Staff/Lead Security Engineer - PAM

CME Chicago Mercantile Exchange Inc.

Chicago (IL)

On-site

USD 132,000 - 220,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CME Group is seeking a Staff/Lead Security Engineer to evolve our Privileged Account Management program and drive adoption of CyberArk/Idira in both on-premises and cloud environments. The role combines engineering, support, and project leadership across IAM-related technologies, including MFA, federation, and identity lifecycle management.

Ideal candidates will have 7+ years in CyberArk/Idira, strong Windows/Linux skills, scripting abilities (PowerShell or Python), and a proven track record in

Qualifications

  • 7+ years of experience with CyberArk/Idira in large-scale deployments.
  • Hands-on design, deployment and support of PAM and IAM solutions.
  • Experience with Windows and Linux environments and cloud basics.

Responsibilities

  • Lead the design, implementation, and support of automated PAM solutions.
  • Identify gaps in PAM coverage and drive remediation efforts.
  • Research trends and perform product evaluations for IAM tooling.
  • Contribute to roadmaps and project plans for PAM and IAM initiatives.
  • Provide advanced incident troubleshooting and participate in on-call rotations.
  • Develop processes, guidelines and documentation for internal teams.

Skills

CyberArk/Idira
Windows & Linux
PowerShell or Python
DevOps / container tooling
IAM concepts
Scripting automation
Stakeholder communication

Education

Bachelor's or Master's in Computer Science / Information Systems
CyberArk/Idira certifications
GCP or cloud certifications
CISSP or equivalent

Tools

CyberArk
Idira
Cloud platforms (GCP/AWS)

Job description

The primary responsibility of the Staff/Lead Security Engineer position will be the continued evolution and advancement of our Privileged Account Management (PAM) program. This includes improvements in both infrastructure, such as driving the adoption of CyberArk/Idira ISPSS and Privileged Cloud, and working to identify opportunities to increase compliance with our standards through better management and usage of our account inventory. This is a multifaceted position that requires engineering, support and project leadership abilities. Additionally, the position will be involved in the support of other IAM-related technologies such as directory services, federation, multifactor authentication (MFA), identity lifecycle management, and identity visibility and intelligence. As this space is constantly evolving, a passion for technology and a strong focus on continued learning will be key to success.

Position Responsibilities
  • Lead the design, implementation, and support of highly automated and reliable PAM solutions
  • Identify gaps in existing PAM coverage, design solutions and lead remediation efforts
  • Research emerging trends and tools and perform product evaluations
  • Produce and contribute to roadmaps and project plans for PAM or larger IAM efforts
  • Provide advanced incident troubleshooting and participate in on-call rotation and disaster recovery tests
  • Proactively identify and automate existing manual tasks
  • Develop processes, guidelines and documentation for consumption by internal teams
  • Assist teams in identifying, properly storing and using their credentials
  • Provide guidance and mentorship for junior staff
Minimum Requirements
  • Knowledge, skills, and abilities:
  • 7+ years of proven experience with CyberArk/Idira
  • Hands‑on experience designing, deploying and supporting large‑scale CyberArk/Idira implementations
  • Strong familiarity with one or more of the following IAM areas: Directory services Identity lifecycle management Federation / MFA Identity Visibility and Intelligence
  • Expertise in both Windows and Linux environments
  • Familiarity or expertise in cloud technologies and platforms a plus
  • Ability to create scripts in either PowerShell or Python
  • Familiarity with devops, containerized workloads and associated tooling and technologies a plus
  • Strong familiarity with security issues surrounding Identity and Access Management and experience in implementation of security systems and controls
  • Thorough knowledge of information security components, principles, practices, and procedures
  • Demonstrated ability to work across a broad range of technologies
  • Ability to succinctly articulate complex technical issues to both technicians and business sponsors
  • Knowledge of audit controls and applicability to IAM services architecture, design, and processes
  • Experience working in an Agile/Scrum and the Product Operating Model
Personal Attributes
  • Strong analytical, problem‑solving and troubleshooting skills
  • High level critical thinking skills
  • Excellent written and oral communication skills
  • Ability to compose and present material that communicates difficult concepts
  • Positive attitude, self‑starter with strong communication and interpersonal skills to lead working groups, negotiate and create consensus
  • Comfortable working in a dynamic environment with multiple goals
  • Highly self‑motivated and directed, with keen attention to detail
  • Able to prioritize and execute tasks in a high‑pressure environment
  • Ability to deal diplomatically and effectively at all levels of the organization including both technical and non‑technical, management and senior leadership
Education & Certification
  • A Bachelor's or Master's degree in Computer Science or Information Systems or equivalent combination of education and related work experience
  • CyberArk/Idira certifications or equivalent experience
  • GCP or similar cloud certifications a plus
  • Security certifications: CISSP or equivalent a plus
Compensation
  • The pay range for this role is $132,100-$220,100.
  • Actual salary offered will be dependent on a wide array of factors including but not limited to: relevant experience, skills, education and comparison to internal employees (where relevant).
  • Our compensation program also includes an annual target bonus opportunity for all employees, as well as the opportunity to become an owner in the company through our broad‑based equity program.
  • Through our benefits program, we strive to offer flexibility, value and choice. From comprehensive health coverage, to a retirement package that includes both a 401(k) and an active pension plan, to highly competitive education reimbursement provisions, paid time off and a mental health benefit, CME Group offers a holistic benefits package for our team and their dependents.
Employment Eligibility Verification and E-Verify

