CME Group

Cyber Defense Analyst III

CME Group • $103K — $172K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4-6 years of experience in a SOC, Detection Engineering, or advanced Cyber Defense monitoring.
  • Deep knowledge of network protocols, OS internals (Windows/Linux/macOS), and MITRE ATT&CK framework.
  • Experience with Python or PowerShell for security automation and REST API interaction.
  • Hands-on experience with modern SOAR platforms like Cortex XSOAR or Splunk SOAR.
  • Familiarity with cloud environments (preferably GCP or AWS) and cloud-specific telemetry issues.
  • Knowledge of version control (Git), Detection-as-Code, and CI/CD workflows.
  • Willingness to learn AI advancements in security investigations.

Responsibilities

  • Perform deep-dive analysis of complex security events across various telemetry sources to identify threats.
  • Ensure enriched and validated security alerts for effective handoffs to Incident Response.
  • Identify and automate manual monitoring tasks using Python scripts or SOAR playbooks.
  • Develop, test, and deploy SIEM detection rules in a Detection-as-Code framework.
  • Collaborate with engineering teams to refine AI-assisted workflows for operational efficiency.
  • Conduct proactive threat hunts and integrate threat intelligence into automated detection.
  • Mentor junior analysts and document monitoring processes comprehensively.

Benefits

  • Comprehensive health coverage for employees and dependents.
  • 401(k) retirement plan coupled with an active pension program.
  • Competitive education reimbursement options for professional development.
  • Generous paid time off policy for work-life balance.
  • Mental health benefits to support overall employee well-being.
Full Job Description
The Cyber Defense Engineer III position is responsible for monitoring, detecting, and validating complex security threats. As our Security Operations Center transitions toward an engineering and automation-first model, this role acts as a critical bridge between traditional cyber defense monitoring and modern development practices. You will take a leading role in deep-dive telemetry analysis while dedicating significant time to identifying process bottlenecks, developing automation scripts, and integrating security telemetry into our SOAR platforms.

This position is ideal for candidates looking to evolve their career by applying an engineering mindset to everyday monitoring challenges, helping us eliminate manual toil, improve detection fidelity, and support the deployment of AI-augmented triage workflows.

Position Responsibilities
  • Perform deep-dive analysis and validation of complex security events across network, host, identity, and cloud (GCP) telemetry to accurately identify malicious activity and reduce false positives.
  • Ensure seamless handoffs to the Incident Response team by providing highly contextualized, enriched, and validated security alerts.
  • Proactively identify manual, repetitive monitoring tasks within the SOC and write Python scripts or build SOAR playbooks to automate them.
  • Support our transition to Detection-as-Code (DaC) by developing, testing, tuning, and deploying SIEM detection rules using version control (Git) and CI/CD pipelines.
  • Partner with our global engineering and automation teams to test, validate, and refine new AI-assisted workflows and agentic triage outputs to ensure high operational accuracy in our monitoring ecosystem.
  • Conduct proactive, hypothesis-driven threat hunts and operationalize threat intelligence into new, automated detection mechanisms.
  • Provide technical mentorship to junior monitoring analysts, fostering a culture of continuous learning, critical thinking, and automation within the SOC.
  • Maintain detailed documentation of monitoring processes, playbook logic, and detection schemas within the Knowledge Management System.


Position Requirements

Experience & Technical Skills
  • 4-6 years of dedicated experience in a Security Operations Center (SOC), Detection Engineering, or advanced Cyber Defense monitoring environment.
  • Deep knowledge of network protocols, operating system internals (Windows/Linux/macOS), and adversary tactics mapped to the MITRE ATT&CK framework.
  • Practical proficiency in Python or PowerShell, specifically for interacting with REST APIs, parsing JSON/XML, and automating daily security monitoring tasks.
  • Hands-on experience building, maintaining, or modifying playbooks within modern SOAR platforms (e.g., Cortex XSOAR, Splunk SOAR, Torq, or Tines).
  • Familiarity with cloud environments (preferably GCP or AWS) and investigating cloud-specific telemetry and identity abuse.
  • Experience or strong interest in modern engineering practices, including version control (Git), Detection-as-Code, and basic CI/CD workflows.
  • Willingness to learn and adapt to emerging AI capabilities, including testing and refining LLM prompts for security investigations.


Soft Skills & Competencies
  • Strong analytical and problem-solving mindset; naturally curious about how things work and how to make them more efficient.
  • Excellent communication skills, capable of translating complex telemetry into clear, actionable summaries for Incident Response and engineering peers.
  • Highly self-directed, able to balance active alert analysis with long-term automation and playbook development projects.
  • Collaborative team player who enjoys mentoring peers and bridging the gap between monitoring operations and development teams.


Formal Education & Certifications
  • BA/BS in Computer Science, Information Security, Engineering, or related field (non-tech degrees acceptable with appropriate levels of Information Security job experience and/or certifications).
  • Relevant industry certifications strongly preferred: SANS GCIA, GCFA, GCDA, or practical automation/cloud certs (e.g., SEC573, AWS/GCP Security).


#LI-DD1

CME Group is committed to offering a competitive total rewards package for our employees that recognizes their contributions to the business and reflects our long-term investment in their future. The pay range for this role is $103,500-$172,500. Actual salary offered will be dependent on a wide array of factors including but not limited to: relevant experience, skills, education and comparison to internal employees (where relevant). Our compensation program also includes an annual target bonus opportunity for all employees, as well as the opportunity to become an owner in the company through our broad-based equity program. Through our benefits program, we strive to offer flexibility, value and choice. From comprehensive health coverage, to a retirement package that includes both a 401(k) and an active pension plan, to highly competitive education reimbursement provisions, paid time off and a mental health benefit, CME Group offers a holistic benefits package for our team and their dependents.

About CME Group

CME Group Inc. is a global markets company. It owns large derivatives, options and futures exchanges in Chicago and New York City using its CME Globex trading platforms. It also owns CME Clearing which provides settlement and clearing of exchange trades. The company offers trading in a wide range of products across various asset classes, including futures and options based on interest rates, equity indexes, foreign exchange, energy, agricultural commodities, and metals. CME Group was formed in 2007 through the merger of the Chicago Mercantile Exchange (CME) and the Chicago Board of Trade (CBOT). The company is headquartered in Chicago, Illinois and has offices in New York City, London, Belfast, Tel Aviv, Dubai, Singapore, and Tokyo.
Learn more about CME Group
Size
3,480 employees
Market Cap
$60.2 billion
Industry
Net Income
$2.1 billion
Founded
1848
5 Year Trend
+5.5%
Revenue
$4.8 billion
NASDAQ

Similar Jobs

More Jobs at CME Group

More Information Technology Jobs

Find similar Cyber Defense Analyst III jobs: