Cyber Defense Analyst III

Posted Yesterday
Be an Early Applicant
Wacker, IL, USA
In-Office
104K-173K Annually
Senior level
Financial Services
The Role
Monitor and investigate complex security events across network, host, identity, and cloud telemetry. Validate and enrich alerts for Incident Response, conduct threat hunting, develop SIEM detections, and automate repetitive SOC workflows using Python, PowerShell, SOAR playbooks, Git, and CI/CD. The role also supports AI-assisted triage, Detection-as-Code, documentation, and mentorship of junior analysts.
Summary Generated by Built In

The Cyber Defense Engineer III position is responsible for monitoring, detecting, and validating complex security threats. As our Security Operations Center transitions toward an engineering and automation-first model, this role acts as a critical bridge between traditional cyber defense monitoring and modern development practices. You will take a leading role in deep-dive telemetry analysis while dedicating significant time to identifying process bottlenecks, developing automation scripts, and integrating security telemetry into our SOAR platforms.

This position is ideal for candidates looking to evolve their career by applying an engineering mindset to everyday monitoring challenges, helping us eliminate manual toil, improve detection fidelity, and support the deployment of AI-augmented triage workflows.

Position Responsibilities

  • Perform deep-dive analysis and validation of complex security events across network, host, identity, and cloud (GCP) telemetry to accurately identify malicious activity and reduce false positives.

  • Ensure seamless handoffs to the Incident Response team by providing highly contextualized, enriched, and validated security alerts.

  • Proactively identify manual, repetitive monitoring tasks within the SOC and write Python scripts or build SOAR playbooks to automate them.

  • Support our transition to Detection-as-Code (DaC) by developing, testing, tuning, and deploying SIEM detection rules using version control (Git) and CI/CD pipelines.

  • Partner with our global engineering and automation teams to test, validate, and refine new AI-assisted workflows and agentic triage outputs to ensure high operational accuracy in our monitoring ecosystem.

  • Conduct proactive, hypothesis-driven threat hunts and operationalize threat intelligence into new, automated detection mechanisms.

  • Provide technical mentorship to junior monitoring analysts, fostering a culture of continuous learning, critical thinking, and automation within the SOC.

  • Maintain detailed documentation of monitoring processes, playbook logic, and detection schemas within the Knowledge Management System.

Position Requirements

Experience & Technical Skills

  • 4–6 years of dedicated experience in a Security Operations Center (SOC), Detection Engineering, or advanced Cyber Defense monitoring environment.

  • Deep knowledge of network protocols, operating system internals (Windows/Linux/macOS), and adversary tactics mapped to the MITRE ATT&CK framework.

  • Practical proficiency in Python or PowerShell, specifically for interacting with REST APIs, parsing JSON/XML, and automating daily security monitoring tasks.

  • Hands-on experience building, maintaining, or modifying playbooks within modern SOAR platforms (e.g., Cortex XSOAR, Splunk SOAR, Torq, or Tines).

  • Familiarity with cloud environments (preferably GCP or AWS) and investigating cloud-specific telemetry and identity abuse.

  • Experience or strong interest in modern engineering practices, including version control (Git), Detection-as-Code, and basic CI/CD workflows.

  • Willingness to learn and adapt to emerging AI capabilities, including testing and refining LLM prompts for security investigations.

Soft Skills & Competencies

  • Strong analytical and problem-solving mindset; naturally curious about how things work and how to make them more efficient.

  • Excellent communication skills, capable of translating complex telemetry into clear, actionable summaries for Incident Response and engineering peers.

  • Highly self-directed, able to balance active alert analysis with long-term automation and playbook development projects.

  • Collaborative team player who enjoys mentoring peers and bridging the gap between monitoring operations and development teams.

Formal Education & Certifications

  • BA/BS in Computer Science, Information Security, Engineering, or related field (non-tech degrees acceptable with appropriate levels of Information Security job experience and/or certifications).

  • Relevant industry certifications strongly preferred: SANS GCIA, GCFA, GCDA, or practical automation/cloud certs (e.g., SEC573, AWS/GCP Security).

#LI-DD1

CME Group is committed to offering a competitive total rewards package for our employees that recognizes their contributions to the business and reflects our long-term investment in their future. The pay range for this role is $103,500-$172,500. Actual salary offered will be dependent on a wide array of factors including but not limited to: relevant experience, skills, education and comparison to internal employees (where relevant). Our compensation program also includes an annual target bonus opportunity for all employees, as well as the opportunity to become an owner in the company through our broad-based equity program. Through our benefits program, we strive to offer flexibility, value and choice. From comprehensive health coverage, to a retirement package that includes both a 401(k) and an active pension plan, to highly competitive education reimbursement provisions, paid time off and a mental health benefit, CME Group offers a holistic benefits package for our team and their dependents.

