Cmegroup

Staff/Lead Security Engineer - PAM

Chicago - 20 S. WackerFull timeLeadPosted about 1 month ago
Apply on Cmegroup →Sign in to save this role

Sign in to see who you know at Cmegroup.

The primary responsibility of the Staff/Lead Security Engineer position will be the continued evolution and advancement of our Privileged Account Management (PAM) program. This includes improvements in both infrastructure, such as driving the adoption of CyberArk/Idira ISPSS and Privileged Cloud, and working to identify opportunities to increase compliance with our standards through better management and usage of our account inventory. This is a multifaceted position that requires engineering, support and project leadership abilities.

Additionally, the position will be involved in the support of other IAM-related technologies such as directory services, federation, multifactor authentication (MFA), identity lifecycle management, and identity visibility and intelligence. As this space is constantly evolving, a passion for technology and a strong focus on continued learning will be key to success.

Position Responsibilities

Lead the design, implementation, and support of highly automated and reliable PAM solutions

Identify gaps in existing PAM coverage, design solutions and lead remediation efforts

Research emerging trends and tools and perform product evaluations

Produce and contribute to roadmaps and project plans for PAM or larger IAM efforts

Provide advanced incident troubleshooting and participate in on-call rotation and disaster recovery tests

Proactively identify and automate existing manual tasks

Develop processes, guidelines and documentation for consumption by internal teams

Assist teams in identifying, properly storing and using their credentials

Provide guidance and mentorship for junior staff

Minimum Requirements: Knowledge, skills, and abilities

7+ years of proven experience with CyberArk/Idira

Hands-on experience designing, deploying and supporting large-scale CyberArk/Idira implementations

Strong familiarity with one or more of the following IAM areas:

Directory services

Identity lifecycle management

Federation / MFA

Identity Visibility and Intelligence

Expertise in both Windows and Linux environments

Familiarity or expertise in cloud technologies and platforms a plus

Ability to create scripts in either PowerShell or Python

Familiarity with devops, containerized workloads and associated tooling and technologies a plus

Strong familiarity with security issues surrounding Identity and Access Management and experience in implementation of security systems and controls

Thorough knowledge of information security components, principles, practices, and procedures

Demonstrated ability to work across a broad range of technologies

Ability to succinctly articulate complex technical issues to both technicians and business sponsors

Knowledge of audit controls and applicability to IAM services architecture, design, and processes

Experience working in an Agile/Scrum and the Product Operating Model

Personal Attributes

Strong analytical, problem-solving and troubleshooting skills

High level critical thinking skills

Excellent written and oral communication skills

Ability to compose and present material that communicates difficult concepts

Positive attitude, self-starter with strong communication and interpersonal skills to lead working groups, negotiate and create consensus

Comfortable working in a dynamic environment with multiple goals

Highly self-motivated and directed, with keen attention to detail

Able to prioritize and execute tasks in a high-pressure environment

Ability to deal diplomatically and effectively at all levels of the organization including both technical and non-technical, management and senior leadership

Education & Certification

A Bachelor's or Master's degree in Computer Science or Information Systems or equivalent combination of education and related work experience

CyberArk/Idira certifications or equivalent experience

GCP or similar cloud certifications a plus

Security certifications: CISSP or equivalent a plus

CME Group is committed to offering a competitive total rewards package for our employees that recognizes their contributions to the business and reflects our long-term investment in their future. The pay range for this role is $132,100-$220,100. Actual salary offered will be dependent on a wide array of factors including but not limited to: relevant experience, skills, education and comparison to internal employees (where relevant). Our compensation program also includes an annual target bonus opportunity for all employees, as well as the opportunity to become an owner in the company through our broad-based equity program. Through our benefits program, we strive to offer flexibility, value and choice. From comprehensive health coverage, to a retirement package that includes both a 401(k) and an active pension plan, to highly competitive education reimbursement provisions, paid time off and a mental health benefit, CME Group offers a holistic benefits package for our team and their dependents.

CME Group: Where Futures are Made

CME Group is the world’s leading derivatives marketplace. But who we are goes deeper than that. Here, you can impact markets worldwide. Transform industries. And build a career by shaping tomorrow. We invest in your success and you own it – all while working alongside a team of leading experts who inspire you in ways big and small. Problem solvers, difference makers, trailblazers. Those are our people. And we’re looking for more.

At CME Group, we embrace our employees' unique experiences and skills to ensure that everyone’s perspectives are acknowledged and valued. As an equal-opportunity employer, we consider all potential employees without regard to any protected characteristic.

Important Notice: Recruitment fraud is on the rise, with scammers using misleading promises of job offers and interviews to solicit money and personal information from job seekers. CME Group adheres to established procedures designed to maintain trust, confidence and security throughout our recruitment process. Learn more here.