Staff/Lead Security Engineer - PAM

CME Chicago Mercantile Exchange Inc.

Chicago (IL)

On-site

USD 132,000 - 220,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

CME Group is seeking a Staff/Lead Security Engineer to evolve our Privileged Account Management program and drive adoption of CyberArk/Idira in both on-premises and cloud environments. The role combines engineering, support, and project leadership across IAM-related technologies, including MFA, federation, and identity lifecycle management.

Ideal candidates will have 7+ years in CyberArk/Idira, strong Windows/Linux skills, scripting abilities (PowerShell or Python), and a proven track record in

Qualifications

  • 7+ years of experience with CyberArk/Idira in large-scale deployments.
  • Hands-on design, deployment and support of PAM and IAM solutions.
  • Experience with Windows and Linux environments and cloud basics.

Responsibilities

  • Lead the design, implementation, and support of automated PAM solutions.
  • Identify gaps in PAM coverage and drive remediation efforts.
  • Research trends and perform product evaluations for IAM tooling.
  • Contribute to roadmaps and project plans for PAM and IAM initiatives.
  • Provide advanced incident troubleshooting and participate in on-call rotations.
  • Develop processes, guidelines and documentation for internal teams.

Skills

CyberArk/Idira
Windows & Linux
PowerShell or Python
DevOps / container tooling
IAM concepts
Scripting automation
Stakeholder communication

Education

Bachelor's or Master's in Computer Science / Information Systems
CyberArk/Idira certifications
GCP or cloud certifications
CISSP or equivalent

Tools

CyberArk
Idira
Cloud platforms (GCP/AWS)

Job description

The primary responsibility of the Staff/Lead Security Engineer position will be the continued evolution and advancement of our Privileged Account Management (PAM) program. This includes improvements in both infrastructure, such as driving the adoption of CyberArk/Idira ISPSS and Privileged Cloud, and working to identify opportunities to increase compliance with our standards through better management and usage of our account inventory. This is a multifaceted position that requires engineering, support and project leadership abilities. Additionally, the position will be involved in the support of other IAM-related technologies such as directory services, federation, multifactor authentication (MFA), identity lifecycle management, and identity visibility and intelligence. As this space is constantly evolving, a passion for technology and a strong focus on continued learning will be key to success.

Position Responsibilities
  • Lead the design, implementation, and support of highly automated and reliable PAM solutions
  • Identify gaps in existing PAM coverage, design solutions and lead remediation efforts
  • Research emerging trends and tools and perform product evaluations
  • Produce and contribute to roadmaps and project plans for PAM or larger IAM efforts
  • Provide advanced incident troubleshooting and participate in on-call rotation and disaster recovery tests
  • Proactively identify and automate existing manual tasks
  • Develop processes, guidelines and documentation for consumption by internal teams
  • Assist teams in identifying, properly storing and using their credentials
  • Provide guidance and mentorship for junior staff
Minimum Requirements
  • Knowledge, skills, and abilities:
  • 7+ years of proven experience with CyberArk/Idira
  • Hands‑on experience designing, deploying and supporting large‑scale CyberArk/Idira implementations
  • Strong familiarity with one or more of the following IAM areas: Directory services Identity lifecycle management Federation / MFA Identity Visibility and Intelligence
  • Expertise in both Windows and Linux environments
  • Familiarity or expertise in cloud technologies and platforms a plus
  • Ability to create scripts in either PowerShell or Python
  • Familiarity with devops, containerized workloads and associated tooling and technologies a plus
  • Strong familiarity with security issues surrounding Identity and Access Management and experience in implementation of security systems and controls
  • Thorough knowledge of information security components, principles, practices, and procedures
  • Demonstrated ability to work across a broad range of technologies
  • Ability to succinctly articulate complex technical issues to both technicians and business sponsors
  • Knowledge of audit controls and applicability to IAM services architecture, design, and processes
  • Experience working in an Agile/Scrum and the Product Operating Model
Personal Attributes
  • Strong analytical, problem‑solving and troubleshooting skills
  • High level critical thinking skills
  • Excellent written and oral communication skills
  • Ability to compose and present material that communicates difficult concepts
  • Positive attitude, self‑starter with strong communication and interpersonal skills to lead working groups, negotiate and create consensus
  • Comfortable working in a dynamic environment with multiple goals
  • Highly self‑motivated and directed, with keen attention to detail
  • Able to prioritize and execute tasks in a high‑pressure environment
  • Ability to deal diplomatically and effectively at all levels of the organization including both technical and non‑technical, management and senior leadership
Education & Certification
  • A Bachelor's or Master's degree in Computer Science or Information Systems or equivalent combination of education and related work experience
  • CyberArk/Idira certifications or equivalent experience
  • GCP or similar cloud certifications a plus
  • Security certifications: CISSP or equivalent a plus
Compensation
  • The pay range for this role is $132,100-$220,100.
  • Actual salary offered will be dependent on a wide array of factors including but not limited to: relevant experience, skills, education and comparison to internal employees (where relevant).
  • Our compensation program also includes an annual target bonus opportunity for all employees, as well as the opportunity to become an owner in the company through our broad‑based equity program.
  • Through our benefits program, we strive to offer flexibility, value and choice. From comprehensive health coverage, to a retirement package that includes both a 401(k) and an active pension plan, to highly competitive education reimbursement provisions, paid time off and a mental health benefit, CME Group offers a holistic benefits package for our team and their dependents.
Employment Eligibility Verification and E-Verify

