Cyber Defense Analyst III

CME Group

Chicago (IL)

On-site

USD 104,000 - 173,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

CME Group is seeking a senior SOC professional to perform deep-dive analysis of complex security events across network, host, identity, and cloud telemetry. You will deliver contextualized alerts to Incident Response and automate tasks with Python scripts and SOAR playbooks.

You will develop, tune, and deploy SIEM detection rules with Git/CI/CD, collaborate with global engineering teams on AI-assisted workflows, and lead proactive threat hunting initiatives.

Qualifications

  • 4–6 years in SOC, Detection Engineering, or advanced cyber defense monitoring.
  • Strong knowledge of networks, OS internals, and MITRE ATT&CK mapping.
  • Experience with REST APIs, JSON/XML, and automation scripts.

Responsibilities

  • Perform deep-dive analysis and validation of complex security events across network, host, identity, and cloud telemetry.
  • Provide highly contextualized, enriched, and validated security alerts for Incident Response.
  • Develop Python scripts or SOAR playbooks to automate repetitive monitoring tasks.
  • Develop, test, tune, and deploy SIEM detection rules using Git and CI/CD pipelines.
  • Collaborate with engineering and automation teams to test AI-assisted workflows and triage outputs.
  • Conduct proactive threat hunts and operationalize threat intelligence into detections.
  • Mentor junior analysts and promote automation and learning within the SOC.
  • Maintain documentation of monitoring processes, playbooks, and detection schemas.

Skills

Security analysis
Python
PowerShell
SOAR platforms
Git
CI/CD
REST APIs
Threat hunting
MITRE ATT&CK
Cloud security (GCP/AWS)

Education

BA/BS in Computer Science, Information Security, Engineering, or related field

Tools

Cortex XSOAR
Splunk SOAR
Torq
Tines
GCP
AWS

Job description

Position Responsibilities
  • Perform deep-dive analysis and validation of complex security events across network, host, identity, and cloud (GCP) telemetry to accurately identify malicious activity and reduce false positives.
  • Ensure seamless handoffs to the Incident Response team by providing highly contextualized, enriched, and validated security alerts.
  • Proactively identify manual, repetitive monitoring tasks within the SOC and write Python scripts or build SOAR playbooks to automate them.
  • Support our transition to Detection-as-Code (DaC) by developing, testing, tuning, and deploying SIEM detection rules using version control (Git) and CI/CD pipelines.
  • Partner with our global engineering and automation teams to test, validate, and refine new AI-assisted workflows and agentic triage outputs to ensure high operational accuracy in our monitoring ecosystem.
  • Conduct proactive, hypothesis-driven threat hunts and operationalize threat intelligence into new, automated detection mechanisms.
  • Provide technical mentorship to junior monitoring analysts, fostering a culture of continuous learning, critical thinking, and automation within the SOC.
  • Maintain detailed documentation of monitoring processes, playbook logic, and detection schemas within the Knowledge Management System.
Position Requirements

Experience & Technical Skills 4–6 years of dedicated experience in a Security Operations Center (SOC), Detection Engineering, or advanced Cyber Defense monitoring environment.

  • Deep knowledge of network protocols, operating system internals (Windows/Linux/macOS), and adversary tactics mapped to the MITRE ATT&CK framework.
  • Practical proficiency in Python or PowerShell, specifically for interacting with REST APIs, parsing JSON/XML, and automating daily security monitoring tasks.
  • Hands-on experience building, maintaining, or modifying playbooks within modern SOAR platforms (e.g., Cortex XSOAR, Splunk SOAR, Torq, or Tines).
  • Familiarity with cloud environments (preferably GCP or AWS) and investigating cloud-specific telemetry and identity abuse.
  • Experience or strong interest in modern engineering practices, including version control (Git), Detection-as-Code, and basic CI/CD workflows.
  • Willingness to learn and adapt to emerging AI capabilities, including testing and refining LLM prompts for security investigations.
Soft Skills & Competencies
  • Strong analytical and problem-solving mindset; naturally curious about how things work and how to make them more efficient.
  • Excellent communication skills, capable of translating complex telemetry into clear, actionable summaries for Incident Response and engineering peers.
  • Highly self-directed, able to balance active alert analysis with long-term automation and playbook development projects.
  • Collaborative team player who enjoys mentoring peers and bridging the gap between monitoring operations and development teams.
Formal Education & Certifications
  • BA/BS in Computer Science, Information Security, Engineering, or related field (non-tech degrees acceptable with appropriate levels of Information Security job experience and/or certifications).
  • Relevant industry certifications strongly preferred: SANS GCIA, GCFA, GCDA, or practical automation/cloud certs (e.g., SEC573, AWS/GCP Security).

CME Group is committed to offering a competitive total rewards package for our employees that recognizes their contributions to the business and reflects our long-term investment in their future. The pay range for this role is $103,500-$172,500. Actual salary offered will be dependent on a wide array of factors including but not limited to: relevant experience, skills, education and comparison to internal employees (where relevant). Our compensation program also includes an annual target bonus opportunity for all employees, as well as the opportunity to become an owner in the company through our broad-based equity program. Through our benefits program, we strive to offer flexibility, value and choice. From comprehensive health coverage, to a retirement package that includes both a 401(k) and an active pension plan, to highly competitive education reimbursement provisions, paid time off and a mental health benefit, CME Group offers a holistic benefits package for our team and their dependents.

CME Group: Where Futures are Made CME Group is the world’s leading derivatives marketplace. But who we are goes deeper than that. Here, you can impact markets worldwide. Transform industries. And build a career by shaping tomorrow. We invest in your success and you own it – all while working alongside a team of leading experts who inspire you in ways big and small. Problem solvers, difference makers, trailblazers. Those are our people. And we’re looking for more. At CME Group, we embrace our employees' unique experiences and skills to ensure that everyone’s perspectives are acknowledged and valued. As an equal-opportunity employer, we consider all potential employees without regard to any protected characteristic.

Additionally, CME Group does not communicate with job applicants over Telegram. Learn more here. For U.S. employment, CME Group is legally required to validate a new hire’s employment eligibility by having them complete an Employment Eligibility Verification (Form I-9) companied with legally acceptable proof of identity and work authorization (as listed on the Form I-9). CME Group uses E-Verify, which is an online system operated by the U.S. Department of Homeland Security in partnership with the Social Security Administration to verify employment eligibility and validate social security numbers. Through participation in the E-Verify program, information entered on Form I-9 will be provided and compared to information available at both of these agencies. See posters below for more details.

E-Verify Notice E-Verify Notice Español U.S. Right to Work Notice U.S. Right to Work Notice Español

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Defense Analyst III
Cyber Defense Analyst III

CME Chicago Mercantile Exchange Inc. • Chicago (IL)

On-site
USD 104,000 - 173,000
Health coverage
401(k)
Equity program
+3
Cyber Defense Response Analyst II
Cyber Defense Response Analyst II

CME Chicago Mercantile Exchange Inc. • Chicago (IL)

On-site
USD 94,000 - 157,000
Health coverage
401(k) + pension
Education reimbursement
+3
Site Reliability Engineer III (Multiple Openings)
Site Reliability Engineer III (Multiple Openings)

CME Group Inc. • Chicago (IL), Northern (KY)

Hybrid
USD 108,000 - 173,000
Site Reliability Engineer III (Multiple Openings)
Site Reliability Engineer III (Multiple Openings)

CME Chicago Mercantile Exchange Inc. • Chicago (IL)

Hybrid
USD 104,000 - 173,000
Cyber Defense Response Analyst II
Cyber Defense Response Analyst II

Socket.dev • Chicago (IL)

On-site
USD 94,000 - 157,000
Cyber Defense Response Analyst II
Cyber Defense Response Analyst II

CME Group • Chicago (IL)

On-site
USD 94,000 - 157,000
Sr Analyst: Memberships & Commercial Operations
Sr Analyst: Memberships & Commercial Operations

CME Chicago Mercantile Exchange Inc. • Chicago (IL)

On-site
USD 77,000 - 129,000
Health coverage
401(k) plan
Pension plan
+3
Mgr HR Operations
Mgr HR Operations

CME Chicago Mercantile Exchange Inc. • Chicago (IL)

On-site
USD 104,000 - 173,000
Principal Enterprise Architect
Principal Enterprise Architect

CME Chicago Mercantile Exchange Inc. • Chicago (IL)

On-site
USD 186,000 - 310,000
Comprehensive health coverage
401(k) and pension plan
Education reimbursement
+2
Manager, Market Risk
Manager, Market Risk

CME Group • Chicago (IL)

On-site
USD 139,000 - 231,000