Staff/Lead Security Engineer - PAM

CME Group Inc.

Chicago, Northern (IL, KY)

Hybrid

USD 132,000 - 220,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Annual bonus opportunity
Equity program

Job summary

CME Group Inc. is seeking a Staff/Lead Security Engineer to advance our Privileged Account Management (PAM) program. You will design, implement, and support highly automated PAM solutions across Windows and Linux, leveraging CyberArk/Idira and cloud capabilities.

You will mentor junior staff, lead cross-functional IAM initiatives, and drive remediation by identifying gaps, evaluating new tools, and producing roadmaps to strengthen our security controls.

Qualifications

  • 7+ years of proven CyberArk/Idira experience.
  • Hands-on design, deployment, and support of large CyberArk/Idira implementations.
  • IAM areas include Directory services, Federation, MFA, and Identity Lifecycle.
  • Expertise in Windows and Linux environments.
  • Cloud technologies familiarity is a plus.
  • Scripting: PowerShell or Python.

Responsibilities

  • Lead design, implementation, and support of automated PAM solutions.
  • Identify gaps in PAM coverage and drive remediation.
  • Research trends and perform product evaluations.
  • Produce roadmaps and project plans for PAM/IAM efforts.
  • Provide advanced incident troubleshooting and participate in on-call.
  • Automate existing manual tasks.
  • Develop processes and documentation for internal teams.
  • Assist teams in storing and using credentials.
  • Provide guidance to junior staff.

Skills

CyberArk/Idira
Windows & Linux
PowerShell/Python
IAM expertise
Cloud familiarity

Education

Bachelor's or Master's in CS/IS
CyberArk/Idira certs
GCP certs
CISSP or equivalent

Tools

CyberArk
Idira
GCP

Job description

The primary responsibility of the Staff/Lead Security Engineer position will be the continued evolution and advancement of our Privileged Account Management (PAM) program. This includes improvements in both infrastructure, such as driving the adoption of CyberArk/Idira ISPSS and Privileged Cloud, and working to identify opportunities to increase compliance with our standards through better management and usage of our account inventory. This is a multifaceted position that requires engineering, support and project leadership abilities. Additionally, the position will be involved in the support of other IAM-related technologies such as directory services, federation, multifactor authentication (MFA), identity lifecycle management, and identity visibility and intelligence. As this space is constantly evolving, a passion for technology and a strong focus on continued learning will be key to success.

Position Responsibilities
  • Lead the design, implementation, and support of highly automated and reliable PAM solutions
  • Identify gaps in existing PAM coverage, design solutions and lead remediation efforts
  • Research emerging trends and tools and perform product evaluations
  • Produce and contribute to roadmaps and project plans for PAM or larger IAM efforts
  • Provide advanced incident troubleshooting and participate in on-call rotation and disaster recovery tests
  • Proactively identify and automate existing manual tasks
  • Develop processes, guidelines and documentation for consumption by internal teams
  • Assist teams in identifying, properly storing and using their credentials
  • Provide guidance and mentorship for junior staff
Minimum Requirements
  • Knowledge, skills, and abilities:
  • 7+ years of proven experience with CyberArk/Idira
  • Hands‑on experience designing, deploying and supporting large‑scale CyberArk/Idira implementations
  • Strong familiarity with one or more of the following IAM areas: Directory services Identity lifecycle management Federation / MFA Identity Visibility and Intelligence
  • Expertise in both Windows and Linux environments
  • Familiarity or expertise in cloud technologies and platforms a plus
  • Ability to create scripts in either PowerShell or Python
  • Familiarity with devops, containerized workloads and associated tooling and technologies a plus
  • Strong familiarity with security issues surrounding Identity and Access Management and experience in implementation of security systems and controls
  • Thorough knowledge of information security components, principles, practices, and procedures
  • Demonstrated ability to work across a broad range of technologies
  • Ability to succinctly articulate complex technical issues to both technicians and business sponsors
  • Knowledge of audit controls and applicability to IAM services architecture, design, and processes
  • Experience working in an Agile/Scrum and the Product Operating Model
Personal Attributes
  • Strong analytical, problem‑solving and troubleshooting skills
  • High level critical thinking skills
  • Excellent written and oral communication skills
  • Ability to compose and present material that communicates difficult concepts
  • Positive attitude, self‑starter with strong communication and interpersonal skills to lead working groups, negotiate and create consensus
  • Comfortable working in a dynamic environment with multiple goals
  • Highly self‑motivated and directed, with keen attention to detail
  • Able to prioritize and execute tasks in a high‑pressure environment
  • Ability to deal diplomatically and effectively at all levels of the organization including both technical and non‑technical, management and senior leadership
Education & Certification
  • A Bachelor's or Master's degree in Computer Science or Information Systems or equivalent combination of education and related work experience
  • CyberArk/Idira certifications or equivalent experience
  • GCP or similar cloud certifications a plus
  • Security certifications: CISSP or equivalent a plus
Compensation
  • The pay range for this role is $132,100-$220,100.
  • Actual salary offered will be dependent on a wide array of factors including but not limited to: relevant experience, skills, education and comparison to internal employees (where relevant).
  • Our compensation program also includes an annual target bonus opportunity for all employees, as well as the opportunity to become an owner in the company through our broad‑based equity program.
  • Through our benefits program, we strive to offer flexibility, value and choice. From comprehensive health coverage, to a retirement package that includes both a 401(k) and an active pension plan, to highly competitive education reimbursement provisions, paid time off and a mental health benefit, CME Group offers a holistic benefits package for our team and their dependents.
Employment Eligibility Verification and E-Verify

