NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Architect in United States of America
10 days ago
Apply with autofill
Apply with autofill
Drweng·10 days ago
10 days ago

Staff IAM Engineer

Chicago, United States of AmericaFull-timeSenior · 5+ yearsArchitect

Sign up free to see how well your resume matches this role.

Boost your chances at drweng

How you compare FREE

?
Your scoreYour score: not yet known
→
19
Top 10%Top 10%: 19 out of 100

Top 10% of NextRaise users matched against Architect roles in United States.

Must-have skills for this role

  • oidc
  • oauth 2.0
  • saml
  • jwt

PDF or DOCX · no account needed

Apply faster with autofill FREEdrweng uses Greenhouse - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Design and own the migration architecture to transition DRW from existing identity solutions to a modern, enterprise IdP. You will lead by doing – writing code, configuring APIs, and building proof of concept integrations.
  • Act as the primary technical authority during vendor evaluations, designing "messy data" Proof of Concepts to rigorously pressure-test commercial IdP and IGA tools against our actual infrastructure.
  • Design the zero-trust token exchange architecture for internal APIs and microservices, ensuring non-human identities are governed securely.
  • Act as the technical diplomat between security, compliance, business, and internal engineering teams. You must translate regulatory and security risks into pragmatic engineering requirements that do not slow down the business.
  • Partner with the internal engineering and security teams to ensure the new enterprise IdP seamlessly feeds identities into custom-built internal applications.

What they're looking for

  • Deep architectural expertise in modern identity protocols (OIDC, OAuth 2.0, SAML) and applied cryptography (JWT, JWKS, RS256).
  • Proven background as a software or systems engineer. Must be highly proficient in IaC and at least one programming language (Go and/or Python preferred) to build custom glue-code and SDKs.
  • Deep understanding of modern machine identity paradigms, including HashiCorp Vault, AWS IAM Roles, OIDC federation for CI/CD pipelines, and ephemeral certificate brokering.
  • Exceptional ability to manage non-engineering and security stakeholders. You must be able to push back on vendor fluff, negotiate architectural compromises with stubborn engineering teams, and explain complex identity risks to executive business stakeholders.
  • Proven experience untangling legacy technical debt, with a pragmatic approach to using Identity-Aware Proxies (IAPs) as "Last-Mile Adapters" during large-scale migrations.
  • Strong system design background with the ability to draw and defend architectures that earn the respect of senior software engineers in a high-speed trading culture.
  • Strategic mindset with the ability to navigate ambiguity and map technical identity solutions directly to regulatory/compliance requirements.

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

DRW is a diversified trading firm with over 3 decades of experience bringing sophisticated technology and exceptional people together to operate in markets around the world. We value autonomy and the ability to quickly pivot to capture opportunities, so we operate using our own capital and trading at our own risk.

Headquartered in Chicago with offices throughout the U.S., Canada, Europe, and Asia, we trade a variety of asset classes including Fixed Income, ETFs, Equities, FX, Commodities and Energy across all major global markets. We have also leveraged our expertise and technology to expand into three non-traditional strategies: real estate, venture capital and cryptoassets.

We operate with respect, curiosity and open minds. The people who thrive here share our belief that it’s not just what we do that matters–it's how we do it. DRW is a place of high expectations, integrity, innovation and a willingness to challenge consensus.

The Team: 

The IAM Team is a net-new, vanguard group that will own, implement, and drive DRW’s comprehensive identity capabilities, aligning them to evolving business requirements. This dedicated group collaborates with stakeholders to advance agentic identity, enhanced authentication and authorization controls, and other emerging identity and security innovations, with potential expansion into customer identity and access management (CIAM). 

The Role: 

We are seeking an experienced Identity Engineer to own the delivery, operation, and continuous improvement of our enterprise authentication and authorization services. The IAM team is responsible for the security, compliance, availability, and user experience of these services; you'll execute implementations, participate in and influence design decisions, and ensure integrations across on‑prem and cloud environments meet SLAs and control requirements. The role focuses on SSO, federation, MFA, and secure access management. 

