> Markdown version of [/jobs/ext/472518-lead-security-software-engineer](https://www.wearedevelopers.com/jobs/ext/472518-lead-security-software-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Software Engineer - **Company:** CME Group - **Location:** United States - **Experience:** Expert - **Salary:** $119,900.0 - $199,800.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), .NET Framework, Application Programming Interfaces (APIs), Amazon Web Services, JIRA, Unit Testing, Microsoft Azure, Bash Shell, C Sharp (Programming Language), C++ (Programming Language), Cloud Computing, Cloud Engineering, Program Optimization, Code Review, Information Systems, Databases, Continuous Integration, D3.Js, Data Architecture, Data Validation, Data Security, Issue Tracking Systems, Information Security Management, Intrusion Detection Systems, Python (Programming Language), Apache Maven, Node.Js, Software Architecture, Systems Development Life Cycle, Aws Command Line Interface (CLI), Ansible, Secure Coding, Security Software, Software Deployment, Software Engineering, System Testing, Website Wireframe, Data Logging, Google Cloud, DevOps Tools - Open-source, Software Security, Git, Cloudformation, Information Technology, Deployment Automation, Atlassian Tools, Cloudwatch, Puppet, Software Coding, Terraform, Splunk, Docker, Jenkins, Programming Languages, Microservices - **Published:** June 5, 2026 - **Apply:** https://www.dice.com/job-detail/8847951b-d3a6-482b-829b-b4cf6e2d22f6 ## About the Role The role requires deep software engineering expertise and prior experience in secure SDLC disciplines (such as strong cryptography, authentication/authorization, secure data handling, auditing, and input validation). Additionally, a strong understanding of modern software architectures-including microservices, Cloud Native designs, and software-defined deployments (CI/CD pipelines, Infrastructure-as-Code, immutable and idempotent declarative principles)-is necessary for success. While not required, a basic technical understanding of security frameworks (CIS, NIST 800, PCI, HIPAA) and exposure to security technologies (IDS/IPS, WAF) is highly desirable., * A Bachelor's or Master's degree in Computer Science, Information Systems or other related field; or equivalent work experience. * 6+ years of application development and/or infrastructure engineering experience. * 2+ years of active hands-on experience with application deployments in the Cloud (AWS, Google Cloud Platform, Azure). * Experience in using DevSecOps tools and frameworks for managing infrastructure as code like (or similar to) CloudFormation, Terraform, Chef, Puppet, Ansible, etc. * Experience with DevSecOps tools such as Jenkins, Maven, Git, and Ansible. * E xperience working with containers and container systems such as Docker and Kubernetes. * Experience writing code and scripts to automate provisioning of AWS services and to configure services, using tools and languages including AWS CLI / API, Jenkins, Python, Bash, and Git. * Experience with Java, Python, JavaScript (Node.js) and possibly .NET (C#, C++). * Experience with logging/monitoring understanding using tools such as CloudWatch and Splunk, etc. * Experience with ticketing systems such as Jira. * Any familiarity with the Atlassian (Jira) SDK and the Atlassian development process is desirable. * Experience with UX/UI design, wireframing, and any of the major client-side visualization libraries (e.g., D3.js, etc.) is desirable. * Familiarity with current and emerging technologies and patterns in software development and architectures, especially within the Cloud Native spac e. * Ability to work across teams and geographic locations. * Excellent oral and written communication skills. * Relevant experience designing, implementing, and supporting larger-scale software products. * Certifications: While a certification is not absolutely required, one or more of the following would be desirable: CISSP, CSSLP, GSSP-*, CASE, CERT Secure Coding, PECB Lead Secure Application Developer. ## Description The Lead Security Software Engineer at CME Group participates in all functions related to software security design, secure SDLC techniques, and applying strong, secure design patterns with minimal oversight at a task level. This position acts as a constructive, communicative team member and mentor who contributes to software security strategy and roadmap planning, serves as a security liaison to external groups, and develops secure reference designs and products across the Global Information Security (GIS) group and the larger enterprise., * Actively drive and contribute to designs of secure software reference designs, delivery systems, and enterprise-wide solutions that demonstrate secure coding principles and practices. * Take responsibility for primary contributions to the implementation of various software products within the GIS team, inclusive of all aspects of the Secure SDLC process through to maturity. * Conduct unit, integration, and system testing of any code produced and projects contributed to, utilizing prior background and experience. * Demonstrate high skill in programming language proficiency, with mastery in at least one primary language area. * Write unit tests for test-driven implementations with minimal guidance. * Exhibit skilled knowledge of database and data architectures, and how to securely access and incorporate them throughout the execution lifecycle of an application. * Ident ify potential opportunities for code optimization. * Provide input for code reviews and help with environment build deployment (local mockups and CI/CD), release notes, and build notices. * Create any necessary development documentation as necessary, such as: use cases, user requirements, design specifications, technical specifications, process flows, data flow diagrams, sequence diagrams, communications diagrams, etc. * R eview code to proactively identify and mitigate potential issues and defects and help to identify sources of defects as well as troubleshoot various forms of code. * Collaborate regularly with various peers in group settings across multiple divisions within CME Group to help produce applied examples of reference architectures and help establish the next generation of secure SDLC at CME Group through implementation projects. ## Related Videos - [Web-based Information Visualization](https://www.wearedevelopers.com/videos/84-web-based-information-visualization) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)