CME Group

Cyber Defense Response Analyst II

CME Group$93K — $156K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 2+ years of experience in Digital Forensics, Incident Handling, and/or Malware Analysis
  • Proficiency with SIEM tools like Q Radar, Sentinel, Splunk, or similar
  • Experience using forensic tools such as KAPE, EnCase, or Cellebrite
  • Strong IT fundamentals with knowledge of networking and operating systems
  • Programming experience with Python for data manipulation and REST APIs

Responsibilities

  • Drive the full incident response lifecycle from triage to remediation, employing forensic and malware analysis skills.
  • Conduct regular threat hunts to identify vulnerabilities and detection gaps.
  • Utilize AI and Python to develop and integrate advanced security tools for incident response.
  • Lead tabletop exercises to enhance team readiness and incident response strategies.
  • Maintain and update the internal knowledge base of incident handling runbooks and playbooks.

Benefits

  • Comprehensive health coverage
  • Retirement package including a 401(k) and pension plan
  • Competitive education reimbursement
  • Paid time off and mental health benefits
  • Annual bonus opportunity and equity program
Full Job Description
The Cyber Defense Response Analyst II is a mid-level technical role focused on responding to and remediating cyber incidents at CME Group, a major player in global financial markets. We are looking for someone who finds joy in the inner workings of technology, with the occasional tendency to get lost in deep research. In this role, you will use industry leading tools while responding to medium-severity incidents in collaboration with teammates around the globe.

We provide autonomy, and great learning environment with access to top tier technology, opportunities to align project work with your individual interests, and access to our extensive training programs, including annual SANS training. Importantly, this is a second shift role (12p-8p US Central Time) that's anticipated to be convertible into a first shift role (8a-4p/9a-5p) within approximately 6 months of hire date.

Primary Responsibilities:
  • Digital Forensics and Incident Response: Drive the full incident response lifecycle from initial triage to remediation, confidently applying specialty skills like endpoint forensics and malware analysis. Be ready to operate in a multi-cloud environment.
  • Threat Hunting:Conduct regular threat hunts to identify misconfigurations, detection gaps, and other anomalies.
  • Automation & Engineering: Use AI, Python and REST APIs to build/integrate security tools for incident response needs, while working with automation engineers to develop heavy-duty solutions for advanced use-cases.
  • Tabletop Exercises (TTX): Lead regular tabletop exercises to improve team readiness.
  • Technical Documentation: Contribute continuously to our internal knowledge base of incident response runbooks and playbooks, keeping it exhaustive, accurate, and reflective of the latest workflows.

Ideal Candidate Attributes:
  • Innate Curiosity: An exceptional level of curiosity and a track record of self-teaching advanced technical concepts.


  • Highly Innovative: You have a consistent record of taking unorthodox approaches to challenges and a demonstrated ability to innovate within information technology domains.


  • A "Researcher" Mindset: A passion for collecting facts, debating details, and diving into "rabbit holes" to solve complex problems.
  • Adept at High-Pressure Communication: Ability to deal effectively at all levels of the organization and translate technical research into clear, actionable intelligence for leadership.
  • Highly Detail Oriented: Very strong attention to detail; you notice things others often don't.


  • Impactfully Collaborative: You excel at technical collaboration and helping teams deliver high-impact.

Preferred Technical Qualifications:
  • DFIR Background: 2+ years of practical experience with Digital Forensics, Incident Handling, and/or Malware Analysis.


  • SIEM/Data Analysis: 2+ years of experience with Q Radar, Sentinel, Splunk, Chronicle, ArcSight, or similar log management technologies.


  • Experience using leading forensicstools: 2+ years of experience using tools such as KAPE, EnCase, Cellebrite, FTK, Magnet Axiom, and Autopsy, plus comfort with malware analysis tools like Ghidra, Ida Pro, PEStudio, and x64dbg.


  • Strong IT Fundamentals: Strong understanding of computer networking, operating systems, and their intersection with Cybersecurity.
  • Programming Skills: Development experience with Python, specifically for data manipulation (Pandas) and interacting with REST APIs.
  • Cloud Experience: Practical experience with AWS, GCP, or Azure.

Education & Certifications:
  • Education: BA/BS in Engineering, Computer Science, or Information Security (non-tech degrees acceptable with appropriate levels of Information Security job experience and/or certifications)
  • Certifications: GCIH, GCFE, GCFA, OSCP, Sec+, and similar cyber-oriented certifications are desired


CME Group is committed to offering a competitive total rewards package for our employees that recognizes their contributions to the business and reflects our long-term investment in their future. The pay range for this role is $93,900-$156,500. Actual salary offered will be dependent on a wide array of factors including but not limited to: relevant experience, skills, education and comparison to internal employees (where relevant). Our compensation program also includes an annual target bonus opportunity for all employees, as well as the opportunity to become an owner in the company through our broad-based equity program. Through our benefits program, we strive to offer flexibility, value and choice. From comprehensive health coverage, to a retirement package that includes both a 401(k) and an active pension plan, to highly competitive education reimbursement provisions, paid time off and a mental health benefit, CME Group offers a holistic benefits package for our team and their dependents.

About CME Group

CME Group Inc. is a global markets company. It owns large derivatives, options and futures exchanges in Chicago and New York City using its CME Globex trading platforms. It also owns CME Clearing which provides settlement and clearing of exchange trades. The company offers trading in a wide range of products across various asset classes, including futures and options based on interest rates, equity indexes, foreign exchange, energy, agricultural commodities, and metals. CME Group was formed in 2007 through the merger of the Chicago Mercantile Exchange (CME) and the Chicago Board of Trade (CBOT). The company is headquartered in Chicago, Illinois and has offices in New York City, London, Belfast, Tel Aviv, Dubai, Singapore, and Tokyo.
Learn more about CME Group
Size
3,480 employees
Market Cap
$60.2 billion
Industry
Net Income
$2.1 billion
Founded
1848
5 Year Trend
+5.5%
Revenue
$4.8 billion
NASDAQ

Similar Jobs

More Jobs at CME Group

More Information Technology Jobs

Find similar Cyber Defense Response Analyst II jobs: