The Lead Security Engineer - DevSecOps at CME Group participates in all functions related to software security design, secure SDLC techniques, and applying strong, secure design patterns with minimal oversight at a task level. This position acts as a constructive, communicative team member and mentor who contributes to software security strategy and roadmap planning, serves as a security liaison to external groups, and develops secure reference designs and products across the Global Information Security (GIS) group and the larger enterprise.
The role requires deep software engineering expertise and prior experience in secure SDLC disciplines (such as strong cryptography, authentication/authorization, secure data handling, auditing, and input validation). Additionally, a strong understanding of modern software architectures—including microservices, Cloud Native designs, and software-defined deployments (CI/CD pipelines, Infrastructure-as-Code, immutable and idempotent declarative principles)—is necessary for success. While not required, a basic technical understanding of security frameworks (CIS, NIST 800, PCI, HIPAA) and exposure to security technologies (IDS/IPS, WAF) is highly desirable.