Security Engineer III
2 days ago
The Application Security Engineer leads efforts to enhance application security and the secure software development lifecycle. This individual is responsible for performing manual application security assessments (application pentests) and communicating security findings to the developers and QA teams. Additionally, the individual will provide application design support and security best practice guidance, in the form of consultations, to various development teams and business stakeholders. This individual will also actively promote security through engaging interactive workshops and exercises, such as internal Capture The Flag (CTF) events.
Principal Accountabilities
Serve as the primary application security expert for development teams, offering security consulting and best practice guidance throughout the Software Development Life Cycle (SDLC).
Perform manual security assessments at key points in the SDLC.
Produce documentation (reports) and present findings of manual security assessments to various stakeholders, including senior leadership.
Participate in security architecture reviews and threat modelling.
Contribute to automation initiatives, including the integration of new security tools and processes (e.g., AI).
Demonstrate a commitment to continuous education and staying current within the application security domain, promoting collaboration and knowledge sharing.
Skills Requirements:
5+ years experience with industry standard penetration testing, or ability to demonstrate equivalent knowledge.
Expertise performing blackbox/greybox/whitebox security assessments of applications (e.g., web applications, APIs, thick clients, web sockets) which use HTTP and/or proprietary protocols.
Expert level skills with application security testing tools including: Burpsuite, sqlmap, nmap, etc.
Experience performing manual reviews of application source code for security vulnerabilities written in various languages including: Java, Javascript, .Net (C#), etc.
Experience with Cloud architectures, security principles and services. Google Cloud Platform (GCP) is preferred.
Experience with automating security testing and/or other relevant activities to streamline service delivery. Preferred scripting languages: Python, bash, Powershell, etc.
Experience with UNIX or Linux.
A self-starter who is highly motivated. Proactively seek answers, ask for help when needed, and communicate solutions.
Excellent Oral and Written communications skills. Ability to effectively communicate and interface with peers and stakeholders at all levels, including senior leadership.
Nice to have:
Experience in securing modern APIs, including knowledge of authentication/authorization standards like OAuth 2.0 and JWT, and understanding API-specific vulnerabilities.
Experience in conducting formal threat modeling using frameworks like STRIDE to identify potential security flaws in the design phase.
Experience with AI/ML security testing methodologies, including understanding of OWASP Top 10 for Large Language Models (LLMs) and common AI security vulnerabilities, and using AI to improve pentesting.
Experience with prior development work.
Experience with application reverse engineering and using tools such as: Java decompilers, .Net decompilers, IDAPro, etc.
Experience with Capture The Flag (CTF) competitions and bug bounty programs.
Relevant industry certifications such as OSCP, eWPTX, CCSP, GCP Professional Cloud Security Engineer, etc.
CME Group: Where Futures are Made
CME Group is the world's leading derivatives marketplace. But who we are goes deeper than that. Here, you can impact markets worldwide. Transform industries. And build a career by shaping tomorrow. We invest in your success and you own it – all while working alongside a team of leading experts who inspire you in ways big and small. Problem solvers, difference makers, trailblazers. Those are our people. And we're looking for more.
At CME Group, we embrace our employees' unique experiences and skills to ensure that everyone's perspectives are acknowledged and valued. As an equal-opportunity employer, we consider all potential employees without regard to any protected characteristic.
Important Notice: Recruitment fraud is on the rise, with scammers using misleading promises of job offers and interviews to solicit money and personal information from job seekers. CME Group adheres to established procedures designed to maintain trust, confidence and security throughout our recruitment process. Learn more here.
-
Security Engineer III
3 days ago
Bangalore - Bagmane Tridib, India CME Group Full time ₹ 6,00,000 - ₹ 18,00,000 per yearThe Application Security Engineer is responsible for providing leadership on how to best improve our application security and secure software development lifecycle. This individual is responsible for performing manual application security assessments (application pentests) and communicating any findings to the developers and QA teams. Additionally, the...
