DRW

Staff IAM Engineer

DRW$150K — $200K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Expertise in modern identity protocols (OIDC, OAuth 2.0, SAML) and applied cryptography (JWT, JWKS, RS256).
  • Proficient software or systems engineer with skills in Infrastructure as Code (IaC) and programming languages (preferably Go and Python).
  • Understanding of machine identity paradigms such as HashiCorp Vault and AWS IAM Roles.
  • Ability to manage diverse stakeholders, particularly translating technicalities for non-engineering audiences.
  • Experience addressing legacy technical debt and utilizing Identity-Aware Proxies (IAPs) in migrations.
  • Strong system design skills, respected by senior engineers in fast-paced environments.
  • Strategic thinker capable of aligning technical solutions with compliance requirements.

Responsibilities

  • Design and oversee the migration architecture for a modern enterprise IdP.
  • Lead hands-on efforts in coding, API configuration, and proof of concept development.
  • Serve as the primary technical authority during vendor evaluations and POC testing.
  • Create zero-trust token exchange architectures for internal APIs and microservices.
  • Act as a technical intermediary between security, compliance, and engineering teams, translating risks into actionable requirements.
  • Collaborate with engineering and security teams to integrate identities into internal applications.

Benefits

  • Comprehensive medical, pharmacy, dental, and vision insurance.
  • 401k plan with discretionary employer match.
  • Short and long-term disability insurance.
  • Life and AD&D insurance.
  • Health savings and flexible spending accounts.
Full Job Description
The Team:

The IAM Team is a net-new, vanguard group that will own, implement, and drive DRW's comprehensive identity capabilities, aligning them to evolving business requirements. This dedicated group collaborates with stakeholders to advance agentic identity, enhanced authentication and authorization controls, and other emerging identity and security innovations, with potential expansion into customer identity and access management (CIAM).

The Role:

We are seeking an experienced Identity Engineer to own the delivery, operation, and continuous improvement of our enterprise authentication and authorization services. The IAM team is responsible for the security, compliance, availability, and user experience of these services; you'll execute implementations, participate in and influence design decisions, and ensure integrations across on-prem and cloud environments meet SLAs and control requirements. The role focuses on SSO, federation, MFA, and secure access management.

Key Responsibilities:
  • Own, implement, and operate end-to-end enterprise authentication and federation solutions; drive architecture reviews and collaborate to influence design decisions, ensuring security, compliance, availability, and performance.
  • Implement, configure, and support SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), LDAP, and JWT-based integrations.
  • Integrate identity solutions with enterprise, third-party applications, APIs, SaaS platforms, and custom web/mobile apps, including SSO, provisioning (SCIM/API), and secure API authentication.
  • Implement MFA, adaptive authentication, fine-grained access policies, and authorization models that meet security standards.
  • Support identity lifecycle and directory integrations with IAM and directory services (e.g., Entra ID/Azure AD, Active Directory, ADFS) and provisioning systems.
  • Troubleshoot authentication/authorization flows; perform root-cause analysis, incident response, and performance tuning.
  • Ensure compliance with security, audit, and regulatory requirements and support related assessments.
  • Collaborate closely with security, infrastructure, application, and DevOps teams to deliver and operate identity services.
  • Create and maintain runbooks, SOPs, operational procedures, and technical documentation.

Required Qualifications:
  • Strong written and verbal communication, stakeholder management, and cross-team collaboration skills.
  • 5+ years of experience in Identity & Access Management (IAM), or equivalent hands-on experience.
  • Strong hands-on experience implementing and operating commercial identity platforms and enterprise identity services (Ping AIC and PingFederate preferred, or the ability to implement required features in Ping).
  • Deep knowledge of SSO, federation, and authentication/authorization protocols (SAML 2.0, OAuth 2.0, OpenID Connect, JWT).
  • Experience integrating with directory and lifecycle systems (Active Directory/LDAP, Azure AD/Entra ID, ADFS) and provisioning (SCIM/API).
  • Practical experience with MFA, adaptive authentication, fine-grained authorization, and access policy enforcement.
  • Strong troubleshooting skills across authentication flows, certificates, TLS, networking, and related infrastructure.
  • Scripting/automation skills (Shell, Python, Go, PowerShell) and familiarity with IaC/CI-CD tools (Terraform, Ansible, or similar).
  • Comfortable working in Linux environments and producing operational runbooks and technical documentation.

Bonus Points:
  • Experience in banking or financial services (regulated enterprise environments).
  • Hands-on cloud experience (AWS, Azure/Entra, or GCP) and container platforms (Docker, Kubernetes).
  • Experience with API security, OAuth/OIDC for APIs, and zero-trust architectures/use cases.
  • Practical experience with CIAM or customer identity projects.
  • Ping Identity certifications or other security/identity certifications.
    • Observability and monitoring experience for identity services (Prometheus, ELK, Splunk, etc.)


The annual base salary range for this position is $150,000 to $200,000 depending on the candidate's experience, qualifications, and relevant skill set. The position is also eligible for an annual discretionary bonus. In addition, DRW offers a comprehensive suite of employee benefits including group medical, pharmacy, dental and vision insurance, 401k (with discretionary employer match), short and long-term disability, life and AD&D insurance, health savings accounts, and flexible spending accounts.

[#LI-LD1]

About DRW

DRW is a financial trading firm that specializes in derivatives trading. The company was founded in 1992 by Don Wilson and has since grown to have offices in Chicago, London, Montreal, New York, and Singapore. DRW trades a variety of financial instruments, including futures, options, and cryptocurrencies. The company is known for its quantitative trading strategies and has developed a number of proprietary trading systems. DRW is also involved in venture capital and has invested in a number of technology startups.
Learn more about DRW
Size
1,000 employees
Industry
Founded
1992

Similar Jobs

More Jobs at DRW

More Information Technology Jobs

Find similar Staff IAM Engineer jobs: