Cyber Defense Response Analyst II

Posted Yesterday
Be an Early Applicant
Wacker, IL, USA
In-Office
94K-157K Annually
Mid level
Financial Services
The Role
Respond to and remediate cyber incidents from triage through resolution, conduct threat hunts, perform endpoint forensics and malware analysis, and operate across multi-cloud environments. Build and integrate security automation using Python, AI, and REST APIs; lead tabletop exercises; and maintain incident response documentation. The role collaborates globally, communicates technical findings to leadership, and works second shift initially, with anticipated transition to first shift after approximately six months.
Summary Generated by Built In

The Cyber Defense Response Analyst II is a mid-level technical role focused on responding to and remediating cyber incidents at CME Group, a major player in global financial markets. We are looking for someone who finds joy in the inner workings of technology, with the occasional tendency to get lost in deep research. In this role, you will use industry leading tools while responding to medium-severity incidents in collaboration with teammates around the globe. 

We provide autonomy, and great learning environment with access to top tier technology, opportunities to align project work with your individual interests, and access to our extensive training programs, including annual SANS training. Importantly, this is a second shift role (12p-8p US Central Time) that's anticipated to be convertible into a first shift role (8a-4p/9a-5p) within approximately 6 months of hire date.

Primary Responsibilities:

  • Digital Forensics and Incident Response: Drive the full incident response lifecycle from initial triage to remediation, confidently applying specialty skills like endpoint forensics and malware analysis. Be ready to operate in a multi-cloud environment.
     

  • Threat Hunting: Conduct regular threat hunts to identify misconfigurations, detection gaps, and other anomalies.
     

  • Automation & Engineering: Use AI, Python and REST APIs to build/integrate security tools for incident response needs, while working with automation engineers to develop heavy-duty solutions for advanced use-cases.
     

  • Tabletop Exercises (TTX): Lead regular tabletop exercises to improve team readiness.
     

  • Technical Documentation: Contribute continuously to our internal knowledge base of incident response runbooks and playbooks, keeping it exhaustive, accurate, and reflective of the latest workflows.
     

Ideal Candidate Attributes:

  • Innate Curiosity: An exceptional level of curiosity and a track record of self-teaching advanced technical concepts.

  • Highly Innovative: You have a consistent record of taking unorthodox approaches to challenges and a demonstrated ability to innovate within information technology domains.

  • A "Researcher" Mindset: A passion for collecting facts, debating details, and diving into "rabbit holes" to solve complex problems.
     

  • Adept at High-Pressure Communication: Ability to deal effectively at all levels of the organization and translate technical research into clear, actionable intelligence for leadership.
     

  • Highly Detail Oriented: Very strong attention to detail; you notice things others often don’t.

  • Impactfully Collaborative: You excel at technical collaboration and helping teams deliver high-impact.
     

Preferred Technical Qualifications:

  • DFIR Background: 2+ years of practical experience with Digital Forensics, Incident Handling, and/or Malware Analysis.

  • SIEM/Data Analysis: 2+ years of experience with Q Radar, Sentinel, Splunk, Chronicle, ArcSight, or similar log management technologies.

  • Experience using leading forensics tools: 2+ years of experience using tools such as KAPE, EnCase, Cellebrite, FTK, Magnet Axiom, and Autopsy, plus comfort with malware analysis tools like Ghidra, Ida Pro, PEStudio, and x64dbg.

  • Strong IT Fundamentals: Strong understanding of computer networking, operating systems, and their intersection with Cybersecurity.
     

  • Programming Skills: Development experience with Python, specifically for data manipulation (Pandas) and interacting with REST APIs.
     

  • Cloud Experience: Practical experience with AWS, GCP, or Azure.
     

Education & Certifications:

  • Education: BA/BS in Engineering, Computer Science, or Information Security (non-tech degrees acceptable with appropriate levels of Information Security job experience and/or certifications)
     

  • Certifications: GCIH, GCFE, GCFA, OSCP, Sec+, and similar cyber-oriented certifications are desired

CME Group is committed to offering a competitive total rewards package for our employees that recognizes their contributions to the business and reflects our long-term investment in their future. The pay range for this role is $93,900-$156,500. Actual salary offered will be dependent on a wide array of factors including but not limited to: relevant experience, skills, education and comparison to internal employees (where relevant). Our compensation program also includes an annual target bonus opportunity for all employees, as well as the opportunity to become an owner in the company through our broad-based equity program. Through our benefits program, we strive to offer flexibility, value and choice. From comprehensive health coverage, to a retirement package that includes both a 401(k) and an active pension plan, to highly competitive education reimbursement provisions, paid time off and a mental health benefit, CME Group offers a holistic benefits package for our team and their dependents.

