IAM Engineer
Listed on 2026-09-28
-
IT/Tech
Cybersecurity
DRW is a diversified trading firm with over 3 decades of experience bringing sophisticated technology and exceptional people together to operate in markets around the world. We value autonomy and the ability to quickly pivot to capture opportunities, so we operate using our own capital and trading at our own risk.
Headquartered in Chicago with offices throughout the U.S., Canada, Europe, and Asia, we trade a variety of asset classes including Fixed Income, ETFs, Equities, FX, Commodities and Energy across all major global markets. We have also leveraged our expertise and technology to expand into three non-traditional strategies: real estate, venture capital and cryptoassets.
We operate with respect, curiosity and open minds. The people who thrive here share our belief that it’s not just what we do that matters-it's how we do it.
DRW is a place of high expectations, integrity, innovation and a willingness to challenge consensus.
The IAM Team is a net-new, vanguard groupthat willown, implement, and drive DRW’s comprehensive identity capabilities, aligning them to evolving business requirements. This dedicated group collaborates with stakeholders to advance agentic identity, enhanced authentication and authorization controls, and other emerging identity and security innovations, with potential expansion into customer identity and access management (CIAM).
The Role:We are seeking an experienced Identity Engineer to own the delivery, operation, and continuous improvement of our enterprise authentication and authorization services. The IAM teamis responsibleforthesecurity,compliance, availability, and user experience of these services;you'llexecute implementations,participateinand influence design decisions, and ensure integrations acrosson - premand cloud environments meet SLAs and control requirements. The role focuses on SSO, federation, MFA, and secure access management.
Key Responsibilities:- Own, implement, andoperateend-to-end enterprise authentication and federation solutions; drive architecture reviews and collaborate to influence design decisions , ensuring security, compliance, availability, and performance.
- Implement, configure, and support SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), LDAP, andJWT - basedintegrations.
- Integrate identity solutions with enterprise, third - party applications, APIs, SaaS platforms, and custom web/mobile apps, including SSO, provisioning (SCIM/API), and secure API authentication.
- Implement MFA, adaptive authentication, fine - grained access policies, and authorization models that meet security standards.
- Support identity lifecycle and directory integrations with IAM and directory services (e.g., Entra /Azure AD, Active Directory, ADFS) and provisioning systems.
- Troubleshoot authentication/authorization flows; perform root - cause analysis, incident response, and performance tuning.
- Ensure compliance with security, audit, and regulatory requirements and support related assessments.
- Collaborate closely with security, infrastructure, application, andDevOps teams to deliver andoperateidentity services.
- Create andmaintainrunbooks, SOPs, operational procedures, and technical documentation.
- Strong written and verbal communication, stakeholder management, andcross - teamcollaboration skills.
- 5+ years of experience in Identity & Access Management (IAM), or equivalent hands-on experience.
- Strong hands-on experience implementing andoperatingcommercial identity platforms and enterprise identity services (Ping AIC and Ping Federate preferred, or the ability to implement required features in Ping).
- Deep knowledge of SSO, federation, and authentication/authorization protocols (SAML 2.0, OAuth 2.0, OpenID Connect, JWT).
- Experience integrating with directory and lifecycle systems (Active Directory/LDAP, Azure AD/Entra , ADFS) and provisioning (SCIM/API).
- Practical experience with MFA, adaptive authentication, fine-grained authorization, and access policy enforcement.
- Strong troubleshooting skills across authentication flows, certificates, TLS, networking, and related infrastructure.
- Scripting/automation skills (Shell, Python, Go, Power Shell) and familiarity with
IaC/CI-CD tools (Terraform, Ansible, or similar). - Comfortable working in Linux environments and producing operational runbooks and technical documentation.
- Experience in banking or financial services (regulated enterprise environments).
- Hands - oncloud experience (AWS, Azure/Entra, or GCP) and container platforms (Docker,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).