DRW is a diversified trading firm with over three decades of experience bringing sophisticated technology and exceptional people together to operate in markets around the world. We value autonomy and the ability to quickly pivot to capture opportunities, so we operate using our own capital and trade at our own risk.
Headquartered in Chicago with offices throughout the U.S., Canada, Europe, and Asia, we trade a variety of asset classes, including Fixed Income, ETFs, Equities, FX, Commodities, and Energy, across all major global markets. We have also leveraged our expertise and technology to expand into real estate, venture capital, and cryptoassets.
We operate with respect, curiosity, and open minds. The people who thrive here share our belief that it is not just what we do that matters—it is how we do it. DRW is a place of high expectations, integrity, innovation, and a willingness to challenge consensus.
The Team:
The IAM Team is a new, vanguard group that will own, implement, and drive DRW’s comprehensive identity capabilities, aligning them with evolving business requirements. This dedicated group collaborates with stakeholders to advance agentic identity, enhanced authentication and authorization controls, and other emerging identity and security innovations, with potential expansion into customer identity and access management (CIAM).
The Role:
We are seeking an experienced Identity Engineer to own the delivery, operation, and continuous improvement of our enterprise authentication and authorization services. The IAM team is responsible for the security, compliance, availability, and user experience of these services. You will execute implementations, participate in and influence design decisions, and ensure integrations across on-premises and cloud environments meet SLAs and control requirements. The role focuses on SSO, federation, MFA, and secure access management.
Key Responsibilities:
- Own, implement, and operate end-to-end enterprise authentication and federation solutions; drive architecture reviews and collaborate to influence design decisions while ensuring security, compliance, availability, and performance.
- Implement, configure, and support SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), LDAP, and JWT-based integrations.
- Integrate identity solutions with enterprise and third-party applications, APIs, SaaS platforms, and custom web and mobile apps, including SSO, provisioning through SCIM or APIs, and secure API authentication.
- Implement MFA, adaptive authentication, fine-grained access policies, and authorization models that meet security standards.
- Support identity lifecycle and directory integrations with IAM and directory services such as Entra ID/Azure AD, Active Directory, and ADFS, as well as provisioning systems.
- Troubleshoot authentication and authorization flows; perform root-cause analysis, incident response, and performance tuning.
- Ensure compliance with security, audit, and regulatory requirements and support related assessments.
- Collaborate closely with security, infrastructure, application, and DevOps teams to deliver and operate identity services.
- Create and maintain runbooks, SOPs, operational procedures, and technical documentation.
Required Qualifications:
- Strong written and verbal communication, stakeholder management, and cross-team collaboration skills.
- Five or more years of experience in Identity and Access Management (IAM), or equivalent hands-on experience.
- Strong hands-on experience implementing and operating commercial identity platforms and enterprise identity services. Ping AIC and PingFederate experience is preferred, or the ability to implement required features in Ping.
- Deep knowledge of SSO, federation, and authentication and authorization protocols, including SAML 2.0, OAuth 2.0, OpenID Connect, and JWT.
- Experience integrating with directory and lifecycle systems, including Active Directory/LDAP, Azure AD/Entra ID, and ADFS, as well as provisioning through SCIM or APIs.
- Practical experience with MFA, adaptive authentication, fine-grained authorization, and access policy enforcement.
- Strong troubleshooting skills across authentication flows, certificates, TLS, networking, and related infrastructure.
- Scripting and automation skills using Shell, Python, Go, or PowerShell, plus familiarity with infrastructure-as-code and CI/CD tools such as Terraform or Ansible.
- Comfort working in Linux environments and producing operational runbooks and technical documentation.
Bonus Points:
- Experience in banking or financial services within regulated enterprise environments.
- Hands-on cloud experience with AWS, Azure/Entra, or GCP and container platforms such as Docker and Kubernetes.
- Experience with API security, OAuth/OIDC for APIs, and zero-trust architectures or use cases.
- Practical experience with CIAM or customer identity projects.
- Ping Identity certifications or other security or identity certifications.
- Observability and monitoring experience for identity services using Prometheus, ELK, Splunk, or similar tools.
Compensation and Benefits:
The annual base salary range for this position is $150,000 to $200,000, depending on the candidate’s experience, qualifications, and relevant skill set. The position is also eligible for an annual discretionary bonus.
DRW offers a comprehensive suite of employee benefits, including group medical, pharmacy, dental, and vision insurance; a 401(k) with discretionary employer match; short- and long-term disability coverage; life and AD&D insurance; health savings accounts; and flexible spending accounts.
Salary Range
$150,000–$200,000 annual base salary, plus eligibility for an annual discretionary bonus
