Staff IAM Engineer

DRW Holdings, LLC.

Chicago (IL)

On-site

USD 150,000 - 200,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Group medical insurance
Dental and vision insurance
401k with discretionary employer match
Short and long-term disability
Life and AD&D insurance
Health savings accounts
Flexible spending accounts

Job summary

DRW, a Chicago-based diversified trading firm, is seeking an experienced Identity Engineer to own the delivery, operation, and continuous improvement of our enterprise authentication and authorization services. The IAM team will focus on SSO, federation, MFA, and secure access management across on-prem and cloud environments, collaborating with security, infrastructure, application, and DevOps teams.

You will implement and operate SAML, OAuth, OIDC, LDAP integrations, maintain runbooks, and

Qualifications

  • 5+ years of IAM experience or equivalent hands-on work.
  • Experience with commercial identity platforms (Ping Identity products) and enterprise IAM services.
  • Deep knowledge of SSO, federation, and authentication protocols (SAML 2.0, OAuth 2.0, OIDC, JWT).
  • Experience with directory and lifecycle systems (AD/LDAP, Azure AD/Entra ID, ADFS) and provisioning (SCIM/API).
  • Experience with MFA, adaptive authentication, and access policy enforcement.
  • Strong troubleshooting across authentication flows, certificates, TLS, networking, and related infra.
  • Scripting/automation skills and familiarity with IaC/CI-CD tools; Linux proficiency.

Responsibilities

  • Own, implement, and operate end-to-end enterprise authentication and federation solutions.
  • Drive architecture reviews and influence design decisions for security and availability.
  • Configure and support SAML 2.0, OAuth 2.0, OIDC, LDAP, and JWT-based integrations.
  • Integrate identity with APIs, SaaS platforms, and custom apps including SSO and provisioning.
  • Implement MFA and fine-grained authorization policies.
  • Collaborate with security, infrastructure, and DevOps teams to run identity services.
  • Create runbooks and technical documentation.
  • Troubleshoot and perform root-cause analysis of auth issues.

Skills

IAM expertise
SSO & federation
SAML/OIDC/OAuth
MFA/adaptive authentication
Directory integration
Scripting/automation
IaC/CI-CD
Linux administration

Tools

Ping Federate
Ping Directory
Azure AD Entra ID
ADFS
Terraform
Ansible
Docker
Kubernetes
Prometheus
ELK / Splunk

Job description

DRW is a diversified trading firm with over 3 decades of experience bringing sophisticated technology and exceptional people together to operate in markets around the world. We value autonomy and the ability to quickly pivot to capture opportunities, so we operate using our own capital and trading at our own risk.

Headquartered in Chicago with offices throughout the U.S., Canada, Europe, and Asia, we trade a variety of asset classes including Fixed Income, ETFs, Equities, FX, Commodities and Energy across all major global markets. We have also leveraged our expertise and technology to expand into three non-traditional strategies: real estate, venture capital and cryptoassets.

We operate with respect, curiosity and open minds. The people who thrive here share our belief that it’s not just what we do that matters-it's how we do it. DRW is a place of high expectations, integrity, innovation and a willingness to challenge consensus.

The Team:

The IAM Team is a net-new, vanguard groupthat willown, implement, and drive DRW’s comprehensive identity capabilities, aligning them to evolving business requirements. This dedicated group collaborates with stakeholders to advance agentic identity, enhanced authentication and authorization controls, and other emerging identity and security innovations, with potential expansion into customer identity and access management (CIAM).

The Role:

We are seeking an experienced Identity Engineer to own the delivery, operation, and continuous improvement of our enterprise authentication and authorization services. The IAM teamis responsibleforthesecurity,compliance, availability, and user experienceof these services;you'llexecute implementations,participateinand influencedesign decisions, and ensure integrations acrosson - premand cloud environments meet SLAs and control requirements. The role focuses on SSO, federation, MFA, and secure access management.

