IAM Engineer

Candidate Experience site

Bengaluru

On-site

INR 2,800,000 - 4,400,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Tradeweb Markets LLC is seeking a Senior IAM Engineer to design and operate CIAM capabilities for client-facing apps in a globally distributed environment. You will implement federation using OIDC/OAuth 2.0, SAML as needed, and drive secure, scalable authentication strategies.

You will partner with product and engineering to standardize identity patterns, enforce strong authentication, and support audits and compliance in financial services contexts.

Qualifications

  • 5+ years of Identity and Access Management experience with strong SSO and modern authentication.
  • Hands-on with OIDC and OAuth 2.0 (and SAML where required).
  • Experience designing end-to-end CIAM journeys (registration, login, recovery).
  • Ability to implement MFA, conditional access, and secure session management.
  • Familiarity with SOX/ISO 27001/NIST in regulated environments.

Responsibilities

  • Design, implement, and operate CIAM capabilities for client-facing apps.
  • Build federated authentication and authorization using OIDC/OAuth 2.0 and SAML.
  • Own identity flows including registration, login, and account recovery.
  • Implement strong authentication patterns and risk-based access controls.
  • Support provisioning patterns like JIT and SCIM for ecosystems.
  • Define CIAM security standards and monitor for compliance and audits.
  • Collaborate with product/engineering to embed identity into architecture.
  • Troubleshoot production auth issues and drive durable fixes.
  • Produce technical docs and runbooks for CIAM integrations.

Skills

OIDC & OAuth 2.0
SAML
CIAM design
MFA / step-up
SCIM provisioning
JIT provisioning
Token/claims design
PKCE & JWKS
Troubleshooting auth
Security & compliance

Education

Bachelor’s degree in Information Systems, Computer Science, Cybersecurity, or related field

Tools

Confluence
Lucidchart/Visio
SQL
PowerShell

Job description

Company Description

Tradeweb Markets is a world leader in the evolution of electronic trading. A fintech company serving approximately 2,500 clients – including the world’s largest banks, asset managers, hedge funds, insurance companies, wealth managers and retail clients -- in more than 65 countries across the globe. Since our first trade in 1998, we have helped transform and electronify the fixed income markets. Tradeweb is a culture built on innovation, creativity and collaboration. Through a combination of very talented and driven people, innovative products and solutions, cutting-edge technology, market data, and a vast network of clients, we continue to work together to improve the way financial markets trade.

Mission: Move first and never stop. Collaborate with clients to create and build solutions that drive efficiency, connectivity, and transparency in electronic trading.

Tradeweb Markets LLC ("Tradeweb") is proud to be an EEO Minorities/Females/Protected Veterans/Disabled/Affirmative Action Employer.
https://www.dol.gov/ofccp/regs/compliance/posters/pdf/eeopost.pdf

Group Details:

To support our continued growth, we are seeking a results-driven Senior IAM Engineer to join our Identity & Access Management team. This role will engineer and support client identity and authentication capabilities for the products our clients use, delivering secure, scalable, and auditable access.

The ideal candidate will design, implement, and troubleshoot client authentication and federation integrations using SAML 2.0, OIDC, and OAuth 2.0, including hands-on details such as claims/token design, JWKS and key rotation, session management, and secure integration patterns.

You will partner closely with product and engineering teams to standardize authentication and authorization approaches, implement conditional access and MFA/step-up authentication, and support JIT/SCIM provisioning where applicable. You will drive reliability improvements, resolve complex federation issues, and ensure solutions meet security and compliance requirements. Financial services experience and familiarity with SOX/GLBA/FFIEC are strongly preferred.