CME Group: Where Futures are Made

CME Group is the world’s leading derivatives marketplace. But who we are goes deeper than that. Here, you can impact markets worldwide. Transform industries. And build a career by shaping tomorrow. We invest in your success and you own it – all while working alongside a team of leading experts who inspire you in ways big and small. Problem solvers, difference makers, trailblazers. Those are our people. And we’re looking for more.

At CME Group, we embrace our employees' unique experiences and skills to ensure that everyone’s perspectives are acknowledged and valued. As an equal-opportunity employer, we consider all potential employees without regard to any protected characteristic.

Important Notice: Recruitment fraud is on the rise, with scammers using misleading promises of job offers and interviews to solicit money and personal information from job seekers. CME Group adheres to established procedures designed to maintain trust, confidence and security throughout our recruitment process. Learn more here.

Skills Required

  • 2+ years of practical experience with digital forensics, incident handling, and/or malware analysis
  • 2+ years of experience with QRadar, Microsoft Sentinel, Splunk, Chronicle, ArcSight, or similar log management technologies
  • 2+ years of experience using forensic tools such as KAPE, EnCase, Cellebrite, FTK, Magnet Axiom, and Autopsy
  • Experience with malware analysis tools such as Ghidra, IDA Pro, PEStudio, and x64dbg
  • Strong understanding of computer networking, operating systems, and cybersecurity
  • Development experience with Python, including Pandas for data manipulation and REST API integration
  • Practical experience with AWS, GCP, or Azure
  • BA or BS in Engineering, Computer Science, or Information Security, or a nontechnical degree combined with appropriate information security experience and/or certifications
  • GCIH, GCFE, GCFA, OSCP, Security+, or similar cybersecurity certification

CME Group Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about CME Group and has not been reviewed or approved by CME Group.

  • Retirement Support U.S. offerings include both a 401(k) and a company-funded cash-balance pension, strengthening long-term financial security. This dual-track structure is highlighted as a notable differentiator among private employers.
  • Leave & Time Off Breadth PTO and holiday schedules are described as generous, with ample time off and carryover commonly highlighted. This breadth of leave meaningfully enhances perceived total rewards.
  • Flexible Benefits A flexible, hybrid work model applies to many roles, increasing day-to-day usability of the package. Flexibility is framed as a standard feature rather than an exception.

CME Group Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
3,291 Employees

What We Do

As the world's leading derivatives marketplace, CME Group (www.cmegroup.com) is where the world comes to manage risk. CME Group exchanges offer the widest range of global benchmark products across all major asset classes, including futures and options based on interest rates, equity indexes, foreign exchange, energy, agricultural commodities, metals, weather and real estate. CME Group brings buyers and sellers together through its CME Globex® electronic trading platform and its trading facilities in New York and Chicago. CME Group also operates CME Clearing, one of the world’s leading central counterparty clearing provider in the world, which offers clearing and settlement services for exchange-traded contracts, as well as for over-the-counter derivatives transactions through CME ClearPort®. These products and services ensure that businesses everywhere can substantially mitigate counterparty credit risk in both listed and over-the-counter derivatives markets.

Similar Jobs

TransUnion Logo TransUnion

Product Manager

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
4 Locations
13000 Employees

TransUnion Logo TransUnion

Senior Analyst – Alternative Data

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
4 Locations
13000 Employees

IMC Trading Logo IMC Trading

Performance Engineer Intern - Summer 2027

Fintech • Machine Learning • Software • Financial Services
Hybrid
Chicago, IL, USA
1954 Employees
200K-200K Annually

IMC Trading Logo IMC Trading

Graduate Performance Engineer

Fintech • Machine Learning • Software • Financial Services
Hybrid
Chicago, IL, USA
1954 Employees
200K-200K Annually

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account