We are seeking a visionary Lead Cyber Defense Monitoring Engineer to direct our transition toward an AI-driven, agentic Security Operations Center (SOC). Unlike a traditional analyst or leadership role, this position requires a hands-on engineering mindset. In addition to overseeing daily SOC operations, you will actively look for opportunities to improve processes, architect and govern complex automation scripts, and lead the team in the development of automated playbooks. This role is the cornerstone for bridging core cyber defense operations with modern automation, machine learning, and engineering practices.
As the Lead, you will define the automation roadmap, mentor senior engineers, serve as the Incident Commander during critical breaches, and pioneer the integration of Large Language Models (LLMs) and data science into our overarching defense strategy.
Key ResponsibilitiesAutomation, AI & Agentic SOC Strategy
Translate the organization's strategic roadmap into actionable team goals. Ensure the team successfully deploys and scales AI-driven autonomous agents capable of performing triage, context gathering, and initial containment.
Oversee the team's automation deliverables and SOAR integrations. Enforce coding standards, manage the peer-review pipeline for Python/REST API scripts, and ensure strict team adherence to Detection as Code (DaC) CI/CD pipelines.
Direct the daily work of the engineering and analyst teams. Foster an engineering-first culture by ensuring staff receive the training and guidance needed to upskill in prompt engineering, script writing, and modern data practices.
Supervise the team's application of data analytics and machine learning models to enterprise security datasets, ensuring their work results in high-fidelity alerting and a reduction in false positives.
Hold the team accountable for key performance indicators (KPIs) related to automation efficacy. Ensure the team consistently optimizes SOC workflows to drastically reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
Consolidated Cyber Defense Leadership
Serve as the Incident Commander for major security events and high-severity breaches, orchestrating the response efforts of your team and coordinating with executive leadership.
Supervise overarching threat hunting and intelligence programs. Ensure the team actively takes novel threats and APT behaviors discovered during hunts and operationalizes them into automated detections.
Manage the holistic health and integration of the core security stack (SIEM, EDR, NDR, Cloud Security), ensuring your team maintains maximum ROI and data quality for the AI engines.
Qualifications & Skills
7+ years of progressive experience in a SOC, Incident Response, or Security Engineering environment, with 2+ years of direct supervisory or team lead experience overseeing technical staff.
Strong conceptual understanding of applied machine learning in cybersecurity, LLM orchestration frameworks, and data pipelines to effectively manage and evaluate the engineering team's output.
Expert-level knowledge of adversary tactics (MITRE ATT&CK), network architecture, and forensic analysis, coupled with proven experience leading technical incident response under pressure.
Strong familiarity with the capabilities and governance of enterprise SOAR platforms (e.g., Cortex XSOAR, Splunk SOAR, Torq, or Tines) to effectively guide team deliverables.
BA/BS in Engineering, Computer Science, or Information Security (non-tech degrees acceptable with appropriate levels of Information Security job experience and/or certifications)
Advanced security, engineering, or leadership certifications such as GSE, GCIA, GCFA, CISSP, AWS Certified Security / Machine Learning, or SANS SEC573/SEC540/MGT512.
CME Group: Where Futures are Made
CME Group is the world’s leading derivatives marketplace. But who we are goes deeper than that. Here, you can impact markets worldwide. Transform industries. And build a career by shaping tomorrow. We invest in your success and you own it – all while working alongside a team of leading experts who inspire you in ways big and small. Problem solvers, difference makers, trailblazers. Those are our people. And we’re looking for more.
At CME Group, we embrace our employees' unique experiences and skills to ensure that everyone’s perspectives are acknowledged and valued. As an equal-opportunity employer, we consider all potential employees without regard to any protected characteristic.
Important Notice: Recruitment fraud is on the rise, with scammers using misleading promises of job offers and interviews to solicit money and personal information from job seekers. CME Group adheres to established procedures designed to maintain trust, confidence and security throughout our recruitment process. Learn more here.
Skills Required
- 7+ years of progressive experience in a SOC, incident response, or security engineering environment
- 2+ years of direct supervisory or team lead experience overseeing technical staff
- Understanding of applied machine learning in cybersecurity, LLM orchestration frameworks, and data pipelines
- Expert knowledge of adversary tactics, MITRE ATT&CK, network architecture, and forensic analysis
- Experience leading technical incident response under pressure
- Familiarity with enterprise SOAR platforms such as Cortex XSOAR, Splunk SOAR, Torq, or Tines
- BA or BS in Engineering, Computer Science, or Information Security, or equivalent security experience and certifications
- Advanced security, engineering, or leadership certification such as GSE, GCIA, GCFA, CISSP, AWS Certified Security or Machine Learning, or SANS SEC573, SEC540, or MGT512
CME Group Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about CME Group and has not been reviewed or approved by CME Group.
-
Retirement Support — U.S. offerings include both a 401(k) and a company-funded cash-balance pension, strengthening long-term financial security. This dual-track structure is highlighted as a notable differentiator among private employers.
-
Leave & Time Off Breadth — PTO and holiday schedules are described as generous, with ample time off and carryover commonly highlighted. This breadth of leave meaningfully enhances perceived total rewards.
-
Flexible Benefits — A flexible, hybrid work model applies to many roles, increasing day-to-day usability of the package. Flexibility is framed as a standard feature rather than an exception.
CME Group Insights
What We Do
As the world's leading derivatives marketplace, CME Group (www.cmegroup.com) is where the world comes to manage risk. CME Group exchanges offer the widest range of global benchmark products across all major asset classes, including futures and options based on interest rates, equity indexes, foreign exchange, energy, agricultural commodities, metals, weather and real estate. CME Group brings buyers and sellers together through its CME Globex® electronic trading platform and its trading facilities in New York and Chicago. CME Group also operates CME Clearing, one of the world’s leading central counterparty clearing provider in the world, which offers clearing and settlement services for exchange-traded contracts, as well as for over-the-counter derivatives transactions through CME ClearPort®. These products and services ensure that businesses everywhere can substantially mitigate counterparty credit risk in both listed and over-the-counter derivatives markets.






