Sr Security Engineer- Red team

1 month ago


Chicago, United States CME Group Full time
Description
Role is located in Chicago office. Hybrid 2 days on site.
We are not able to support 100% remote work.

We are looking for a Sr Cyber Security Engineer - Red Team to be an integral part of our Offensive Security organization and contribute towards improving CME Group's security posture.

This role will be responsible for participating in the execution of Red Team cyber exercises of internal and internet facing information systems and infrastructure to identify misconfigurations and cyber security vulnerabilities that could be exploited by a threat actor to gain unauthorized access to computer systems and data. In addition, the role will require participation in Purple Team exercises to help the Blue Team improve their detection capabilities.
This is a perfect opportunity for the right person to become a key part of a team of highly skilled cybersecurity professionals who execute a pivotal role in protecting and defending national critical infrastructure.

Principal Responsibilities
  • Lead red team exercises against a hybrid environment using threat intelligence and the MITRE ATT&CK Framework.
  • Participate in purple team exercises that are intelligence driven to test cyber detections
  • Build and maintain Red and Purple team infrastructure, automating functions where possible.
  • Continually research new offensive security tactics, techniques, and procedures and communicate knowledge of the same to other team members.
  • Conduct ad-hoc offensive security testing using industry standard tools and/or internally developed tools.
  • Lead report creation activities including compromise narratives and detailed technical findings with appropriate risk severity ratings, tactical and strategic recommendations to reduce risk levels, peer review of team's deliverables.
  • Assist cyber defense teams during incident investigations providing subject matter expertise on attacker tradecraft and mindset.
  • Interface with other information security departments, as well as other technology departments and business stakeholders to raise awareness of security issues and to provide knowledge sharing on remediation.
  • Active contributor to Red and Purple Team activities for internal presentations and conferences


Position Requirements
  • Approx 8 years' experience with industry standard Red Team testing tools (Cobalt Strike, Mythic C2, Rubeus, Bloodhound, Covenant, etc.); or the ability to demonstrate equivalent knowledge.
  • Expert understanding of how an Advanced Persistent Threat could compromise a financial institution without using phishing.
  • Expert understanding of Red Team concepts, tools, and automation strategies.
  • Expert understanding of MITRE ATT&CK framework tactics, techniques, and procedures.
  • Expert understanding of measuring and rating vulnerabilities based on principal characteristics of a vulnerability.
  • Expert understanding of Windows and Linux system hardening concepts and techniques.
  • Expert understanding of modifying payloads to bypass detections like EDR.
  • Expert understanding of how to compromise a company without using phishing.
  • Strong understanding with at least one scripting language (Python, Ruby, PowerShell, Bash, etc.).
  • Experience with at least one cloud environment (AWS, GCP, Azure).
  • Experience attacking cloud, on-prem and/or hybrid environments from initial access all the way through actions on objective.


Nice to have
  • Previous experience of Red Team project delivery to include creation and execution of statement of work, risk mitigation strategies, and working with stakeholders to remediate findings.
  • Experience of using multi operating system command and control tools.
  • Experience developing custom attack tradecraft or modifying existing tools.
  • Experience using automated configuration management such as Chef.
  • Experience discovering and exploiting vulnerabilities in AI systems.
  • Experience of conducting Offensive Security and/or Red Team exercises against macOS, iOS, or ChromeOS.
  • Recognized industry certifications such as, but not limited to, GPEN, GXPN, GREM, eCPTX, eCPPT, OSCP, OSWE, CISSP, CPSA, CRT, etc.
  • Knowledgeable in Industry Security standards (i.e.: TIBER-EU, CBEST, NIST Cyber Security Framework, ISO27002, etc.).
  • Knowledgeable in Agile project management.

    #LI-Hybrid
    #LI-DS
    #dice


CME Group: Where Futures Are Made

CME Group (www.cmegroup.com) is the world's leading derivatives marketplace. But who we are goes deeper than that. Here, you can impact markets worldwide. Transform industries. And build a career shaping tomorrow. We invest in your success and you own it, all while working alongside a team of leading experts who inspire you in ways big and small. Problem solvers, difference makers, trailblazers. Those are our people. And we're looking for more.

At CME Group, we embrace our employees' diverse experiences, cultures and skills, and work to ensure that everyone's perspectives are acknowledged and valued. As an equal opportunity employer, we recognize the importance of a diverse and inclusive workplace and consider all potential employees without regard to any protected characteristic.
The Candidate Privacy Policy can be found here.


  • Chicago, United States Request Technology, LLC Full time

    ***Remote if in: IL, TX, FL, GA, MA, MD, MN, NC, NJ, NY, DC, WI or in office Chicago, IL / Dallas, TX**A prestigious company is looking for an Associate Principal, Red Team Tester. This tester will plan, design, and execute security red teaming. These Red team activities include Intelligence Gathering, Network/Operating System/Application Penetration...


  • Chicago, United States Keeper Security Full time

    Keeper is hiring a talented Sr. System Support Engineer to join the Keeper family. This is a 100% remote position! Keeper's cybersecurity software is trusted by millions of people and thousands of organizations, globally. Keeper is published in 21 languages and is sold in over 120 countries. Join one of the fastest growing Cybersecurity companies and gain...

  • Sr. Linux Engineer

    1 week ago


    Chicago, United States Nava Software Solutions LLC Full time

    Job DescriptionJob DescriptionNAVA Software solutions is looking for a Sr. Linux EngineerDetails:Senior Linux Engineer Location: Chicago, IL or Kennesaw, GA or Chandler, AZ (Hybrid role) Duration: 12 monthsJob description:We are seeking to fill a senior level Linux Engineering position.Candidate will have 7+ years of experience working with Redhat products...

  • Sr. Linux Engineer

    6 days ago


    Chicago, United States Nava Software Solutions LLC Full time

    Job DescriptionJob DescriptionNAVA Software solutions is looking for a Sr. Linux EngineerDetails:Senior Linux Engineer Location: Chicago, IL or Kennesaw, GA or Chandler, AZ (Hybrid role) Duration: 12 monthsJob description:We are seeking to fill a senior level Linux Engineering position.Candidate will have 7+ years of experience working with Redhat products...


  • Chicago, United States Keeper Security, Inc. Full time

    Job DescriptionJob DescriptionKeeper is hiring a talented Sr. System Support Engineer to join the Keeper family. This is a 100% remote position!Keeper’s cybersecurity software is trusted by millions of people and thousands of organizations, globally. Keeper is published in 21 languages and is sold in over 120 countries. Join one of the fastest growing...


  • Chicago, United States Keeper Security, Inc. Full time

    Job DescriptionJob DescriptionKeeper is hiring a talented Sr. System Support Engineer to join the Keeper family. This is a 100% remote position!Keeper’s cybersecurity software is trusted by millions of people and thousands of organizations, globally. Keeper is published in 21 languages and is sold in over 120 countries. Join one of the fastest growing...

  • Sr. Security Engineer

    2 months ago


    Chicago, Illinois, United States Circana Full time

    Sr. Security EngineerLet's be unstoppable togetherCircana (formerly IRI and NPD) is the leading advisor on the complexity of consumer behavior. Through unparalleled technology, advanced analytics, cross-industry data, and deep expertise, we provide clarity that helps almost 7,000 of the world's leading brands and retailers take action and unlock business...


  • Chicago, United States OpenGov Full time

    OpenGov is home to an exceptional team - passionate about our mission to power more effective and accountable government. By bringing the OpenGov Cloud to our nation's state and local government, we're transforming communities so they can thrive! Imagine yourself being able to help small business owners open their doors faster, ensuring our tax dollars are...

  • Sr Linux Engineer

    3 days ago


    Chicago, United States Aloden, Inc. Full time

    Sr. Linux Engineer Location: Chicago, Illinois (Hybrid) Candidate Preference: Local to Chicago or within commuting distance. Work Authorization: W2 Candidates Only Responsibilities: Administer and maintain Red Hat Enterprise Linux (RHEL) systems (versions 7, 8, and 9) in an enterprise environment. Automate routine tasks using tools like Ansible or...

