Back to jobs

SENIOR SOFTWARE ENGINEER

Gruve
Full-timesenior€180,000-200,000/year
Sign in to applyFree account, takes a minute.

Job description

<div class="content-intro"><p><strong>About Gruve</strong></p> <p>Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.</p></div><p><strong>About the Role</strong></p> <p>Gruve is looking to hire a Senior Software Engineer with <span class="TextRun SCXW204898893 BCX8" lang="EN-US" data-contrast="none"><span class="NormalTextRun SCXW204898893 BCX8">Hands-on builder on IGA/IAM engagements. Develops the connectors, lifecycle workflows, rules and integrations that turn an approved identity design into working platform behavior — and stands behind them through UAT, cutover and </span><span class="NormalTextRun SCXW204898893 BCX8">hypercare</span><span class="NormalTextRun SCXW204898893 BCX8">.</span></span><span class="EOP Selected SCXW204898893 BCX8" data-ccp-props="{"201341983":0,"335559739":100,"335559740":264}"> </span></p> <p><strong>Key Responsibilities</strong></p> <ul> <li><span data-contrast="auto">Build and extend IGA connectors for target applications — out-of-box, configured and fully custom — across SCIM, REST, SOAP, JDBC, LDAP, PowerShell and flat-file integration patterns.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Develop identity lifecycle logic: joiner-mover-leaver workflows, provisioning and deprovisioning policies, birthright access rules, and platform rules (BeanShell/Java in IdentityIQ, Saviynt configuration and jobs, Okta Workflows, PowerShell and Microsoft Graph for Entra ID).</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Implement access request catalogs, approval and escalation workflows, and access certification campaigns including reviewer models and closed-loop revocation.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Build aggregation, correlation and entitlement normalization logic; develop data-quality and role-mining support pipelines against messy source data.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Integrate the platform with ServiceNow ITSM for ticketed fulfilment and with HR systems (Workday, SuccessFactors) as authoritative identity sources.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Configure federation and authentication integrations: SAML and OIDC application onboarding, MFA and adaptive access policy implementation, directory integration.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Write unit and integration tests, participate in peer code review, and maintain deployment artifacts through the practice CI/CD pipeline.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Support UAT execution, defect triage and root-cause analysis; own assigned defects through closure during cutover and hypercare windows.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Produce build documentation, configuration records and knowledge-transfer material to a standard the client can operate against post-go-live.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Contribute reusable connectors and accelerators back into the practice IP library.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> </ul> <p><strong>Basic Qualifications</strong></p> <ul> <li><span data-contrast="auto">Vendor certification — SailPoint Certified Engineer, Saviynt L200/L300, Okta Certified Developer, or industry equivalent.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Cloud identity services on Azure, AWS or GCP; Kubernetes and containerized deployment basics.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Exposure to PAM integration (CyberArk, Delinea) or ITDR/ISPM tooling.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Specialized target experience — SAP GRC, mainframe/RACF, Epic or Cerner in healthcare, or core banking platforms.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Experience on a legacy-to-modern IGA migration.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Regulated-environment platform delivery — FedRAMP, HITRUST or PCI-scoped estates.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> </ul> <p><strong>Preferred Qualifications</strong></p> <ul> <li><span data-contrast="auto">6–8+ years of software engineering, with at least 4 years building on IGA/IAM platforms.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Hands-on connector and workflow development on at least one of SailPoint IdentityIQ / ISC, Saviynt EIC, Okta, or Microsoft Entra ID.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Strong Java (including BeanShell), .NET, and/or Python and PowerShell; solid SQL against identity and entitlement data.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">REST and SOAP API integration; SCIM 2.0 provisioning; LDAP and Active Directory schema fluency.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Practical understanding of core IGA concepts — identity lifecycle, entitlements, roles, aggregation and correlation, access requests, certification, orphan and dormant accounts.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Federation fundamentals: SAML 2.0 and OAuth 2.0 / OIDC flows, token handling, application onboarding.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Secure engineering hygiene — secrets and credential handling, secure coding against OWASP Top 10, TLS and certificate basics, and an understanding of why an over-permissioned connector is a security finding.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Git-based workflow and active participation in CI/CD-driven delivery.</span><span data-ccp-props="{"201341983":0,"335559739":60,"335559740":264}"> </span></li> <li><span data-contrast="auto">Clear written English for design notes, defect records and client-facing documentation. </span></li> </ul> <p><strong>Salary Range</strong> <br><br>$180k - $200k <br><br><em><strong>This is a full-time opportunity with Gruve.</strong></em></p> <p></p><div class="content-conclusion"><p><strong>Why Gruve</strong></p> <p>At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.</p> <p>Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.</p></div>