Staff Cyber Defense Engineer (SOC Lead) – Automation & AI

Posted 10 Hours Ago
Be an Early Applicant
Bangalore, Bengaluru Urban, Karnataka, IND
In-Office
Senior level
Financial Services
The Role
Lead the transition to an AI-driven, automated SOC by defining the automation roadmap, overseeing SOAR integrations and Detection as Code pipelines, mentoring engineers, and applying machine learning to security data. Serve as incident commander for major breaches, supervise threat hunting and intelligence programs, manage SIEM, EDR, NDR, and cloud security integrations, and optimize workflows to reduce detection and response times.
Summary Generated by Built In

We are seeking a visionary Lead Cyber Defense Monitoring Engineer to direct our transition toward an AI-driven, agentic Security Operations Center (SOC). Unlike a traditional analyst or leadership role, this position requires a hands-on engineering mindset. In addition to overseeing daily SOC operations, you will actively look for opportunities to improve processes, architect and govern complex automation scripts, and lead the team in the development of automated playbooks. This role is the cornerstone for bridging core cyber defense operations with modern automation, machine learning, and engineering practices.

As the Lead, you will define the automation roadmap, mentor senior engineers, serve as the Incident Commander during critical breaches, and pioneer the integration of Large Language Models (LLMs) and data science into our overarching defense strategy.

Key Responsibilities

Automation, AI & Agentic SOC Strategy

  • Translate the organization's strategic roadmap into actionable team goals. Ensure the team successfully deploys and scales AI-driven autonomous agents capable of performing triage, context gathering, and initial containment. 

  • Oversee the team's automation deliverables and SOAR integrations. Enforce coding standards, manage the peer-review pipeline for Python/REST API scripts, and ensure strict team adherence to Detection as Code (DaC) CI/CD pipelines. 

  • Direct the daily work of the engineering and analyst teams. Foster an engineering-first culture by ensuring staff receive the training and guidance needed to upskill in prompt engineering, script writing, and modern data practices. 

  • Supervise the team's application of data analytics and machine learning models to enterprise security datasets, ensuring their work results in high-fidelity alerting and a reduction in false positives. 

  • Hold the team accountable for key performance indicators (KPIs) related to automation efficacy. Ensure the team consistently optimizes SOC workflows to drastically reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). 

Consolidated Cyber Defense Leadership 

  • Serve as the Incident Commander for major security events and high-severity breaches, orchestrating the response efforts of your team and coordinating with executive leadership. 

  • Supervise overarching threat hunting and intelligence programs. Ensure the team actively takes novel threats and APT behaviors discovered during hunts and operationalizes them into automated detections. 

  • Manage the holistic health and integration of the core security stack (SIEM, EDR, NDR, Cloud Security), ensuring your team maintains maximum ROI and data quality for the AI engines. 

Qualifications & Skills 

  • 7+ years of progressive experience in a SOC, Incident Response, or Security Engineering environment, with 2+ years of direct supervisory or team lead experience overseeing technical staff. 

  • Strong conceptual understanding of applied machine learning in cybersecurity, LLM orchestration frameworks, and data pipelines to effectively manage and evaluate the engineering team's output. 

  • Expert-level knowledge of adversary tactics (MITRE ATT&CK), network architecture, and forensic analysis, coupled with proven experience leading technical incident response under pressure. 

  • Strong familiarity with the capabilities and governance of enterprise SOAR platforms (e.g., Cortex XSOAR, Splunk SOAR, Torq, or Tines) to effectively guide team deliverables. 

  • BA/BS in Engineering, Computer Science, or Information Security (non-tech degrees acceptable with appropriate levels of Information Security job experience and/or certifications)

  • Advanced security, engineering, or leadership certifications such as GSE, GCIA, GCFA, CISSP, AWS Certified Security / Machine Learning, or SANS SEC573/SEC540/MGT512.

CME Group: Where Futures are Made

CME Group is the world’s leading derivatives marketplace. But who we are goes deeper than that. Here, you can impact markets worldwide. Transform industries. And build a career by shaping tomorrow. We invest in your success and you own it – all while working alongside a team of leading experts who inspire you in ways big and small. Problem solvers, difference makers, trailblazers. Those are our people. And we’re looking for more.

At CME Group, we embrace our employees' unique experiences and skills to ensure that everyone’s perspectives are acknowledged and valued. As an equal-opportunity employer, we consider all potential employees without regard to any protected characteristic.

Important Notice: Recruitment fraud is on the rise, with scammers using misleading promises of job offers and interviews to solicit money and personal information from job seekers. CME Group adheres to established procedures designed to maintain trust, confidence and security throughout our recruitment process. Learn more here.

Skills Required

  • 7+ years of progressive experience in a SOC, incident response, or security engineering environment
  • 2+ years of direct supervisory or team lead experience overseeing technical staff
  • Understanding of applied machine learning in cybersecurity, LLM orchestration frameworks, and data pipelines
  • Expert knowledge of adversary tactics, MITRE ATT&CK, network architecture, and forensic analysis
  • Experience leading technical incident response under pressure
  • Familiarity with enterprise SOAR platforms such as Cortex XSOAR, Splunk SOAR, Torq, or Tines
  • BA or BS in Engineering, Computer Science, or Information Security, or equivalent security experience and certifications
  • Advanced security, engineering, or leadership certification such as GSE, GCIA, GCFA, CISSP, AWS Certified Security or Machine Learning, or SANS SEC573, SEC540, or MGT512

CME Group Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about CME Group and has not been reviewed or approved by CME Group.

  • Retirement Support — U.S. offerings include both a 401(k) and a company-funded cash-balance pension, strengthening long-term financial security. This dual-track structure is highlighted as a notable differentiator among private employers.
  • Leave & Time Off Breadth — PTO and holiday schedules are described as generous, with ample time off and carryover commonly highlighted. This breadth of leave meaningfully enhances perceived total rewards.
  • Flexible Benefits — A flexible, hybrid work model applies to many roles, increasing day-to-day usability of the package. Flexibility is framed as a standard feature rather than an exception.

CME Group Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
3,291 Employees

What We Do

As the world's leading derivatives marketplace, CME Group (www.cmegroup.com) is where the world comes to manage risk. CME Group exchanges offer the widest range of global benchmark products across all major asset classes, including futures and options based on interest rates, equity indexes, foreign exchange, energy, agricultural commodities, metals, weather and real estate. CME Group brings buyers and sellers together through its CME Globex® electronic trading platform and its trading facilities in New York and Chicago. CME Group also operates CME Clearing, one of the world’s leading central counterparty clearing provider in the world, which offers clearing and settlement services for exchange-traded contracts, as well as for over-the-counter derivatives transactions through CME ClearPort®. These products and services ensure that businesses everywhere can substantially mitigate counterparty credit risk in both listed and over-the-counter derivatives markets.

Similar Jobs

ZS Logo ZS

Consultant

Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Hybrid
3 Locations
15000 Employees

ZS Logo ZS

Associate - Platform Services

Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Hybrid
4 Locations
15000 Employees

ZS Logo ZS

Business Technology Solutions Associate

Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Hybrid
5 Locations
15000 Employees

ZS Logo ZS

Decision Analytics Associate

Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Hybrid
5 Locations
15000 Employees

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account