Back to jobs

Staff IAM Engineer

Chicago

DRW is a diversified trading firm with over 3 decades of experience bringing sophisticated technology and exceptional people together to operate in markets around the world. We value autonomy and the ability to quickly pivot to capture opportunities, so we operate using our own capital and trading at our own risk.

Headquartered in Chicago with offices throughout the U.S., Canada, Europe, and Asia, we trade a variety of asset classes including Fixed Income, ETFs, Equities, FX, Commodities and Energy across all major global markets. We have also leveraged our expertise and technology to expand into three non-traditional strategies: real estate, venture capital and cryptoassets.

We operate with respect, curiosity and open minds. The people who thrive here share our belief that it’s not just what we do that matters–it's how we do it. DRW is a place of high expectations, integrity, innovation and a willingness to challenge consensus.

The Team: 

The IAM Team is a net-new, vanguard group that will own, implement, and drive DRW’s comprehensive identity capabilities, aligning them to evolving business requirements. This dedicated group collaborates with stakeholders to advance agentic identity, enhanced authentication and authorization controls, and other emerging identity and security innovations, with potential expansion into customer identity and access management (CIAM). 

The Role: 

We are seeking an experienced Identity Engineer to own the delivery, operation, and continuous improvement of our enterprise authentication and authorization services. The IAM team is responsible for the security, compliance, availability, and user experience of these services; you'll execute implementations, participate in and influence design decisions, and ensure integrations across onprem and cloud environments meet SLAs and control requirements. The role focuses on SSO, federation, MFA, and secure access management. 

Key Responsibilities: 

  • Own, implement, and operate end-to-end enterprise authentication and federation solutions; drive architecture reviews and collaborate to influence design decisions, ensuring security, compliance, availability, and performance. 
  • Implement, configure, and support SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), LDAP, and JWTbased integrations. 
  • Integrate identity solutions with enterprise, thirdparty applications, APIs, SaaS platforms, and custom web/mobile apps, including SSO, provisioning (SCIM/API), and secure API authentication. 
  • Implement MFA, adaptive authentication, finegrained access policies, and authorization models that meet security standards. 
  • Support identity lifecycle and directory integrations with IAM and directory services (e.g., Entra ID/Azure AD, Active Directory, ADFS) and provisioning systems. 
  • Troubleshoot authentication/authorization flows; perform rootcause analysis, incident response, and performance tuning. 
  • Ensure compliance with security, audit, and regulatory requirements and support related assessments. 
  • Collaborate closely with security, infrastructure, application, and DevOps teams to deliver and operate identity services. 
  • Create and maintain runbooks, SOPs, operational procedures, and technical documentation. 

Required Qualifications: 

  • Strong written and verbal communication, stakeholder management, and crossteam collaboration skills. 
  • 5+ years of experience in Identity & Access Management (IAM), or equivalent hands-on experience. 
  • Strong hands-on experience implementing and operating commercial identity platforms and enterprise identity services (Ping AIC and PingFederate preferred, or the ability to implement required features in Ping). 
  • Deep knowledge of SSO, federation, and authentication/authorization protocols (SAML 2.0, OAuth 2.0, OpenID Connect, JWT). 
  • Experience integrating with directory and lifecycle systems (Active Directory/LDAP, Azure AD/Entra ID, ADFS) and provisioning (SCIM/API). 
  • Practical experience with MFA, adaptive authentication, fine-grained authorization, and access policy enforcement. 
  • Strong troubleshooting skills across authentication flows, certificates, TLS, networking, and related infrastructure. 
  • Scripting/automation skills (Shell, Python, Go, PowerShell) and familiarity with IaC/CI-CD tools (Terraform, Ansible, or similar). 
  • Comfortable working in Linux environments and producing operational runbooks and technical documentation. 

Bonus Points: 

  • Experience in banking or financial services (regulated enterprise environments). 
  • Handson cloud experience (AWS, Azure/Entra, or GCP) and container platforms (Docker, Kubernetes). 
  • Experience with API security, OAuth/OIDC for APIs, and zerotrust architectures/use cases. 
  • Practical experience with CIAM or customer identity projects. 
  • Ping Identity certifications or other security/identity certifications. 
    • Observability and monitoring experience for identity services (Prometheus, ELK, Splunk, etc.) 

The annual base salary range for this position is $150,000 to $200,000 depending on the candidate’s experience, qualifications, and relevant skill set. The position is also eligible for an annual discretionary bonus. In addition, DRW offers a comprehensive suite of employee benefits including group medical, pharmacy, dental and vision insurance, 401k (with discretionary employer match), short and long-term disability, life and AD&D insurance, health savings accounts, and flexible spending accounts.

For more information about DRW's processing activities and our use of job applicants' data, please view our Privacy Notice at https://drw.com/privacy-notice.

California residents, please review the California Privacy Notice for information about certain legal rights at https://drw.com/california-privacy-notice.

[#LI-LD1] 

Apply for this job

*

indicates a required field

Phone
Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in DRW ’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...