Hiring.Camp

Cyber Defense Monitoring Engineer – Automation & AI

Cmegroup

·

Today

Location
Bangalore - Bagmane Tridib, India
Type
Full-time
Department
Engineering
Source
Workday

Description

Position Overview:  We are seeking a forward-thinking Cyber Defense Monitoring (CDM) Level 3 to help lead our transition toward an AI-driven, agentic Security Operations Center (SOC). Unlike a traditional analyst role, this position requires an engineering mindset. In addition to daily SOC operations, you will actively look for opportunities to improve processes, assist in writing and maintaining automation scripts, and support the development of automated playbooks. This role is a stepping stone for bridging core cyber defense operations with modern automation and engineering practices. 

You will act as the senior escalation point for complex threats while dedicating significant time to engineering autonomous workflows, integrating Large Language Models (LLMs) into investigation pipelines, and applying data science principles to threat detection. 

Automation, AI & Agentic SOC Engineering 

  • Build the Agentic SOC: Design, train, and deploy AI-driven autonomous agents capable of performing tier-1 and tier-2 triage, context gathering, and initial containment without human intervention. 

  • SOAR & Playbook Engineering: Architect and write complex automation playbooks utilizing Python, REST APIs, and modern SOAR platforms to streamline incident response lifecycles. 

  • Data Science & Machine Learning: Apply data analytics and ML models to massive security datasets to identify anomalous behaviors, reduce false positive rates, and improve the fidelity of SIEM alerts. 

  • Detection as Code (DaC): Implement software engineering best practices (CI/CD pipelines, version control, automated testing) for the deployment and management of security rules and detection logic. 

  • Continuous Optimization: Proactively identify bottlenecks in current SOC workflows and engineer programmatic solutions to reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). 

Cyber Defense Operations

  • Advanced Escalation & Response: Serve as the final technical escalation point (Level 3) for the more complex and severe security events, directing the triage of advanced persistent threats (APTs). 

  • Threat Hunting & Intel: Conduct proactive, hypothesis-driven threat hunts across the enterprise and integrate actionable threat intelligence into automated defense mechanisms. 

  • Security Stack Oversight: Oversee the health, tuning, and strategic direction of core monitoring tools (SIEM, EDR, NDR), ensuring they generate high-quality data for our automation engines. 

Qualifications & Skills 

  • Advanced proficiency in scripting and programming languages (e.g., Python, Go, or PowerShell) with a strong understanding of interacting with RESTful APIs and JSON/XML data structures. 

  • Experience working with LLMs, prompt engineering, AI orchestration frameworks (like LangChain), and foundational data science tools (Pandas, Jupyter, SQL). 

  • 5+ years of progressive experience in a SOC or Incident Response environment, with deep knowledge of network protocols, operating system internals (Windows/Linux), and adversary tactics (MITRE ATT&CK). 

  • Hands-on experience architecting workflows in leading SOAR platforms (e.g., Cortex XSOAR, Splunk SOAR, Torq, or Tines). 

  • BA/BS in Engineering, Computer Science, or Information Security (non-tech degrees acceptable with appropriate levels of Information Security job experience and/or certifications)

  • A blend of security and engineering certifications such as GCIA, GCFA, AWS Certified Security / Machine Learning, or relevant SANS automation courses (e.g., SEC573, SEC540). 

CME Group: Where Futures are Made

CME Group is the world’s leading derivatives marketplace. But who we are goes deeper than that. Here, you can impact markets worldwide. Transform industries. And build a career by shaping tomorrow. We invest in your success and you own it – all while working alongside a team of leading experts who inspire you in ways big and small. Problem solvers, difference makers, trailblazers. Those are our people. And we’re looking for more.

At CME Group, we embrace our employees' unique experiences and skills to ensure that everyone’s perspectives are acknowledged and valued. As an equal-opportunity employer, we consider all potential employees without regard to any protected characteristic.

Important Notice: Recruitment fraud is on the rise, with scammers using misleading promises of job offers and interviews to solicit money and personal information from job seekers. CME Group adheres to established procedures designed to maintain trust, confidence and security throughout our recruitment process. Learn more here.

Skills

PythonAWSCI/CDLinuxSQLMachine LearningPandasData ScienceSIEMSOCSplunkRESTAWS CertifiedGo

Similar Jobs

1

Security Architect (Cloud Monitoring & Response) - Product Security Section, Cyber Security Defense Department (CSDD)

Rakuten·Rakuten Crimson House, Japan·Hybrid

2mo ago