Senior Cyber Security Engineer; Operations & Engineering
Chicago, Cook County, Illinois, 60290, USA
Listed on 2026-07-09
-
IT/Tech
Cybersecurity, Information Security, Security Management & Operations
About The Role
CMT is seeking a Senior Cyber Security Engineer to join a small, capable global technology and security team. Reporting to the Head of Technology and CISO, you will take a leading, hands‑on role in running and improving the firm’s security programme, spanning security operations, engineering, incident response, vulnerability management, and identity, cloud, and endpoint security.
You will own core security platforms and controls day to day, working alongside infrastructure and support teams and external SOC providers, with support and direction from the Head of Technology and CISO. One day you might be investigating an incident, the next deploying a new control, coordinating a global remediation effort, or presenting recommendations to senior stakeholders.
This role is expected to independently drive security outcomes, coordinate remediation efforts across technology teams, and take ownership of issues through to resolution. Success in this role requires a strong sense of ownership, sound judgement, and the ability to balance security risk against business objectives. We are looking for someone who is curious, pragmatic, highly self‑motivated, and comfortable operating with a high degree of autonomy in a fast‑moving trading environment.
This is an on‑site role based in our Chicago office. It is not a hybrid or remote position.
On‑site — Chicago
Key Responsibilities Security Operations & Incident Response- Lead technical investigations of security incidents, working with external SOC providers to validate, contain, and remediate threats.
- Act as the escalation point for cyber security incidents.
- Coordinate response activities across technology teams and third‑party providers.
- Conduct post‑incident reviews and drive improvements to controls, processes, and detection capabilities.
- Develop and maintain incident response procedures and playbooks.
- Design, implement, and continuously improve security controls across endpoints, identity, cloud, infrastructure, and SaaS platforms.
- Develop automation and integrations that improve security visibility, operational efficiency, and control effectiveness.
- Establish and maintain security hardening standards and technical baselines.
- Evaluate emerging technologies and recommend practical security improvements.
- Own the vulnerability management lifecycle from identification through remediation.
- Assess risk associated with vulnerabilities, security findings, and control gaps.
- Coordinate remediation efforts across infrastructure, support, and engineering teams.
- Track remediation progress and provide meaningful reporting to management.
- Validate remediation effectiveness and manage exceptions where appropriate.
- Administer, optimise, and continuously improve enterprise security platforms and controls across endpoint, identity, vulnerability management, cloud, SaaS, monitoring, and security awareness domains.
- Lead platform upgrades, policy reviews, configuration improvements, and operational enhancements.
- Measure and report on the effectiveness of security controls and security tooling.
- Enhance identity and access controls including MFA, conditional access, privileged access management, and access governance.
- Support zero trust, segmentation, and least‑privilege initiatives.
- Review and improve authentication and authorisation controls across enterprise platforms.
- Lead security projects from planning through delivery.
- Partner with infrastructure, cloud, development, and support teams to embed security into technology initiatives.
- Contribute to security strategy, roadmap planning, and continuous improvement activities.
- Support audits, assessments, and vendor due diligence activities.
- Represent the security function in discussions with technology teams, vendors, service providers, and business stakeholders.
- Communicate security risks and recommendations clearly to both technical and non‑technical audiences.
- Build strong relationships across the organisation to drive security outcomes and promote a security‑conscious…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).