Cyber Defense Analyst III

CME Group

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Chicago, IL
Salary
$103,500–$172,500 / yr
Employment
Full-time
Posted
8 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $149k
This role $138k
$94k most similar roles pay here $189k

This role pays less than 60% of similar roles. Most pay $122,275–$174,744 — the shaded band above. At the midpoint, this role pays about $138k versus about $149k for comparable roles.

Based on 240 similar postings.

Employer

About CME Group

CME Group operates the world''s largest financial derivatives marketplace, offering futures and options products across interest rates, equity indexes, foreign exchange, energy, agricultural products, and metals. Industry: Financial Exchanges & Derivatives

CME Group currently has 7 open roles on FindRole.

Listed pay typically runs $125,800–$209,600 across 7 roles with salary data.

Most-posted roles

View all roles at CME Group

At a glance

TL;DR · Cyber Defense Analyst III

The Cyber Defense Analyst III serves as a critical bridge between traditional security monitoring and modern engineering practices within the Security Operations Center. This role involves performing deep-dive telemetry analysis across network, host, identity, and cloud environments to identify malicious activity while reducing false positives. The analyst will proactively identify manual bottlenecks to develop Python scripts or SOAR playbooks, supporting a transition toward Detection-as-Code using Git and CI/CD pipelines. Key responsibilities include conducting hypothesis-driven threat hunts, mentoring junior analysts, and refining AI-assisted triage workflows. Required skills include proficiency in Python or PowerShell for REST API interaction, experience with platforms like Cortex XSOAR or Splunk SOAR, and knowledge of the MITRE ATT&CK framework. The role addresses the technical challenge of automating repetitive tasks to improve detection fidelity within a complex security ecosystem.

What you'll do

  • Analyze and validate complex security events across network, host, identity, and cloud telemetry to identify malicious activity.
  • Provide enriched and contextualized security alerts to the Incident Response team to ensure seamless handoffs.
  • Develop Python scripts and SOAR playbooks to automate repetitive manual monitoring tasks within the SOC.
  • Build, test, and deploy SIEM detection rules using Detection-as-Code principles, version control, and CI/CD pipelines.
  • Test and refine AI-assisted workflows and agentic triage outputs to ensure high operational accuracy.
  • Conduct hypothesis-driven threat hunts and operationalize threat intelligence into automated detection mechanisms.
  • Provide technical mentorship to junior analysts regarding automation, critical thinking, and monitoring processes.
  • Maintain detailed documentation of monitoring processes, playbook logic, and detection schemas in the Knowledge Management System.

What we're looking for

  • 4–6 years of experience in a SOC, Detection Engineering, or advanced Cyber Defense monitoring environment.
  • Deep knowledge of network protocols, OS internals (Windows/Linux/macOS), and MITRE ATT&CK framework tactics.
  • Proficiency in Python or PowerShell for interacting with REST APIs, parsing JSON/XML, and automating security tasks.
  • Hands-on experience building or modifying playbooks within modern SOAR platforms like Cortex XSOAR, Splunk SOAR, Torq, or Tines.
  • Familiarity with cloud environments (preferably GCP or AWS) and investigating cloud-specific telemetry and identity abuse.
  • Experience or strong interest in version control (Git), Detection-as-Code, and basic CI/CD workflows.
  • Willingness to learn and adapt to emerging AI capabilities and LLM prompt refinement for security investigations.
  • BA/BS in Computer Science, Information Security, Engineering, or a related field; relevant industry certifications are preferred.

More like this

Similar roles

Cyber Defense Response Analyst II

CME Group

Chicago, IL 36 days ago $93,900–$156,500
Digital Forensics Incident Response Malware Analysis Python Pandas REST APIs AWS GCP Azure Q Radar Sentinel Splunk Chronicle ArcSight KAPE EnCase Cellebrite FTK Magnet Axiom Autopsy Ghidra Ida Pro PEStudio x64dbg SIEM

Cyber Threat Detection & Response Analyst

McKesson Corporation

Richmond, VA 4 days ago $98,900–$164,900
SIEM EDR XDR SOAR Python PowerShell Bash KQL SPL AWS Azure GCP Linux Windows IDS/IPS Firewalls NIST CIS Benchmarks
4+ yrs exp

Computer Network Defense Analyst

Leidos

Arlington, VA 10 days ago $69,550–$125,725
Network Defense SIEM Splunk Elastic AWS Azure IDS/IPS Firewalls Windows Red Hat Cloud Migration Incident Response Network Log Analysis Security+ DISA Disaster Recovery Business Continuity
2+ yrs exp

Cyber Security Analyst III Senior

The Federal Reserve

Cleveland, OH 18 days ago $111,400–$139,200
NIST 800-53 NIST Cybersecurity Framework Microsoft Azure Google Cloud Platform SIEM Cyber Incident Response Threat Intelligence Network Architecture Penetration Testing Digital Forensics ITIL COBIT GRC
10+ yrs exp

Cyber Threat Intelligence Analyst III

Leidos

Washington, DC +2 23 days ago
Cyber Threat Intelligence Cyber Kill Chain Diamond Model Splunk Analyst1 Python Bash PowerShell C++ CrowdStrike Falcon Tanium Proofpoint TAP Zscaler Malware Analysis Incident Response Threat Hunting Forensics XML HTML
8+ yrs exp

Cyber Analyst

Leidos

Lawton, OK 56 days ago $87,100–$157,450
SOC Detection Engineering Forensics Linux Wireshark Agile Scrum Network Analysis Memory Forensics Cybersecurity Threat Intelligence TTPs
4+ yrs exp