Key Responsibilities: 

  • Own, implement, and operate end-to-end enterprise authentication and federation solutions; drive architecture reviews and collaborate to influence design decisions, ensuring security, compliance, availability, and performance. 
  • Implement, configure, and support SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), LDAP, and JWT‑based integrations. 
  • Integrate identity solutions with enterprise, third‑party applications, APIs, SaaS platforms, and custom web/mobile apps, including SSO, provisioning (SCIM/API), and secure API authentication. 
  • Implement MFA, adaptive authentication, fine‑grained access policies, and authorization models that meet security standards. 
  • Support identity lifecycle and directory integrations with IAM and directory services (e.g., Entra ID/Azure AD, Active Directory, ADFS) and provisioning systems. 
  • Troubleshoot authentication/authorization flows; perform root‑cause analysis, incident response, and performance tuning. 
  • Ensure compliance with security, audit, and regulatory requirements and support related assessments. 
  • Collaborate closely with security, infrastructure, application, and DevOps teams to deliver and operate identity services. 
  • Create and maintain runbooks, SOPs, operational procedures, and technical documentation. 

Required Qualifications: 

  • Strong written and verbal communication, stakeholder management, and cross‑team collaboration skills. 
  • 5+ years of experience in Identity & Access Management (IAM), or equivalent hands-on experience. 
  • Strong hands-on experience implementing and operating commercial identity platforms and enterprise identity services (Ping AIC and PingFederate preferred, or the ability to implement required features in Ping). 
  • Deep knowledge of SSO, federation, and authentication/authorization protocols (SAML 2.0, OAuth 2.0, OpenID Connect, JWT). 
  • Experience integrating with directory and lifecycle systems (Active Directory/LDAP, Azure AD/Entra ID, ADFS) and provisioning (SCIM/API). 
  • Practical experience with MFA, adaptive authentication, fine-grained authorization, and access policy enforcement. 
  • Strong troubleshooting skills across authentication flows, certificates, TLS, networking, and related infrastructure. 
  • Scripting/automation skills (Shell, Python, Go, PowerShell) and familiarity with IaC/CI-CD tools (Terraform, Ansible, or similar). 
  • Comfortable working in Linux environments and producing operational runbooks and technical documentation. 

Bonus Points: 

  • Experience in banking or financial services (regulated enterprise environments). 
  • Hands‑on cloud experience (AWS, Azure/Entra, or GCP) and container platforms (Docker, Kubernetes). 
  • Experience with API security, OAuth/OIDC for APIs, and zero‑trust architectures/use cases. 
  • Practical experience with CIAM or customer identity projects. 
  • Ping Identity certifications or other security/identity certifications. 
    • Observability and monitoring experience for identity services (Prometheus, ELK, Splunk, etc.) 

The annual base salary range for this position is $150,000 to $200,000 depending on the candidate’s experience, qualifications, and relevant skill set. The position is also eligible for an annual discretionary bonus. In addition, DRW offers a comprehensive suite of employee benefits including group medical, pharmacy, dental and vision insurance, 401k (with discretionary employer match), short and long-term disability, life and AD&D insurance, health savings accounts, and flexible spending accounts.

For more information about DRW's processing activities and our use of job applicants' data, please view our Privacy Notice at https://drw.com/privacy-notice.

California residents, please review the California Privacy Notice for information about certain legal rights at https://drw.com/california-privacy-notice.

[#LI-LD1] 

Company

Drweng
Chicago, United States of America

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Drweng's careers site·first seen 11 Sept 2026·last verified 18 Sept 2026·How we source jobs

Similar jobs

  • Principal Architect - Gen AI at sedgwickTelecommuter TN–match not yet calculated
  • Encryption & Post-Quantum Architect at sbdincTowson, United States of America–match not yet calculated
  • Test Architect - Standard Missile Development at globalhrTUCSON, United States of America–match not yet calculated
  • Manager, Solutions Architecture - AI Infrastructure Build Readiness at NVIDIASanta Clara, United States of America–match not yet calculated
  • Test Architect - Standard Missile Development at RTXtucson, United States of America–match not yet calculated

Browse more jobs

  • Architect jobs in United States
  • BIM Manager jobs in United States
  • Architectural Drafter jobs in United States
  • Landscape Architect jobs in United States
  • Architect jobs in India
  • Architect jobs in Germany