-
Software Engineer III
1 week ago
Bangalore - Bagmane Tridib, India CME Group Full time ₹ 15,00,000 - ₹ 25,00,000 per yearThe Software Engineer III engineers secure, scalable and reliable technology solutions, with appropriate mentoring, to advance CMEG in the global marketplace and serve risk management needs of customers around the world.Principal Accountabilities:•Intermediate proficiency in language knowledge; Writes application modules and unit tests with...
-
Network Ops Engineer III
2 weeks ago
Bangalore - Bagmane Tridib, India CME Group Full time ₹ 12,00,000 - ₹ 36,00,000 per yearDescription:This is a full-time NOCC Engineer role. The NOCC Engineer will be responsible for monitoring and maintaining network systems, identifying and troubleshooting issues. You would be working closely with the Incident Management, IT teams and 3rd party service providers to ensure the availability of all systems & applications to our internal users &...
-
QA Automation Engineer
5 days ago
Bangalore - Bagmane Tridib, India CME Group Full time ₹ 12,00,000 - ₹ 24,00,000 per yearThe QA Analyst III is an experienced test engineer w/ strong technical skills & business knowledge to independently analyze requirements, create & execute QA test cases, deliver & support any feature in the software application. The incumbent should be familiar w/ principle testing methodologies, & be capable to establish & maintain testing environments,...
-
Security Engineer Iii
2 days ago
Bangalore, Karnataka, India JPMorgan Chase Full timeJob Category Security Engineering Your seniority as a security engineer puts you in the ranks of the top talent in your field Play a critical role at one of the world s most iconic financial institutions where security is vital As a Security Engineer III at JPMorganChase within the Cybersecurity Technology Controls team you serve as a seasoned member of a...
-
Software Engineer II
2 weeks ago
Bangalore - Bagmane Tridib, India CME Group Full time ₹ 12,00,000 - ₹ 36,00,000 per yearThe Software Engineer II engineers secure, scalable and reliable technology solutions, with appropriate mentoring, to advance CMEG in the global marketplace and serve risk management needs of customers around the world.Principal Accountabilities:• Conducts coding at a medium task level including design• Conducts unit testing of own code. Reviews unit...
-
Security Engineer Iii
2 weeks ago
Bangalore, Karnataka, India JPMorgan Chase Full timeJob Category Security Engineering Description Your seniority as a security engineer puts you in the ranks of the top talent in your field Play a critical role at one of the world s most iconic financial institutions where security is vital As a Security Engineer III at JPMorgan Chase within the Cybersecurity Tech Controls team you serve as a seasoned member...
-
Software Engineer I – India
3 days ago
Bangalore - Bagmane Tridib, India CME Group Full time ₹ 40,00,000 - ₹ 80,00,000 per yearThe Software Engineer I engineers secure, scalable and reliable technology solutions, with appropriate mentoring, to advance CMEG in the global marketplace and serve risk management needs of customers around the world.Principal Accountabilities:• Writes Java code at story level; potentially minimal design and aligns with overall milestones• Conducts unit...
-
Sr Platform Engineer
1 day ago
Bangalore - Bagmane Tridib, India Chicago Mercantile Exchange Full time ₹ 12,00,000 - ₹ 24,00,000 per yearThe Platform Engineering team is a collection of highly skilled individuals ranging from development to operations with a security first mindset who strive to push the boundaries of technology. We champion a DevSecOps culture and raise the bar on how and when we deploy applications to production. Our core principals are centered around automation, testing,...
-
Site Reliability Engineer II
2 weeks ago
Bangalore - Bagmane Tridib, India CME Group Full time ₹ 8,00,000 - ₹ 16,00,000 per yearDescription:CME Group is seeking a SRE II to help, build, operate and scale systems in our Markets portfolio. Markets SREs work on products and applications related to CME's Globex trading platform. Our systems deliver an exceptional combination of low-latency performance and rock-solid reliability to seamlessly handle the world's busiest trading days.The...