Staff/Lead Security Engineer - PAM

cmegroup

Chicago (IL)

On-site

USD 132,000 - 220,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health coverage
401(k) + pension
Education reimbursement
Paid time off
Mental health benefits

Job summary

CME Group is seeking a Staff/Lead Security Engineer to advance our Privileged Account Management program, driving CyberArk/Idira deployments and enhancing PAM infrastructure and compliance across the organization.

You will lead design and automation, mentor junior engineers, support IAM technologies such as MFA, federation, and identity lifecycle, and contribute to roadmaps, incident response, and disaster recovery tests.

Qualifications

  • 7+ years of proven CyberArk/Idira experience.
  • Hands-on design, deployment and support of large CyberArk/Idira implementations.
  • Familiarity with IAM areas: Directory services, lifecycle management, federation, MFA, visibility.
  • Expertise in Windows and Linux environments.
  • Cloud platforms and DevOps tooling experience a plus.
  • Ability to script in PowerShell or Python.
  • Security controls and audit knowledge in IAM architecture.
  • Experience in Agile/Scrum and Product Operating Model.

Responsibilities

  • Lead PAM design, implementation and support of automated, reliable solutions.
  • Identify gaps in PAM coverage and drive remediation efforts.
  • Research trends, evaluate tools, and contribute to roadmaps.
  • Produce project plans for PAM and IAM initiatives.
  • Provide advanced incident troubleshooting and participate in on-call rotations.
  • Automate manual tasks and develop internal documentation.
  • Mentor junior staff and guide teams in credential management.

Skills

CyberArk/Idira
Windows & Linux
PowerShell or Python
Cloud technologies
DevOps / containerized workloads
Agile / Product Operating Model
IAM security knowledge

Education

Bachelor's or Master's in Computer Science or Information Systems
CyberArk/Idira certifications
GCP or cloud certifications
CISSP or equivalent

Job description

The primary responsibility of the Staff/Lead Security Engineer position will be the continued evolution and advancement of our Privileged Account Management (PAM) program. This includes improvements in both infrastructure, such as driving the adoption of CyberArk/Idira ISPSS and Privileged Cloud, and working to identify opportunities to increase compliance with our standards through better management and usage of our account inventory. This is a multifaceted position that requires engineering, support and project leadership abilities.

Additionally, the position will be involved in the support of other IAM-related technologies such as directory services, federation, multifactor authentication (MFA), identity lifecycle management, and identity visibility and intelligence. As this space is constantly evolving, a passion for technology and a strong focus on continued learning will be key to success.

Position Responsibilities:
  • Lead the design, implementation, and support of highly automated and reliable PAM solutions
  • Identify gaps in existing PAM coverage, design solutions and lead remediation efforts
  • Research emerging trends and tools and perform product evaluations
  • Produce and contribute to roadmaps and project plans for PAM or larger IAM efforts
  • Provide advanced incident troubleshooting and participate in on-call rotation and disaster recovery tests
  • Proactively identify and automate existing manual tasks
  • Develop processes, guidelines and documentation for consumption by internal teams
  • Assist teams in identifying, properly storing and using their credentials
  • Provide guidance and mentorship for junior staff
Minimum Requirements: Knowledge, skills, and abilities:
  • 7+ years of proven experience with CyberArk/Idira
  • Hands-on experience designing, deploying and supporting large-scale CyberArk/Idira implementations
  • Strong familiarity with one or more of the following IAM areas: Directory services, Identity lifecycle management, Federation / MFA, Identity Visibility and Intelligence
  • Expertise in both Windows and Linux environments
  • Familiarity or expertise in cloud technologies and platforms a plus
  • Ability to create scripts in either PowerShell or Python
  • Familiarity with devops, containerized workloads and associated tooling and technologies a plus
  • Strong familiarity with security issues surrounding Identity and Access Management and experience in implementation of security systems and controls
  • Thorough knowledge of information security components, principles, practices, and procedures
  • Demonstrated ability to work across a broad range of technologies
  • Ability to succinctly articulate complex technical issues to both technicians and business sponsors
  • Knowledge of audit controls and applicability to IAM services architecture, design, and processes
  • Experience working in an Agile/Scrum and the Product Operating Model
Personal Attributes:
  • Strong analytical, problem-solving and troubleshooting skills
  • High level critical thinking skills
  • Excellent written and oral communication skills
  • Ability to compose and present material that communicates difficult concepts
  • Positive attitude, self-starter with strong communication and interpersonal skills to lead working groups, negotiate and create consensus
  • Comfortable working in a dynamic environment with multiple goals
  • Highly self-motivated and directed, with keen attention to detail
  • Able to prioritize and execute tasks in a high-pressure environment
  • Ability to deal diplomatically and effectively at all levels of the organization including both technical and non-technical, management and senior leadership
Education & Certification
  • A Bachelor's or Master's degree in Computer Science or Information Systems or equivalent combination of education and related work experience
  • CyberArk/Idira certifications or equivalent experience
  • GCP or similar cloud certifications a plus
  • Security certifications: CISSP or equivalent a plus