For U.S. employment, CME Group is legally required to validate a new hire’s employment eligibility by having them complete an Employment Eligibility Verification (Form I-9) companied with legally acceptable proof of identity and work authorization (as listed on the Form I-9). CME Group uses E-Verify, which is an online system operated by the U.S. Department of Homeland Security in partnership with the Social Security Administration to verify employment eligibility and validate social security numbers. Through participation in the E-Verify program, information entered on Form I-9 will be provided and compared to information available at both of these agencies. See posters below for more details.

E-Verify Notice

E-Verify Notice Español

U.S. Right to Work Notice

U.S. Right to Work Notice Español

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff/Lead Security Engineer - PAM
Staff/Lead Security Engineer - PAM

CME Chicago Mercantile Exchange Inc. • Chicago (IL)

On-site
USD 132,000 - 220,000
Staff/Lead Security Engineer - PAM
Staff/Lead Security Engineer - PAM

cmegroup • Chicago (IL)

On-site
USD 132,000 - 220,000
Health coverage
401(k) + pension
Education reimbursement
+2
Staff/Lead Security Engineer - PAM
Staff/Lead Security Engineer - PAM

Socket.dev • Chicago (IL)

On-site
USD 132,000 - 220,000
Senior PAM & IAM Engineering Lead - Equity Eligible
Senior PAM & IAM Engineering Lead - Equity Eligible

cmegroup • Chicago (IL)

On-site
USD 132,000 - 220,000
Health coverage
401(k) + pension
Education reimbursement
+2
Lead Privileged Access & IAM Engineer
Lead Privileged Access & IAM Engineer

CME Group Inc. • Chicago (IL), Northern (KY)

Hybrid
USD 132,000 - 220,000
Annual bonus opportunity
Equity program
PAM & IAM Security Architect
PAM & IAM Security Architect

CME Chicago Mercantile Exchange Inc. • Chicago (IL)

On-site
USD 132,000 - 220,000
Senior Technology Security Engineer (IAM)
Senior Technology Security Engineer (IAM)

Pointwest Technologies Corp • Des Moines (IA)

On-site
USD 90,000 - 120,000
Senior Technology Security Engineer (IAM)
Senior Technology Security Engineer (IAM)

Pointwest-North America • Des Moines (IA)

On-site
USD 100,000 - 130,000
Senior Manager, Privileged Access Management – PAM
Senior Manager, Privileged Access Management – PAM

Jobtailor • Town of Florida (NY)

On-site
USD 140,000 - 185,000
Lead PAM and IAM Security Engineer
Lead PAM and IAM Security Engineer

Socket.dev • Chicago (IL)

On-site
USD 132,000 - 220,000