Job Responsibilities:
  • Design, implement, and operate CIAM capabilities for client-facing applications, balancing security, scalability, and user experience.
  • Build and support federated authentication and authorization using OIDC and OAuth 2.0 (and SAML where required), including client configuration, scopes, consent, redirect URI strategy, and token/claims design.
  • Own client identity flows such as registration, login, account linking, progressive profiling, and self-service account recovery, including secure handling of email/phone verification.
  • Implement strong authentication patterns for clients, including MFA, step-up authentication, risk-based/conditional access, and session management controls.
  • Integrate applications using modern provisioning and identity lifecycle patterns such as JIT provisioning and SCIM where applicable to client/partner ecosystems.
  • Define and enforce CIAM security standards: secure token lifetimes/refresh strategies, PKCE, key rotation/JWKS, secrets management, and protection against common auth attacks (replay, token theft, redirect abuse).
  • Partner with product and engineering teams to standardize CIAM integration patterns and embed identity into application architecture (roles/permissions, fine-grained authorization, and least privilege).
  • Troubleshoot complex production issues across the auth stack (tokens, redirects, cookies/sessions, upstream IdPs), drive root-cause analysis, and implement durable fixes.
  • Instrument and monitor CIAM services and client auth journeys (logging, metrics, alerting), improving reliability, latency, and conversion while maintaining security.
  • Produce and maintain technical documentation and runbooks for CIAM integrations and operational processes, supporting audits and incident response.
  • Support compliance and risk requirements by enabling evidence collection and reporting around authentication events, policy enforcement, and access anomalies.
Required Qualifications
  • Bachelor’s degree in Information Systems, Computer Science, Cybersecurity, or a related field (or equivalent practical experience).
  • 5+ years of experience in Identity and Access Management, with strong expertise in SSO and modern authentication for client-facing applications.
  • Strong, hands-on experience with OIDC and OAuth 2.0 (and SAML where required), including token/claims design, scopes, PKCE, redirect URI strategy, and key management (JWKS, rotation).
  • Experience designing and implementing end-to-end CIAM journeys: registration, login, account recovery, progressive profiling, and account linking.
  • Experience implementing modern authentication controls such as MFA, step-up authentication, conditional/risk-based access, and secure session management.
  • Working knowledge of user lifecycle automation patterns for client/partner ecosystems, including JIT provisioning and SCIM where applicable.
  • Ability to troubleshoot complex identity issues across distributed systems (cookies/sessions, redirects, tokens, upstream IdPs), perform root-cause analysis, and drive durable remediation.
  • Familiarity with security and compliance expectations in regulated environments (e.g., SOX, ISO 27001, NIST, GLBA) and how they influence authentication, logging, and access controls.
  • Strong written and verbal communication skills, with the ability to translate between product, engineering, security, and compliance stakeholders.
  • Experience producing clear technical documentation and diagrams (e.g., Confluence, Lucidchart/Visio), including integration runbooks, sequence flows, and configuration standards.
  • Highly organized and detail-oriented, with the ability to manage multiple concurrent integrations and production support priorities.
Preferred Qualifications
  • Proven experience leading or significantly contributing to enterprise-scale SSO/authentication initiatives, including rollout planning, migration/cutover strategies, and production hardening.
  • Deep hands-on experience implementing and operating complex federation patterns, including custom OIDC/OAuth configurations (scopes, policies, claims), SAML metadata/certificate management, and advanced sign-in policies (conditional access, step-up/MFA).
  • Experience designing and implementing authorization frameworks, including RBAC/ABAC, policy-based access control, permission modeling, and standards such as OAuth scopes, OIDC claims, and (where applicable) UMA or OPA-style policy engines.
  • Strong proficiency in scripting or programming for IAM/SSO automation and troubleshooting, using languages such as Python or Go, as well as tools like SQL or PowerShell (e.g., log analysis, token/claim validation, configuration automation).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IAM Engineer
IAM Engineer

Tradeweb • Bengaluru

On-site
INR 1,200,000 - 1,600,000
IAM Engineer
IAM Engineer

Luxoft • Bengaluru

On-site
INR 2,200,000 - 3,800,000
Analyst - IAM SSO Engineer
Analyst - IAM SSO Engineer

PepsiCo • Hyderabad

On-site
INR 1,400,000 - 2,100,000
Senior IAM Consultant / IAM Architect
Senior IAM Consultant / IAM Architect

Alignity Solutions • Hyderabad

Hybrid
INR 1,500,000 - 2,300,000
IAM Consultant
IAM Consultant

Kiya.ai • Hyderabad, Bengaluru

Hybrid
INR 2,500,000 - 4,000,000
Senior Okta IGA / IAM Engineer
Senior Okta IGA / IAM Engineer

Code Vyasa • Bengaluru

On-site
INR 2,500,000 - 4,000,000
CyberSecurity Architect - IAM
CyberSecurity Architect - IAM

Cognizant • Chennai District

On-site
INR 3,500,000 - 6,000,000
Senior Lead – Access Management
Senior Lead – Access Management

Northern Trust • Pune District

On-site
INR 3,000,000 - 4,200,000
Senior IAM Engineer (Okta, CyberArk/OneLogin & DevOps)
Senior IAM Engineer (Okta, CyberArk/OneLogin & DevOps)

Luxoft • Bengaluru

On-site
INR 2,500,000 - 4,200,000
Full Stack Lead
Full Stack Lead

AHEAD • Gurugram District

On-site
INR 2,400,000 - 4,200,000