Description:
The CTI Level III Tactical Engineer is responsible for building automations to assist with the day-to-day CME Group tactical threat intelligence activities and operations including analysis, collection, and dissemination of threat intelligence products. This role will primarily focus on building automations, and leveraging AI in order to support the larger Cyber Defense team and streamline Cyber Threat Intelligence processes.
Key responsibilities include:
Leverage a mix of AI and automations to streamline Cyber Threat Intelligence processes
Coordinate with security operations and incident response staff to tune and improve detection capabilities or to aid in investigations or respond to incidents
Consume and analyze threat intelligence reports in order to assist in the creation of signatures, queries, or other analytics that will be deployed for detection and prevention purposes
Analyze new vulnerabilities for potential impact and attack vectors
Basic Qualifications:
3+ years of experience in the field of information security, computer science, computer forensics, or information assurance
Familiarity with AI and mechanisms of integrating AI into workflows.
Familiar with the MITRE ATT&CK framework
Experience with collecting, analyzing, and interpreting threat intelligence data from multiple sources
Experience with cyber incident response and digital forensics, security engineering, security operations, computer network operations, information operations, information warfare, or topical cyber
Intermediate knowledge of Cyber threat intelligence processes and tradecraft to include the Cyber Kill Chain and Diamond Model of Intrusion Analysis
Experience with multiple scripting languages, including Python and PowerShell.
Familiar with Linux operating system, including using the Linux terminal
Experience with key security operations technologies such as SIEM and log aggregation
Experience with host and network log sources to apply to investigation, IR methodology in investigations, and the groups behind targeted attacks and tactics, techniques, and procedures (TTPs)
Knowledge of attacker tactics, techniques, and procedures and common attack vectors and vulnerabilities
BA or BS degree in Computer Science, Cyber Security, or related field
Additional Qualifications:
Experience with performing advanced static and dynamic malware analysis and with setting up and leveraging automated malware analysis platforms
Possession of excellent oral and written communication skills
Experience working in an Intelligence Community or similar intelligence experience.
Experience working in cloud environments
Formal Education & Certifications
BA/BS in Computer Science, Cyber Security, or related field or related work experience
GIAC Python Coder (GPYC), GIAC Security Essentials (GSEC), GIAC Certified Enterprise Defender (GCED), other relevant GIAC Certification, or other technical industry certifications
Threat Intelligence Courses
CME Group: Where Futures are Made
CME Group is the world’s leading derivatives marketplace. But who we are goes deeper than that. Here, you can impact markets worldwide. Transform industries. And build a career by shaping tomorrow. We invest in your success and you own it – all while working alongside a team of leading experts who inspire you in ways big and small. Problem solvers, difference makers, trailblazers. Those are our people. And we’re looking for more.
At CME Group, we embrace our employees' unique experiences and skills to ensure that everyone’s perspectives are acknowledged and valued. As an equal-opportunity employer, we consider all potential employees without regard to any protected characteristic.
Important Notice: Recruitment fraud is on the rise, with scammers using misleading promises of job offers and interviews to solicit money and personal information from job seekers. CME Group adheres to established procedures designed to maintain trust, confidence and security throughout our recruitment process. Learn more here.
Skills Required
- 3+ years of experience in information security, computer science, computer forensics, or information assurance
- Familiarity with artificial intelligence and integrating AI into workflows
- Familiarity with the MITRE ATT&CK framework
- Experience collecting, analyzing, and interpreting threat intelligence data from multiple sources
- Experience with cyber incident response, digital forensics, security engineering, security operations, computer network operations, information operations, information warfare, or topical cyber
- Intermediate knowledge of cyber threat intelligence processes and tradecraft, including the Cyber Kill Chain and Diamond Model of Intrusion Analysis
- Experience with multiple scripting languages, including Python and PowerShell
- Familiarity with Linux, including the Linux terminal
- Experience with security operations technologies such as SIEM and log aggregation
- Experience using host and network log sources for investigations and incident response
- Knowledge of attacker tactics, techniques, procedures, attack vectors, and vulnerabilities
- BA or BS degree in Computer Science, Cyber Security, or a related field, or equivalent work experience
- Experience performing advanced static and dynamic malware analysis and using automated malware analysis platforms
- Excellent oral and written communication skills
- Experience in an Intelligence Community or similar intelligence environment
- Experience working in cloud environments
- GIAC Python Coder, GIAC Security Essentials, GIAC Certified Enterprise Defender, another relevant GIAC certification, or other technical industry certification
- Threat intelligence courses
CME Group Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about CME Group and has not been reviewed or approved by CME Group.
-
Retirement Support — U.S. offerings include both a 401(k) and a company-funded cash-balance pension, strengthening long-term financial security. This dual-track structure is highlighted as a notable differentiator among private employers.
-
Leave & Time Off Breadth — PTO and holiday schedules are described as generous, with ample time off and carryover commonly highlighted. This breadth of leave meaningfully enhances perceived total rewards.
-
Flexible Benefits — A flexible, hybrid work model applies to many roles, increasing day-to-day usability of the package. Flexibility is framed as a standard feature rather than an exception.
CME Group Insights
What We Do
As the world's leading derivatives marketplace, CME Group (www.cmegroup.com) is where the world comes to manage risk. CME Group exchanges offer the widest range of global benchmark products across all major asset classes, including futures and options based on interest rates, equity indexes, foreign exchange, energy, agricultural commodities, metals, weather and real estate. CME Group brings buyers and sellers together through its CME Globex® electronic trading platform and its trading facilities in New York and Chicago. CME Group also operates CME Clearing, one of the world’s leading central counterparty clearing provider in the world, which offers clearing and settlement services for exchange-traded contracts, as well as for over-the-counter derivatives transactions through CME ClearPort®. These products and services ensure that businesses everywhere can substantially mitigate counterparty credit risk in both listed and over-the-counter derivatives markets.