Key Responsibilities:
  • Own, implement, andoperateend-to-end enterprise authentication and federation solutions; drive architecture reviews and collaborate to influence design decisions , ensuring security, compliance, availability, and performance.
  • Implement, configure, and support SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), LDAP, andJWT - basedintegrations.
  • Integrate identity solutions with enterprise, third - partyapplications, APIs, SaaS platforms, and custom web/mobile apps, including SSO, provisioning (SCIM/API), and secure API authentication.
  • Implement MFA, adaptive authentication, fine - grainedaccess policies, and authorization models that meet security standards.
  • Support identity lifecycle and directory integrations with IAM and directory services (e.g., Entra ID/Azure AD, Active Directory, ADFS) and provisioning systems.
  • Troubleshoot authentication/authorization flows; performroot - causeanalysis, incident response, and performance tuning.
  • Ensure compliance with security, audit, and regulatory requirements and support related assessments.
  • Collaborate closely with security, infrastructure, application, andDevOps teams to deliver andoperateidentity services.
  • Create andmaintainrunbooks, SOPs, operational procedures, and technical documentation.
Required Qualifications:
  • Strongwritten and verbal communication, stakeholder management, andcross - teamcollaboration skills.
  • 5+ years of experience in Identity & Access Management (IAM), or equivalent hands-on experience.
  • Strong hands-on experience implementing andoperatingcommercial identityplatforms andenterprise identity services (Ping AIC and PingFederate preferred, or the ability to implement required features in Ping).
  • Deep knowledge of SSO, federation, and authentication/authorization protocols (SAML 2.0, OAuth 2.0, OpenID Connect, JWT).
  • Experience integrating with directory and lifecycle systems (Active Directory/LDAP, Azure AD/Entra ID, ADFS) and provisioning (SCIM/API).
  • Practical experience with MFA, adaptive authentication, fine-grained authorization, and access policy enforcement.
  • Strong troubleshooting skills across authentication flows, certificates, TLS, networking, and related infrastructure.
  • Scripting/automation skills (Shell, Python, Go, PowerShell) and familiarity withIaC/CI-CD tools (Terraform, Ansible, or similar).
  • Comfortable working in Linux environments and producing operational runbooks and technical documentation.
Bonus Points:
  • Experience in banking or financial services (regulated enterprise environments).
  • Hands - oncloud experience (AWS, Azure/Entra, or GCP) and container platforms (Docker, Kubernetes).
  • Experience with API security, OAuth/OIDC for APIs, andzero - trustarchitectures/use cases.
  • Practical experience with CIAM or customer identity projects.
  • Ping Identity certifications or other security/identity certifications.
  • Observability and monitoring experience for identity services (Prometheus, ELK, Splunk, etc.).

The annual base salary range for this position is $150,000 to $200,000 depending on the candidate’s experience, qualifications, and relevant skill set. The position is also eligible for an annual discretionary bonus. In addition, DRW offers a comprehensive suite of employee benefits including group medical, pharmacy, dental and vision insurance, 401k (with discretionary employer match), short and long-term disability, life and AD&D insurance, health savings accounts, and flexible spending accounts.

For more information about DRW's processing activities and our use of job applicants' data, please view our Privacy Notice at https://drw.com/privacy-notice .

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff IAM Engineer
Staff IAM Engineer

P2P • Chicago (IL)

On-site
USD 150,000 - 200,000
Group medical insurance
Dental insurance
Vision insurance
+5
Staff IAM Engineer
Staff IAM Engineer

DRW • Chicago (IL)

On-site
USD 150,000 - 200,000
Senior IAM Engineer — SSO, MFA & Cloud Identity
Senior IAM Engineer — SSO, MFA & Cloud Identity

DRW Holdings, LLC. • Chicago (IL)

On-site
USD 150,000 - 200,000
Group medical insurance
Dental and vision insurance
401k with discretionary employer match
+4
Systems Engineer - Microsoft
Systems Engineer - Microsoft

DRW Holdings, LLC. • Chicago (IL)

On-site
USD 120,000 - 160,000
Medical, dental, vision insurance
401k with discretionary employer match
Disability insurance (short/long-term)
+2
Senior Identity Engineer — SSO, MFA & Cloud IAM
Senior Identity Engineer — SSO, MFA & Cloud IAM

P2P • Chicago (IL)

On-site
USD 150,000 - 200,000
Group medical insurance
Dental insurance
Vision insurance
+5
Systems Engineer - Microsoft
Systems Engineer - Microsoft

P2P • Chicago (IL)

On-site
USD 120,000 - 160,000
401k with employer match
Medical insurance
Dental insurance
+3
Senior Project Manager - Infrastructure & Operations
Senior Project Manager - Infrastructure & Operations

DRW • Chicago (IL)

On-site
USD 160,000 - 200,000
Group medical insurance
Dental and vision insurance
401k with discretionary match
+4
Systems Engineer - Microsoft
Systems Engineer - Microsoft

Precision Labs • Chicago (IL), Northern (KY)

Hybrid
USD 120,000 - 160,000
Senior Project Manager - Infrastructure & Operations
Senior Project Manager - Infrastructure & Operations

Drweng • Chicago (IL)

On-site
USD 160,000 - 200,000
Sr. IAM Engineer
Sr. IAM Engineer

IDMWORKS • Oregon (WI)

Hybrid
USD 115,000 - 160,000