CME Group
Cyber Defense Monitoring Engineer – Automation & AI
Bangalore - Bagmane Tridib
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →hirly's read of this role
- Seniority
- Mid level
- Country
- IN
- Work mode
- On-site / unstated
- First seen by hirly
- 28 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Position Overview : We are seeking a forward-thinking Cyber Defense Monitoring (CDM) Level 3 to help lead our transition toward an AI-driven, agentic Security Operations Center (SOC). Unlike a traditional analyst role, this position requires an engineering mindset. In addition to daily SOC operations, you will actively look for opportunities to improve processes, assist in writing and maintaining automation scripts, and support the development of automated playbooks. This role is a stepping stone for bridging core cyber defense operations with modern automation and engineering practices.
You will act as the senior escalation point for complex threats while dedicating significant time to engineering autonomous workflows, integrating Large Language Models (LLMs) into investigation pipelines, and applying data science principles to threat detection.
Automation, AI & Agentic SOC Engineering
Build the Agentic SOC: Design, train, and deploy AI-driven autonomous agents capable of performing tier-1 and tier-2 triage, context gathering, and initial containment without human intervention.
SOAR & Playbook Engineering: Architect and write complex automation playbooks utilizing Python, REST APIs, and modern SOAR platforms to streamline incident response lifecycles.
Data Science & Machine Learning: Apply data analytics and ML models to massive security datasets to identify anomalous behaviors, reduce false positive rates, and improve the fidelity of SIEM alerts.
Detection as Code (DaC): Implement software engineering best practices (CI/CD pipelines, version control, automated testing) for the deployment and management of security rules and detection logic.
Continuous Optimization: Proactively identify bottlenecks in current SOC workflows and engineer programmatic solutions to reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
Cyber Defense Operations
Advanced Escalation & Response: Serve as the final technical escalation point (Level 3) for the more complex and severe security events, directing the triage of advanced persistent threats (APTs).
Threat Hunting & Intel: Conduct proactive, hypothesis-driven threat hunts across the enterprise and integrate actionable threat intelligence into automated defense mechanisms.
Security Stack Oversight: Oversee the health, tuning, and strategic direction of core monitoring tools (SIEM, EDR, NDR), ensuring they generate high-quality data for our automation engines.
Qualifications & Skills
Advanced proficiency in scripting and programming languages (e.g., Python, Go, or PowerShell) with a strong understanding of interacting with RESTful APIs and JSON/XML data structures.
Experience working with LLMs, prompt engineering, AI orchestration frameworks (like LangChain), and foundational data science tools (Pandas, Jupyter, SQL).
5+ years of progressive experience in a SOC or Incident Response environment, with deep knowledge of network protocols, operating system internals (Windows/Linux), and adversary tactics (MITRE ATT&CK).
Hands-on experience architecting workflows in leading SOAR platforms (e.g., Cortex XSOAR, Splunk SOAR, Torq, or Tines).
BA/BS in Engineering, Computer Science, or Information Security (non-tech degrees acceptable with appropriate levels of Information Security job experience and/or certifications)
A blend of security and engineering certifications such as GCIA, GCFA, AWS Certified Security / Machine Learning, or relevant SANS automation courses (e.g., SEC573, SEC540).
CME Group: Where Futures are Made
CME Group is the world’s leading derivatives marketplace. But who we are goes deeper than that. Here, you can impact markets worldwide. Transform industries. And build a career by shaping tomorrow. We invest in your success and you own it – all while working alongside a team of leading experts who inspire you in ways big and small. Problem solvers, difference makers, trailblazers. Those are our people. And we’re looking for more.
At CME Group, we embrace our employees' unique experiences and skills to ensure that everyone’s perspectives are acknowledged and valued. As an equal-opportunity employer, we consider all potential employees without regard to any protected characteristic.
Important Notice: Recruitment fraud is on the rise, with scammers using misleading promises of job offers and interviews to solicit money and personal information from job seekers. CME Group adheres to established procedures designed to maintain trust, confidence and security throughout our recruitment process. Learn more here .
Similar jobs
- Monitoring EngineerMovadogroup · Bangalore, IndiaFirst seen today
- Production Monitoring EngineerFnz · Gurugram Job Posting Location - IndiaFirst seen 4d ago
- Production Monitoring EngineerInfilect · Bengaluru, IndiaFirst seen 7d ago
- Infrastructure Monitoring Engineer (On Contract)Pubmatic · Pune, INFirst seen 29d ago
- Command Center Monitoring Engineer - Managed Collaboration Services (MCS)Hp · Heredia, Heredia, Costa RicaFirst seen 2d ago
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job