For U.S. employment, CME Group is legally required to validate a new hire’s employment eligibility by having them complete an Employment Eligibility Verification (Form I-9) companied with legally acceptable proof of identity and work authorization (as listed on the Form I-9). CME Group uses E-Verify, which is an online system operated by the U.S. Department of Homeland Security in partnership with the Social Security Administration to verify employment eligibility and validate social security numbers. Through participation in the E-Verify program, information entered on Form I-9 will be provided and compared to information available at both of these agencies. See posters below for more details.

E-Verify Notice

E-Verify Notice Español

U.S. Right to Work Notice

U.S. Right to Work Notice Español

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff/Lead Security Engineer - PAM
Staff/Lead Security Engineer - PAM

CME Group Inc. • Chicago (IL), Northern (KY)

On-site
USD 132,000 - 220,000
Annual bonus opportunity
Equity program
Staff/Lead Security Engineer - PAM
Staff/Lead Security Engineer - PAM

CME Group • Chicago (IL)

On-site
USD 132,000 - 220,000
Competitive compensation
Excellent benefits package
401(k) with pension
Cyber Defense Analyst III
Cyber Defense Analyst III

CME Chicago Mercantile Exchange Inc. • Chicago (IL)

On-site
USD 104,000 - 173,000
Health coverage
401(k)
Equity program
+3
Cyber Defense Analyst III
Cyber Defense Analyst III

CME Group • Chicago (IL)

On-site
USD 104,000 - 173,000
PAM Engineering Lead
PAM Engineering Lead

WTW • Minneapolis (MN)

On-site
USD 130,000 - 170,000
Health benefits
401(k) plan with company contribution
Paid time off
Lead Privileged Access & IAM Engineer
Lead Privileged Access & IAM Engineer

CME Group Inc. • Chicago (IL), Northern (KY)

Hybrid
USD 132,000 - 220,000
Annual bonus opportunity
Equity program
PAM & IAM Security Architect
PAM & IAM Security Architect

CME Chicago Mercantile Exchange Inc. • Chicago (IL)

On-site
USD 132,000 - 220,000
CyberArk PAM Architect - W2
CyberArk PAM Architect - W2

Prudent Technologies and Consulting, Inc. • Jersey City (NJ)

On-site
USD 140,000 - 190,000
Senior IAM Engineer
Senior IAM Engineer

EPAM Systems Inc • United States

Remote
USD 140,000 - 190,000
Cyber Defense Response Analyst II
Cyber Defense Response Analyst II

CME Chicago Mercantile Exchange Inc. • Chicago (IL)

On-site
USD 94,000 - 157,000
Health coverage
401(k) + pension
Education reimbursement
+3