Cyber Defense Monitoring Engineer – Automation & AI

Posted 12 Days Ago
Be an Early Applicant
Bangalore, Bengaluru Urban, Karnataka, IND
In-Office
Senior level
Financial Services
The Role
Leads Level 3 cyber defense monitoring and complex incident escalation while engineering an AI-driven SOC. Designs autonomous agents, SOAR playbooks, detection-as-code workflows, and LLM-integrated investigation pipelines. Applies machine learning and data analytics to improve threat detection and reduce false positives. Conducts threat hunting, oversees SIEM/EDR/NDR platforms, integrates threat intelligence, and optimizes SOC workflows to reduce detection and response times.
Summary Generated by Built In

Position Overview:  We are seeking a forward-thinking Cyber Defense Monitoring (CDM) Level 3 to help lead our transition toward an AI-driven, agentic Security Operations Center (SOC). Unlike a traditional analyst role, this position requires an engineering mindset. In addition to daily SOC operations, you will actively look for opportunities to improve processes, assist in writing and maintaining automation scripts, and support the development of automated playbooks. This role is a stepping stone for bridging core cyber defense operations with modern automation and engineering practices. 

You will act as the senior escalation point for complex threats while dedicating significant time to engineering autonomous workflows, integrating Large Language Models (LLMs) into investigation pipelines, and applying data science principles to threat detection. 

Automation, AI & Agentic SOC Engineering 

  • Build the Agentic SOC: Design, train, and deploy AI-driven autonomous agents capable of performing tier-1 and tier-2 triage, context gathering, and initial containment without human intervention. 

  • SOAR & Playbook Engineering: Architect and write complex automation playbooks utilizing Python, REST APIs, and modern SOAR platforms to streamline incident response lifecycles. 

  • Data Science & Machine Learning: Apply data analytics and ML models to massive security datasets to identify anomalous behaviors, reduce false positive rates, and improve the fidelity of SIEM alerts. 

  • Detection as Code (DaC): Implement software engineering best practices (CI/CD pipelines, version control, automated testing) for the deployment and management of security rules and detection logic. 

  • Continuous Optimization: Proactively identify bottlenecks in current SOC workflows and engineer programmatic solutions to reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). 

Cyber Defense Operations

  • Advanced Escalation & Response: Serve as the final technical escalation point (Level 3) for the more complex and severe security events, directing the triage of advanced persistent threats (APTs). 

  • Threat Hunting & Intel: Conduct proactive, hypothesis-driven threat hunts across the enterprise and integrate actionable threat intelligence into automated defense mechanisms. 

  • Security Stack Oversight: Oversee the health, tuning, and strategic direction of core monitoring tools (SIEM, EDR, NDR), ensuring they generate high-quality data for our automation engines. 

Qualifications & Skills 

  • Advanced proficiency in scripting and programming languages (e.g., Python, Go, or PowerShell) with a strong understanding of interacting with RESTful APIs and JSON/XML data structures. 

  • Experience working with LLMs, prompt engineering, AI orchestration frameworks (like LangChain), and foundational data science tools (Pandas, Jupyter, SQL). 

  • 5+ years of progressive experience in a SOC or Incident Response environment, with deep knowledge of network protocols, operating system internals (Windows/Linux), and adversary tactics (MITRE ATT&CK). 

  • Hands-on experience architecting workflows in leading SOAR platforms (e.g., Cortex XSOAR, Splunk SOAR, Torq, or Tines). 

  • BA/BS in Engineering, Computer Science, or Information Security (non-tech degrees acceptable with appropriate levels of Information Security job experience and/or certifications)

  • A blend of security and engineering certifications such as GCIA, GCFA, AWS Certified Security / Machine Learning, or relevant SANS automation courses (e.g., SEC573, SEC540). 

CME Group: Where Futures are Made

CME Group is the world’s leading derivatives marketplace. But who we are goes deeper than that. Here, you can impact markets worldwide. Transform industries. And build a career by shaping tomorrow. We invest in your success and you own it – all while working alongside a team of leading experts who inspire you in ways big and small. Problem solvers, difference makers, trailblazers. Those are our people. And we’re looking for more.

At CME Group, we embrace our employees' unique experiences and skills to ensure that everyone’s perspectives are acknowledged and valued. As an equal-opportunity employer, we consider all potential employees without regard to any protected characteristic.

Important Notice: Recruitment fraud is on the rise, with scammers using misleading promises of job offers and interviews to solicit money and personal information from job seekers. CME Group adheres to established procedures designed to maintain trust, confidence and security throughout our recruitment process. Learn more here.

Skills Required

  • Advanced proficiency in Python, Go, or PowerShell scripting and programming
  • Strong understanding of RESTful APIs and JSON/XML data structures
  • Experience with LLMs, prompt engineering, and AI orchestration frameworks such as LangChain
  • Experience with foundational data science tools including Pandas, Jupyter, and SQL
  • At least 5 years of progressive experience in a SOC or incident response environment
  • Deep knowledge of network protocols, Windows/Linux operating system internals, and MITRE ATT&CK
  • Hands-on experience architecting workflows in SOAR platforms such as Cortex XSOAR, Splunk SOAR, Torq, or Tines
  • BA or BS in Engineering, Computer Science, or Information Security, or equivalent security experience and certifications
  • Security and engineering certifications such as GCIA, GCFA, AWS Certified Security/Machine Learning, or relevant SANS automation courses

CME Group Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about CME Group and has not been reviewed or approved by CME Group.

  • Retirement Support — U.S. offerings include both a 401(k) and a company-funded cash-balance pension, strengthening long-term financial security. This dual-track structure is highlighted as a notable differentiator among private employers.
  • Leave & Time Off Breadth — PTO and holiday schedules are described as generous, with ample time off and carryover commonly highlighted. This breadth of leave meaningfully enhances perceived total rewards.
  • Flexible Benefits — A flexible, hybrid work model applies to many roles, increasing day-to-day usability of the package. Flexibility is framed as a standard feature rather than an exception.

CME Group Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
3,291 Employees

What We Do

As the world's leading derivatives marketplace, CME Group (www.cmegroup.com) is where the world comes to manage risk. CME Group exchanges offer the widest range of global benchmark products across all major asset classes, including futures and options based on interest rates, equity indexes, foreign exchange, energy, agricultural commodities, metals, weather and real estate. CME Group brings buyers and sellers together through its CME Globex® electronic trading platform and its trading facilities in New York and Chicago. CME Group also operates CME Clearing, one of the world’s leading central counterparty clearing provider in the world, which offers clearing and settlement services for exchange-traded contracts, as well as for over-the-counter derivatives transactions through CME ClearPort®. These products and services ensure that businesses everywhere can substantially mitigate counterparty credit risk in both listed and over-the-counter derivatives markets.

Similar Jobs

Atlassian Logo Atlassian

Senior Engineering Manager

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
Bengaluru, Bengaluru Urban, Karnataka, IND
11000 Employees

Atlassian Logo Atlassian

Senior Engineering Manager

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
Bengaluru, Bengaluru Urban, Karnataka, IND
11000 Employees

Atlassian Logo Atlassian

Senior Engineering Manager

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
Bengaluru, Bengaluru Urban, Karnataka, IND
11000 Employees

Coursera + Udemy  Logo Coursera + Udemy

Accounts Payable Specialist

Artificial Intelligence • Consumer Web • Edtech • Enterprise Web • HR Tech • Social Impact • Generative AI
Remote or Hybrid
India
1500 Employees

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account