DEVOPS DIRECTOR
Gruve
Full-timemid€200,000-230,000/year
Sign in to applyFree account, takes a minute.
Job description
<div class="content-intro"><p><strong>About Gruve</strong></p>
<p>Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.</p></div><p><strong>About the Role</strong></p>
<p><span class="TextRun SCXW132507984 BCX8" lang="EN-US" data-contrast="none"><span class="NormalTextRun SCXW132507984 BCX8">Owns the engineering platform beneath every IGA/IAM engagement: environments, pipelines, infrastructure-as-code, and the secure operation of identity platforms in client and Gruve-hosted estates. Also owns the identity of the delivery chain itself — the service accounts, workload identities, secrets and certificates that identity platforms run on and that auditors ask about first.</span></span><span class="EOP Selected SCXW132507984 BCX8" data-ccp-props="{"201341983":0,"335559739":100,"335559740":264}"> </span></p>
<p><strong>Key Responsibilities</strong></p>
<ul>
<li><span data-contrast="auto">Own environment strategy across the portfolio: development, test, UAT and production estates for IGA platforms, including refresh cadence, data masking and anonymization of production identity data in lower environments.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
<li><span data-contrast="auto">Build and govern CI/CD for identity artifacts — configuration-as-code promotion, object versioning and packaging for SailPoint, Saviynt, and Okta, automated deployment, drift detection and rollback.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
<li><span data-contrast="auto">Own infrastructure-as-code (Terraform, Ansible) for identity platform infrastructure and containerized deployment on Kubernetes (EKS/AKS/GKE).</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
<li><span data-contrast="auto">Own secrets and non-human identity management across the practice: vaulting, workload identity federation, service-account and API-key lifecycle, and certificate and PKI lifecycle for connector and federation endpoints.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
<li><span data-contrast="auto">Design and validate platform reliability for identity workloads: HA and DR architecture, RPO/RTO validation, and capacity and performance tuning for aggregation cycles, certification campaigns and peak provisioning load.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
<li><span data-contrast="auto">Secure the delivery chain: SAST/DAST and dependency scanning in the pipeline, SBOM generation, artifact signing, and least-privilege pipeline and repository access.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
<li><span data-contrast="auto">Stand up observability for identity platforms — provisioning failure rates, aggregation SLA, connector health, task and workflow queue depth — and route identity audit logs into the client SIEM.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
<li><span data-contrast="auto">Lead the DevOps and platform engineering team across US and Pune; set engineering standards, chair change advisory for platform changes, and own audit evidence for client and internal audit.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
<li><span data-contrast="auto">Partner with the Principal Engineering Manager on architecture decisions with platform impact, and support presales for hosting, managed-service and platform-modernization scope.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
<li><span data-contrast="auto">Own platform upgrade and patch strategy across client estates, including vendor release tracking, regression risk assessment and coordinated upgrade windows.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
</ul>
<p><strong>Basic Qualifications</strong></p>
<ul>
<li><span data-contrast="auto">CKA/CKAD, HashiCorp Terraform Associate, or Azure/AWS Solutions Architect certification.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
<li><span data-contrast="auto">CISSP or CCSP.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
<li><span data-contrast="auto">SRE practice — SLI/SLO definition, error budgets, chaos and DR testing.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
<li><span data-contrast="auto">Zero Trust architecture, ZTNA and micro segmentation experience.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
<li><span data-contrast="auto">Experience running a hosted or managed identity service with contractual SLAs.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
</ul>
<p><strong>Preferred Qualifications</strong></p>
<ul>
<li><span data-contrast="auto">10–15+ years in infrastructure, platform or DevOps engineering, including 5+ years leading teams and 4+ years supporting IAM/IGA or comparable security platforms.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
<li><span data-contrast="auto">Deep CI/CD ownership (Azure DevOps, GitHub Actions or Jenkins) and infrastructure-as-code (Terraform, Ansible) at enterprise scale.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
<li><span data-contrast="auto">Kubernetes depth and strong cloud platform experience on Azure and/or AWS or GCP, including cloud IAM models and workload identity federation.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
<li><span data-contrast="auto">Hands-on operation of identity platforms — deployment, upgrade, patching, HA/DR and performance tuning for SailPoint, Saviynt, Okta or Entra ID.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
<li><span data-contrast="auto">Secrets management and machine/workload identity: HashiCorp Vault or cloud KMS, service-account governance, and PKI and certificate lifecycle management.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
<li><span data-contrast="auto">Security controls and audit evidence: CIS benchmarks, system hardening, vulnerability and patch management, and mapping platform controls to NIST 800-53, SOC 2, ISO 27001 or SOX ITGC.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
<li><span data-contrast="auto">Understanding of the identity domain the platform serves — provisioning, aggregation, certification and federation — sufficient to design environments and pipelines that fit how IGA actually behaves.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
<li><span data-contrast="auto">Director-level client interface and experience managing distributed US/India teams across time zones.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li>
</ul>
<p><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"><strong>Salary Range</strong><br><br>$200k - $230k USD<br><br><em><strong>This is a full-time opportunity with Gruve.</strong></em><br></span></p>
<p></p><div class="content-conclusion"><p><strong>Why Gruve</strong></p>
<p>At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.</p>
<p>Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.</p></div>