell; solid SQL against identity and entitlement data.
  • REST and SOAP API integration; SCIM 2.0 provisioning; LDAP and Active Directory schema fluency.
  • Practical understanding of core IGA concepts — identity lifecycle, entitlements, roles, aggregation and correlation, access requests, certification, orphan and dormant accounts.
  • Federation fundamentals: SAML 2.0 and OAuth 2.0 / OIDC flows, token handling, application onboarding.
  • Secure engineering hygiene — secrets and credential handling, secure coding against OWASP Top 10, TLS and certificate basics, and an understanding of why an over-permissioned connector is a security finding.
  • Git-based workflow and active participation in CI/CD-driven delivery.
  • Clear written English for design notes, defect records and client-facing documentation.

Responsibilities

  • Build and extend IGA connectors for target applications — out-of-box, configured and fully custom — across SCIM, REST, SOAP, JDBC, LDAP, PowerShell and flat-file integration patterns.
  • Develop identity lifecycle logic: joiner-mover-leaver workflows, provisioning and deprovisioning policies, birthright access rules, and platform rules (BeanShell/Java in IdentityIQ, Saviynt configuration and jobs, Okta Workflows, PowerShell and Microsoft Graph for Entra ID).
  • Implement access request catalogs, approval and escalation workflows, and access certification campaigns including reviewer models and closed-loop revocation.
  • Build aggregation, correlation and entitlement normalization logic; develop data-quality and role-mining support pipelines against messy source data.
  • Integrate the platform with ServiceNow ITSM for ticketed fulfilment and with HR systems (Workday, SuccessFactors) as authoritative identity sources.
  • Configure federation and authentication integrations: SAML and OIDC application onboarding, MFA and adaptive access policy implementation, directory integration.
  • Write unit and integration tests, participate in peer code review, and maintain deployment artifacts through the practice CI/CD pipeline.
  • Support UAT execution, defect triage and root-cause analysis; own assigned defects through closure during cutover and hypercare windows.
  • Produce build documentation, configuration records and knowledge-transfer material to a standard the client can operate against post-go-live.
  • Contribute reusable connectors and accelerators back into the practice IP library.

Benefits

  • This is a full-time opportunity with Gruve.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service