CME Group is committed to offering a competitive total rewards package for our employees that recognizes their contributions to the business and reflects our long-term investment in their future.

The pay range for this role is $132,100-$220,100. Actual salary offered will be dependent on a wide array of factors including but not limited to: relevant experience, skills, education and comparison to internal employees (where relevant). Our compensation program also includes an annual target bonus opportunity for all employees, as well as the opportunity to become an owner in the company through our broad-based equity program.

Through our benefits program, we strive to offer flexibility, value and choice.

  • comprehensive health coverage
  • retirement package that includes both a 401(k) and an active pension plan
  • highly competitive education reimbursement provisions
  • paid time off
  • mental health benefit

CME Group offers a holistic benefits package for our team and their dependents.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff/Lead Security Engineer - PAM
Staff/Lead Security Engineer - PAM

CME Chicago Mercantile Exchange Inc. • Chicago (IL)

On-site
USD 132,000 - 220,000
Staff/Lead Security Engineer - PAM
Staff/Lead Security Engineer - PAM

CME Group Inc. • Chicago (IL), Northern (KY)

Hybrid
USD 132,000 - 220,000
Annual bonus opportunity
Equity program
Staff/Lead Security Engineer - PAM
Staff/Lead Security Engineer - PAM

Socket.dev • Chicago (IL)

On-site
USD 132,000 - 220,000
Senior PAM & IAM Engineering Lead - Equity Eligible
Senior PAM & IAM Engineering Lead - Equity Eligible

cmegroup • Chicago (IL)

On-site
USD 132,000 - 220,000
Health coverage
401(k) + pension
Education reimbursement
+2
PAM & IAM Security Architect
PAM & IAM Security Architect

CME Chicago Mercantile Exchange Inc. • Chicago (IL)

On-site
USD 132,000 - 220,000
Security Engineer
Security Engineer

Insight Global • United States

On-site
Medical, dental, and vision insurance
HSA, FSA, and DCFSA account options
401k retirement account access with employer matching
+1
Lead Privileged Access & IAM Engineer
Lead Privileged Access & IAM Engineer

CME Group Inc. • Chicago (IL), Northern (KY)

Hybrid
USD 132,000 - 220,000
Annual bonus opportunity
Equity program
Privileged Access Management (PAM) Engineer - CyberArk Specialist | Cross-Border Banking and Ma[...]
Privileged Access Management (PAM) Engineer - CyberArk Specialist | Cross-Border Banking and Ma[...]

Techfellow Limited • Woodbridge Township (NJ)

Hybrid
USD 127,000 - 150,000
Senior Technology Security Engineer (IAM)
Senior Technology Security Engineer (IAM)

Pointwest Technologies Corp • Des Moines (IA)

On-site
USD 90,000 - 120,000
Senior Technology Security Engineer (IAM)
Senior Technology Security Engineer (IAM)

Pointwest-North America • Des Moines (IA)

On-site
USD 100,000 - 130,000