For U.S. employment, CME Group is legally required to validate a new hire’s employment eligibility by having them complete an Employment Eligibility Verification (Form I-9) companied with legally acceptable proof of identity and work authorization (as listed on the Form I-9). CME Group uses E-Verify, which is an online system operated by the U.S. Department of Homeland Security in partnership with the Social Security Administration to verify employment eligibility and validate social security numbers. Through participation in the E-Verify program, information entered on Form I-9 will be provided and compared to information available at both of these agencies. See posters below for more details.

E-Verify Notice

E-Verify Notice Español

U.S. Right to Work Notice

U.S. Right to Work Notice Español

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff/Lead Security Engineer - PAM
Staff/Lead Security Engineer - PAM

CME Group Inc. • Chicago (IL), Northern (KY)

Hybrid
USD 132,000 - 220,000
Annual bonus opportunity
Equity program
Lead Privileged Access & IAM Engineer
Lead Privileged Access & IAM Engineer

CME Group Inc. • Chicago (IL), Northern (KY)

Hybrid
USD 132,000 - 220,000
Annual bonus opportunity
Equity program
PAM & IAM Security Architect
PAM & IAM Security Architect

CME Chicago Mercantile Exchange Inc. • Chicago (IL)

On-site
USD 132,000 - 220,000
Senior Technology Security Engineer (IAM)
Senior Technology Security Engineer (IAM)

Pointwest Technologies Corp • Des Moines (IA)

On-site
USD 90,000 - 120,000
Senior Technology Security Engineer (IAM)
Senior Technology Security Engineer (IAM)

Pointwest-North America • Des Moines (IA)

On-site
USD 100,000 - 130,000
Senior Manager, Privileged Access Management – PAM
Senior Manager, Privileged Access Management – PAM

Jobtailor • Town of Florida (NY)

On-site
USD 140,000 - 185,000
Information Security Engineer - CyberArk
Information Security Engineer - CyberArk

NCR Corporation • United States

On-site
USD 90,000 - 120,000
Systems Engineer II - PAM
Systems Engineer II - PAM

Early Warning Services LLC • Scottsdale (AZ)

Hybrid
USD 99,000 - 121,000
Healthcare coverage
401(k) Retirement Plan
Flexible Paid Time Off
+2
CyberArk Engineer
CyberArk Engineer

KeyData Cyber • United States

On-site
USD 96,000 - 179,000
PAM Engineer (CyberArk/hashivault)
PAM Engineer (CyberArk/hashivault)

TEKsystems • Town of Texas (WI)

Hybrid
USD 90,000 - 103,000
Medical, dental & vision
Critical Illness, Accident, and Hosp.
401(k) Retirement Plan
+6