Position Overview: We are seeking a forward-thinking Cyber Defense Monitoring (CDM) Level 3 to help lead our transition toward an AI-driven, agentic Security Operations Center (SOC). Unlike a traditional analyst role, this position requires an engineering mindset. In addition to daily SOC operations, you will actively look for opportunities to improve processes, assist in writing and maintaining automation scripts, and support the development of automated playbooks. This role is a stepping stone for bridging core cyber defense operations with modern automation and engineering practices.
You will act as the senior escalation point for complex threats while dedicating significant time to engineering autonomous workflows, integrating Large Language Models (LLMs) into investigation pipelines, and applying data science principles to threat detection.
Automation, AI & Agentic SOC Engineering
Build the Agentic SOC: Design, train, and deploy AI-driven autonomous agents capable of performing tier-1 and tier-2 triage, context gathering, and initial containment without human intervention.
SOAR & Playbook Engineering: Architect and write complex automation playbooks utilizing Python, REST APIs, and modern SOAR platforms to streamline incident response lifecycles.
Data Science & Machine Learning: Apply data analytics and ML models to massive security datasets to identify anomalous behaviors, reduce false positive rates, and improve the fidelity of SIEM alerts.
Detection as Code (DaC): Implement software engineering best practices (CI/CD pipelines, version control, automated testing) for the deployment and management of security rules and detection logic.
Continuous Optimization: Proactively identify bottlenecks in current SOC workflows and engineer programmatic solutions to reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
Cyber Defense Operations
Advanced Escalation & Response: Serve as the final technical escalation point (Level 3) for the more complex and severe security events, directing the triage of advanced persistent threats (APTs).
Threat Hunting & Intel: Conduct proactive, hypothesis-driven threat hunts across the enterprise and integrate actionable threat intelligence into automated defense mechanisms.
Security Stack Oversight: Oversee the health, tuning, and strategic direction of core monitoring tools (SIEM, EDR, NDR), ensuring they generate high-quality data for our automation engines.
Qualifications & Skills
Advanced proficiency in scripting and programming languages (e.g., Python, Go, or PowerShell) with a strong understanding of interacting with RESTful APIs and JSON/XML data structures.
Experience working with LLMs, prompt engineering, AI orchestration frameworks (like LangChain), and foundational data science tools (Pandas, Jupyter, SQL).
5+ years of progressive experience in a SOC or Incident Response environment, with deep knowledge of network protocols, operating system internals (Windows/Linux), and adversary tactics (MITRE ATT&CK).
Hands-on experience architecting workflows in leading SOAR platforms (e.g., Cortex XSOAR, Splunk SOAR, Torq, or Tines).
BA/BS in Engineering, Computer Science, or Information Security (non-tech degrees acceptable with appropriate levels of Information Security job experience and/or certifications)
A blend of security and engineering certifications such as GCIA, GCFA, AWS Certified Security / Machine Learning, or relevant SANS automation courses (e.g., SEC573, SEC540).
CME Group: Where Futures are Made
CME Group is the world’s leading derivatives marketplace. But who we are goes deeper than that. Here, you can impact markets worldwide. Transform industries. And build a career by shaping tomorrow. We invest in your success and you own it – all while working alongside a team of leading experts who inspire you in ways big and small. Problem solvers, difference makers, trailblazers. Those are our people. And we’re looking for more.
At CME Group, we embrace our employees' unique experiences and skills to ensure that everyone’s perspectives are acknowledged and valued. As an equal-opportunity employer, we consider all potential employees without regard to any protected characteristic.
Important Notice: Recruitment fraud is on the rise, with scammers using misleading promises of job offers and interviews to solicit money and personal information from job seekers. CME Group adheres to established procedures designed to maintain trust, confidence and security throughout our recruitment process. Learn more here.
Skills Required
- Advanced proficiency in Python, Go, or PowerShell scripting and programming
- Strong understanding of RESTful APIs and JSON/XML data structures
- Experience with LLMs, prompt engineering, and AI orchestration frameworks such as LangChain
- Experience with foundational data science tools including Pandas, Jupyter, and SQL
- At least 5 years of progressive experience in a SOC or incident response environment
- Deep knowledge of network protocols, Windows/Linux operating system internals, and MITRE ATT&CK
- Hands-on experience architecting workflows in SOAR platforms such as Cortex XSOAR, Splunk SOAR, Torq, or Tines
- BA or BS in Engineering, Computer Science, or Information Security, or equivalent security experience and certifications
- Security and engineering certifications such as GCIA, GCFA, AWS Certified Security/Machine Learning, or relevant SANS automation courses
CME Group Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about CME Group and has not been reviewed or approved by CME Group.
-
Retirement Support — U.S. offerings include both a 401(k) and a company-funded cash-balance pension, strengthening long-term financial security. This dual-track structure is highlighted as a notable differentiator among private employers.
-
Leave & Time Off Breadth — PTO and holiday schedules are described as generous, with ample time off and carryover commonly highlighted. This breadth of leave meaningfully enhances perceived total rewards.
-
Flexible Benefits — A flexible, hybrid work model applies to many roles, increasing day-to-day usability of the package. Flexibility is framed as a standard feature rather than an exception.
CME Group Insights
What We Do
As the world's leading derivatives marketplace, CME Group (www.cmegroup.com) is where the world comes to manage risk. CME Group exchanges offer the widest range of global benchmark products across all major asset classes, including futures and options based on interest rates, equity indexes, foreign exchange, energy, agricultural commodities, metals, weather and real estate. CME Group brings buyers and sellers together through its CME Globex® electronic trading platform and its trading facilities in New York and Chicago. CME Group also operates CME Clearing, one of the world’s leading central counterparty clearing provider in the world, which offers clearing and settlement services for exchange-traded contracts, as well as for over-the-counter derivatives transactions through CME ClearPort®. These products and services ensure that businesses everywhere can substantially mitigate counterparty credit risk in both listed and over-the-counter derivatives markets.







