Security Engineer III
19 hours ago
The Application Security Engineer leads efforts to enhance application security and the secure software development lifecycle. This individual is responsible for performing manual application security assessments (application pentests) and communicating security findings to the developers and QA teams. Additionally, the individual will provide application design support and security best practice guidance, in the form of consultations, to various development teams and business stakeholders. This individual will also actively promote security through engaging interactive workshops and exercises, such as internal Capture The Flag (CTF) events.
Principal Accountabilities
Serve as the primary application security expert for development teams, offering security consulting and best practice guidance throughout the Software Development Life Cycle (SDLC).
Perform manual security assessments at key points in the SDLC.
Produce documentation (reports) and present findings of manual security assessments to various stakeholders, including senior leadership.
Participate in security architecture reviews and threat modelling.
Contribute to automation initiatives, including the integration of new security tools and processes (e.g., AI).
Demonstrate a commitment to continuous education and staying current within the application security domain, promoting collaboration and knowledge sharing.
Skills Requirements:
5+ years experience with industry standard penetration testing, or ability to demonstrate equivalent knowledge.
Expertise performing blackbox/greybox/whitebox security assessments of applications (e.g., web applications, APIs, thick clients, web sockets) which use HTTP and/or proprietary protocols.
Expert level skills with application security testing tools including: Burpsuite, sqlmap, nmap, etc.
Experience performing manual reviews of application source code for security vulnerabilities written in various languages including: Java, Javascript, .Net (C#), etc.
Experience with Cloud architectures, security principles and services. Google Cloud Platform (GCP) is preferred.
Experience with automating security testing and/or other relevant activities to streamline service delivery. Preferred scripting languages: Python, bash, Powershell, etc.
Experience with UNIX or Linux.
A self-starter who is highly motivated. Proactively seek answers, ask for help when needed, and communicate solutions.
Excellent Oral and Written communications skills. Ability to effectively communicate and interface with peers and stakeholders at all levels, including senior leadership.
Nice to have:
Experience in securing modern APIs, including knowledge of authentication/authorization standards like OAuth 2.0 and JWT, and understanding API-specific vulnerabilities.
Experience in conducting formal threat modeling using frameworks like STRIDE to identify potential security flaws in the design phase.
Experience with AI/ML security testing methodologies, including understanding of OWASP Top 10 for Large Language Models (LLMs) and common AI security vulnerabilities, and using AI to improve pentesting.
Experience with prior development work.
Experience with application reverse engineering and using tools such as: Java decompilers, .Net decompilers, IDAPro, etc.
Experience with Capture The Flag (CTF) competitions and bug bounty programs.
Relevant industry certifications such as OSCP, eWPTX, CCSP, GCP Professional Cloud Security Engineer, etc.
CME Group: Where Futures are Made
CME Group is the world's leading derivatives marketplace. But who we are goes deeper than that. Here, you can impact markets worldwide. Transform industries. And build a career by shaping tomorrow. We invest in your success and you own it – all while working alongside a team of leading experts who inspire you in ways big and small. Problem solvers, difference makers, trailblazers. Those are our people. And we're looking for more.
At CME Group, we embrace our employees' unique experiences and skills to ensure that everyone's perspectives are acknowledged and valued. As an equal-opportunity employer, we consider all potential employees without regard to any protected characteristic.
Important Notice: Recruitment fraud is on the rise, with scammers using misleading promises of job offers and interviews to solicit money and personal information from job seekers. CME Group adheres to established procedures designed to maintain trust, confidence and security throughout our recruitment process. Learn more here.
-
Network Ops Engineer III
1 week ago
Bangalore - Bagmane Tridib, India CME Group Full time ₹ 12,00,000 - ₹ 36,00,000 per yearDescription:This is a full-time NOCC Engineer role. The NOCC Engineer will be responsible for monitoring and maintaining network systems, identifying and troubleshooting issues. You would be working closely with the Incident Management, IT teams and 3rd party service providers to ensure the availability of all systems & applications to our internal users &...
-
QA Automation Engineer
6 days ago
Bangalore - Bagmane Tridib, India CME Group Full time ₹ 12,00,000 - ₹ 24,00,000 per yearThe QA Analyst III is an experienced test engineer w/ strong technical skills & business knowledge to independently analyze requirements, create & execute QA test cases, deliver & support any feature in the software application. The incumbent should be familiar w/ principle testing methodologies, & be capable to establish & maintain testing environments,...
-
Security Platform Engineer Iii
2 weeks ago
Bangalore, Karnataka, India Eli Lilly Full timeAt Lilly we unite caring with discovery to make life better for people around the world We are a global healthcare leader headquartered in Indianapolis Indiana Our employees around the world work to discover and bring life-changing medicines to those who need them improve the understanding and management of disease and give back to our communities through...
-
Security Engineer Iii
3 weeks ago
Bangalore, Karnataka, India JPMorgan Chase Full timeJob Category Security Engineering Your seniority as a security engineer puts you in the ranks of the top talent in your field Play a critical role at one of the world s most iconic financial institutions where security is vital As a Security Engineer III at JPMorganChase within the Cybersecurity Technology Controls team you serve as a seasoned member of a...
-
Sr. Platform Engineer
1 week ago
Bangalore - Bagmane Tridib, India CME Group Full time ₹ 12,00,000 - ₹ 24,00,000 per yearJoin our Technology (DevOps) team as a Sr. Platform Engineer. In this critical role, you'll leverage your expertise in CI/CD, container orchestration (Kubernetes), and infrastructure-as-code to engineer the next generation of scalable, secure, and resilient platforms that power global markets.What You'll GetA supportive environment fostering career...
-
Staff Software Engineer
6 days ago
Bangalore - Bagmane Tridib, India CME Group Full time ₹ 12,00,000 - ₹ 36,00,000 per yearThe Ld Software Engineer independently engineers secure, scalable and reliable technology solutions to advance CMEG in the global marketplace and serve risk management needs of customers around the world.Principal Accountabilities:• Conducts full system testing.• Defines key metrics driving code optimization and leads discussion of code reviews; Manages...
-
Software Engineer II
1 week ago
Bangalore - Bagmane Tridib, India CME Group Full time ₹ 12,00,000 - ₹ 36,00,000 per yearThe Software Engineer II engineers secure, scalable and reliable technology solutions, with appropriate mentoring, to advance CMEG in the global marketplace and serve risk management needs of customers around the world.Principal Accountabilities:• Conducts coding at a medium task level including design• Conducts unit testing of own code. Reviews unit...
-
Software Engineer I – India
2 days ago
Bangalore - Bagmane Tridib, India Chicago Mercantile Exchange Full time ₹ 4,32,000 - ₹ 6,48,000 per yearThe Software Engineer I engineers secure, scalable and reliable technology solutions, with appropriate mentoring, to advance CMEG in the global marketplace and serve risk management needs of customers around the world.Principal Accountabilities:• Writes Java code at story level; potentially minimal design and aligns with overall milestones• Conducts unit...
-
Site Reliability Engineer I
2 days ago
Bangalore - Bagmane Tridib, India CME Group Full time ₹ 80,00,000 - ₹ 1,20,00,000 per yearThe SitReliability Engineer (SRE) works in an operational capacity, collaborating with product, business owners and development teams to establish and manage Service Level Objectives (SLOs), Service Level Indicators (SLI's), Service Level Agreements (SLAs), while evaluating error budgets and operational results to identify and prioritize activities to ensure...
-
Security Engineer III
1 week ago
bangalore, India CME Group Full timeThe Application Security Engineer leads efforts to enhance application security and the secure software development lifecycle. This individual is responsible for performing manual application security assessments (application pentests) and communicating security findings to the developers and QA teams. Additionally, the individual will provide application...