  • Sr Linux Engineer

    2 weeks ago


    Chicago, United States Accord Technologies Inc. Full time

    Job DescriptionJob DescriptionSr Linux EngineerChicago, Illinois (Hybrid Role, Nearby candidates)W2 Candidates only Required Skills (Technical): - 7+ years' experience working with Red Hat products in an enterprise environment - Senior systems administration (RHEL 7, 8 and 9) - Automation skills (ex. Ansible, BladeLogic) - Programming skills (ex. Shell...


  • Chicago, Illinois, United States MyCareersFuture Full time

    Job SummaryMyCareersFuture is seeking a highly skilled and experienced Senior Build Engineer to join our team. As a key member of our infrastructure team, you will be responsible for managing and operating our Red Hat Enterprise Linux and Windows VM infrastructure.Key ResponsibilitiesManage and operate Red Hat Enterprise Linux and Windows VM infrastructure,...


  • Chicago, Illinois, United States Red Lobster Full time

    Job Title: Host/HostessJob Summary:We are seeking a friendly and organized Host/Hostess to join our team at Red Lobster. As a Host/Hostess, you will be the first point of contact for our guests and will be responsible for creating a warm and welcoming atmosphere. Your goal will be to make every guest feel valued and ensure that their dining experience is...


  • Chicago, Illinois, United States Jump Trading Full time

    Jump Crypto is the crypto division of Jump Trading Group, a research driven quantitative trading firm that's one of the largest traders by volume across traditional asset classes.Jump Crypto is committed to building and standing up critical infrastructure needed to catalyze the growth of the crypto ecosystem.As a Blockchain Security Engineer at Jump Crypto,...


  • Chicago, United States TALENT Software Services Full time

    Are you an experienced Information Security Sr Analyst with a desire to excel? If so, then Talent Software Services may have the job for you! Our client is seeking an experienced Information Security Sr Analyst to work in Overland Park, Kansas.Position Summary: The Information Security Analyst will support the Cyber Defense and Operations (CDO) programs...


  • Chicago, United States Jump Trading Full time

    Jump Crypto is the crypto division of Jump Trading Group, a research driven quantitative trading firm that's one of the largest traders by volume across traditional asset classes.Jump Crypto is committed to building and standing up critical infrastructure needed to catalyze the growth of the crypto ecosystem.As a Blockchain Security Engineer at Jump...


  • Chicago, United States Enterprise Performance Group Full time

    Job DescriptionJob DescriptionSr. IT Datacenter Engineer -- Location : Chicago O’Hare area  The Sr. IT Datacenter Engineer responsibilities will include: Acting as a Team Leader to deliver IT managed servicesMaintain relationships with strategic suppliersContribute to innovation and promote development of enterprise technology road maps .Partner with...


  • Chicago, United States Atlantic Partners Corporation Full time

    An Asset Management firm is seeking a SR. Cyber Security Engineer . This role will focus on planning, designing and executing security-related projects, processes and procedures in a Microsoft-oriented environment. Areas of focus for this position will include managing the Microsoft Defender Security Suite, incident response, threat hunting, improvements to...


  • Chicago, United States Atlantic Partners Corporation Full time

    An Asset Management firm is seeking a SR. Cyber Security Engineer . This role will focus on planning, designing and executing security-related projects, processes and procedures in a Microsoft-oriented environment. Areas of focus for this position will include managing the Microsoft Defender Security Suite, incident response, threat hunting, improvements to...

  • Sr. Android Engineer

    4 weeks ago


    Chicago, United States Uber Technologies, Inc. Full time

    Sr. Android EngineerUber Freight - Chicago, ILAbout Uber Freight Uber Freight is a logistics platform and partner with a mission to reimagine the way goods move to help communities thrive. Backed by innovative technology and a dedicated team of domain experts, we provide logistics solutions that give shippers and carriers of all sizes greater reliability,...

  • Sr. Android Engineer

    4 weeks ago


    Chicago, Illinois, United States Uber Technologies, Inc. Full time

    Sr. Android EngineerUber Freight - Chicago, ILAbout Uber FreightUber Freight is a logistics platform and partner with a mission to reimagine the way goods move to help communities thrive. Backed by innovative technology and a dedicated team of domain experts, we provide logistics solutions that give shippers and carriers of all sizes greater reliability,...