CME Group: Where Futures are Made

CME Group is the world’s leading derivatives marketplace. But who we are goes deeper than that. Here, you can impact markets worldwide. Transform industries. And build a career by shaping tomorrow. We invest in your success and you own it – all while working alongside a team of leading experts who inspire you in ways big and small. Problem solvers, difference makers, trailblazers. Those are our people. And we’re looking for more.

At CME Group, we embrace our employees' unique experiences and skills to ensure that everyone’s perspectives are acknowledged and valued. As an equal-opportunity employer, we consider all potential employees without regard to any protected characteristic.

Important Notice: Recruitment fraud is on the rise, with scammers using misleading promises of job offers and interviews to solicit money and personal information from job seekers. CME Group adheres to established procedures designed to maintain trust, confidence and security throughout our recruitment process. Learn more here.

Skills Required

  • 4-6 years of dedicated experience in a Security Operations Center, Detection Engineering, or advanced Cyber Defense monitoring environment
  • Deep knowledge of network protocols, operating system internals across Windows, Linux, and macOS, and adversary tactics mapped to MITRE ATT&CK
  • Practical proficiency in Python or PowerShell for REST APIs, JSON/XML parsing, and security monitoring automation
  • Hands-on experience building, maintaining, or modifying playbooks in modern SOAR platforms
  • Familiarity with cloud environments, preferably GCP or AWS, and cloud telemetry and identity abuse investigations
  • Experience or strong interest in Git, Detection-as-Code, and basic CI/CD workflows
  • Willingness to learn and adapt to AI capabilities, including testing and refining LLM prompts for security investigations
  • Strong analytical and problem-solving skills
  • Excellent communication skills for translating complex telemetry into actionable summaries
  • Ability to work independently while balancing alert analysis and automation projects
  • Collaborative mindset and willingness to mentor peers
  • BA or BS in Computer Science, Information Security, Engineering, or a related field; nontechnical degrees accepted with appropriate information security experience or certifications
  • Relevant certifications such as SANS GCIA, GCFA, GCDA, SEC573, AWS Security, or GCP Security

CME Group Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about CME Group and has not been reviewed or approved by CME Group.

  • Retirement Support — U.S. offerings include both a 401(k) and a company-funded cash-balance pension, strengthening long-term financial security. This dual-track structure is highlighted as a notable differentiator among private employers.
  • Leave & Time Off Breadth — PTO and holiday schedules are described as generous, with ample time off and carryover commonly highlighted. This breadth of leave meaningfully enhances perceived total rewards.
  • Flexible Benefits — A flexible, hybrid work model applies to many roles, increasing day-to-day usability of the package. Flexibility is framed as a standard feature rather than an exception.

CME Group Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
3,291 Employees

What We Do

As the world's leading derivatives marketplace, CME Group (www.cmegroup.com) is where the world comes to manage risk. CME Group exchanges offer the widest range of global benchmark products across all major asset classes, including futures and options based on interest rates, equity indexes, foreign exchange, energy, agricultural commodities, metals, weather and real estate. CME Group brings buyers and sellers together through its CME Globex® electronic trading platform and its trading facilities in New York and Chicago. CME Group also operates CME Clearing, one of the world’s leading central counterparty clearing provider in the world, which offers clearing and settlement services for exchange-traded contracts, as well as for over-the-counter derivatives transactions through CME ClearPort®. These products and services ensure that businesses everywhere can substantially mitigate counterparty credit risk in both listed and over-the-counter derivatives markets.

Similar Jobs

GoodRx Logo GoodRx

Subscription Pricing & Strategy Director

Consumer Web • Coupons • Healthtech • Social Impact • Pharmaceutical
Remote or Hybrid
USA
800 Employees
169K-361K Annually

Vercel Logo Vercel

Product Manager

Artificial Intelligence • Cloud • Software
Easy Apply
Remote or Hybrid
United States
172K-258K Annually

Caterpillar Logo Caterpillar

Autonomy Validation Engineer

Artificial Intelligence • Cloud • Internet of Things • Software • Cybersecurity • Industrial • Industrial Equipment
Hybrid
Peoria, IL, USA
100000 Employees
98K-158K Annually

Caterpillar Logo Caterpillar

Senior Software Engineer

Artificial Intelligence • Cloud • Internet of Things • Software • Cybersecurity • Industrial • Industrial Equipment
Hybrid
Peoria, IL, USA
100000 Employees
113K-183K Annually

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account