Cyber Defense Response Analyst II

CME Chicago Mercantile Exchange Inc.

Chicago (IL)

On-site

USD 94,000 - 157,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health coverage
401(k) + pension
Education reimbursement
Paid time off
Mental health benefits
Holistic benefits package

Job summary

CME Group in Chicago, IL is seeking a Cyber Defense Response Analyst II to join our security team. You will respond to and remediate medium-severity cyber incidents, perform DFIR, and hunt threats in a multi-cloud environment, using leading tools and automation.

Ideal candidates will have 2+ years of DFIR, SIEM, and malware analysis experience, strong Python skills, and AWS/GCP/Azure familiarity. This is a second shift role with potential to move to first shift within six months.

Qualifications

  • 2+ years of practical DFIR, incident handling, and/or malware analysis.

Responsibilities

  • Digital Forensics and Incident Response: drive full incident lifecycle from triage to remediation in a multi-cloud environment.
  • Threat Hunting: conduct regular threat hunts to identify misconfigurations and detection gaps.
  • Automation & Engineering: use Python and REST APIs to build security tooling and work with automation engineers on advanced use-cases.
  • Tabletop Exercises (TTX): lead regular tabletop exercises to improve team readiness.
  • Technical Documentation: maintain thorough incident response runbooks and playbooks.

Skills

DFIR
Threat Hunting
Python
REST APIs
Cloud Experience
IT Fundamentals

Education

BA/BS in Engineering or CS
Security Certifications (GCIH GCFE GCFA OSCP Sec+)

Tools

KAPE
EnCase
Cellebrite
FTK
Magnet Axiom
Autopsy
Ghidra
IDA Pro
PEStudio
x64dbg

Job description

The Cyber Defense Response Analyst II is a mid-level technical role focused on responding to and remediating cyber incidents at CME Group, a major player in global financial markets. We are looking for someone who finds joy in the inner workings of technology, with the occasional tendency to get lost in deep research. In this role, you will use industry leading tools while responding to medium-severity incidents in collaboration with teammates around the globe. We provide autonomy, and great learning environment with access to top tier technology, opportunities to align project work with your individual interests, and access to our extensive training programs, including annual SANS training. Importantly, this is a second shift role (12p-8p US Central Time) that's anticipated to be convertible into a first shift role (8a-4p/9a-5p) within approximately 6 months of hire date.

Primary Responsibilities:
  • Digital Forensics and Incident Response: Drive the full incident response lifecycle from initial triage to remediation, confidently applying specialty skills like endpoint forensics and malware analysis. Be ready to operate in a multi-cloud environment.
  • Threat Hunting: Conduct regular threat hunts to identify misconfigurations, detection gaps, and other anomalies.
  • Automation & Engineering: Use AI, Python and REST APIs to build/integrate security tools for incident response needs, while working with automation engineers to develop heavy-duty solutions for advanced use-cases.
  • Tabletop Exercises (TTX): Lead regular tabletop exercises to improve team readiness.
  • Technical Documentation: Contribute continuously to our internal knowledge base of incident response runbooks and playbooks, keeping it exhaustive, accurate, and reflective of the latest workflows.
Ideal Candidate Attributes:
  • Innate Curiosity: An exceptional level of curiosity and a track record of self-teaching advanced technical concepts.
  • Highly Innovative: You have a consistent record of taking unorthodox approaches to challenges and a demonstrated ability to innovate within information technology domains.
  • A 'Researcher' Mindset: A passion for collecting facts, debating details, and diving into 'rabbit holes' to solve complex problems.
  • Adept at High-Pressure Communication: Ability to deal effectively at all levels of the organization and translate technical research into clear, actionable intelligence for leadership.
  • Highly Detail Oriented: Very strong attention to detail; you notice things others often don’t.
  • Impactfully Collaborative: You excel at technical collaboration and helping teams deliver high-impact.
Preferred Technical Qualifications:
  • DFIR Background: 2+ years of practical experience with Digital Forensics, Incident Handling, and/or Malware Analysis.
  • SIEM/Data Analysis: 2+ years of experience with Q Radar, Sentinel, Splunk, Chronicle, ArcSight, or similar log management technologies.
  • Experience using leading forensics tools: 2+ years of experience using tools such as KAPE, EnCase, Cellebrite, FTK, Magnet Axiom, and Autopsy, plus comfort with malware analysis tools like Ghidra, Ida Pro, PEStudio, and x64dbg.
  • Strong IT Fundamentals: Strong understanding of computer networking, operating systems, and their intersection with Cybersecurity.
  • Programming Skills: Development experience with Python, specifically for data manipulation (Pandas) and interacting with REST APIs.
  • Cloud Experience: Practical experience with AWS, GCP, or Azure.
Education & Certifications:
  • Education: BA/BS in Engineering, Computer Science, or Information Security (non-tech degrees acceptable with appropriate levels of Information Security job experience and/or certifications)
  • Certifications: GCIH, GCFE, GCFA, OSCP, Sec+, and similar cyber-oriented certifications are desired
Compensation and Benefits:

CME Group is committed to offering a competitive total rewards package for our employees that recognizes their contributions to the business and reflects our long-term investment in their future. The pay range for this role is $93,900-$156,500. Actual salary offered will be dependent on a wide array of factors including but not limited to: relevant experience, skills, education and comparison to internal employees (where relevant). Our compensation program also includes an annual target bonus opportunity for all employees, as well as the opportunity to become an owner in the company through our broad-based equity program.

  • comprehensive health coverage
  • a retirement package that includes both a 401(k) and an active pension plan
  • highly competitive education reimbursement provisions
  • paid time off
  • a mental health benefit
  • CME Group offers a holistic benefits package for our team and their dependents
Company Culture:

CME Group: Where Futures are Made

CME Group is the world's leading derivatives marketplace. But who we are goes deeper than that. Here, you can impact markets worldwide. Transform industries. And build a career by shaping tomorrow.

We invest in your success and you own it – all while working alongside a team of leading experts who inspire you in ways big and small. Problem solvers, difference makers, trailblazers. Those are our people. And we're looking for more.

At CME Group, we embrace our employees' unique experiences and skills to ensure that everyone's perspectives are acknowledged and valued. As an equal-opportunity employer, we consider all potential employees without regard to any protected characteristic.

Best Place to Work

As the world's leading derivatives marketplace, CME Group is where the world comes to manage risk. We enable clients to trade futures, options, cash and OTC markets, optimize portfolios, and analyze data – empowering market participants worldwide to efficiently manage risk and capture opportunities.

E-Verify Notice

E-Verify Notice E-Verify Notice Español U.S. Right to Work Notice U.S. Right to Work Notice Español

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff/Lead Security Engineer - PAM
Staff/Lead Security Engineer - PAM

Socket.dev • Chicago (IL)

On-site
USD 132,000 - 220,000
Staff Site Reliability Engineer
Staff Site Reliability Engineer

CME Group Inc. • Chicago (IL), Northern (KY)

Hybrid
USD 132,000 - 220,000
Comprehensive benefits
Site Reliability Engineer III (Multiple Openings)
Site Reliability Engineer III (Multiple Openings)

CME Chicago Mercantile Exchange Inc. • Chicago (IL)

Hybrid
USD 104,000 - 173,000
Site Reliability Engineer III (Multiple Openings)
Site Reliability Engineer III (Multiple Openings)

CME Group Inc. • Chicago (IL), Northern (KY)

Hybrid
USD 108,000 - 173,000
Dir Corporate Communications
Dir Corporate Communications

CME Chicago Mercantile Exchange Inc. • Chicago (IL)

On-site
USD 125,000 - 210,000
Health coverage
401(k) plan
Education reimbursement
+2
Securities Clearing - Credit Risk Consultant
Securities Clearing - Credit Risk Consultant

CME Group Inc. • Chicago (IL), Northern (KY)

Hybrid
USD 58,000 - 62,000
Lead Security Software Engineer
Lead Security Software Engineer

CME Group Inc. • Chicago (IL)

On-site
USD 119,000 - 200,000
Comprehensive health coverage
401(k) and pension plan
Education reimbursement
Sales Associate - CD&S
Sales Associate - CD&S

CME Chicago Mercantile Exchange Inc. • New York (NY)

Hybrid
USD 77,000 - 128,000
Health coverage
401(k) and pension plan
Education reimbursement
+2
MD Clearing & Post Trade Product Management
MD Clearing & Post Trade Product Management

CME Chicago Mercantile Exchange Inc. • Chicago (IL)

On-site
USD 261,000 - 437,000
Staff Site Reliability Engineer
Staff Site Reliability Engineer

CME Group • Chicago (IL)

Hybrid
USD 132,000 - 220,000
Career progression
Exposure to CME products and teams
Competitive compensation