Cyber Defense Response Analyst II
CME Group
Chicago, IL
The Role
The analyst drives the full incident response lifecycle — from initial triage through remediation — handling medium-severity incidents in a multi-cloud environment. Responsibilities also include regular threat hunting, leading tabletop exercises, building automation tools using Python and REST APIs, and maintaining internal IR runbooks and playbooks. The role operates on a second shift schedule initially.
Skills & Experience
Candidates should have 2+ years of DFIR or malware analysis experience and familiarity with SIEM platforms such as Splunk, QRadar, or Sentinel. Forensic tools including KAPE, EnCase, FTK, and Magnet Axiom are required, alongside malware analysis tools like Ghidra and IDA Pro. Python development, cloud platform experience (AWS, GCP, Azure), and certifications such as GCIH, GCFA, or GCFE are desirable.
Who It Suits
This role suits a curious, self-motivated mid-level security professional who thrives on deep technical research and cross-functional collaboration. Someone with a researcher’s mindset, comfortable working under pressure and communicating findings to leadership, will excel — particularly those eager to develop across forensics, threat hunting, and security engineering disciplines.
Typical advertised salary for Incident Response roles in United States: $125,000–$180,000 (median $150,000 — from 154 recent listings analysed by Forensic Focus).
Compare Incident Response salaries in United States →
Certifications mentioned: GCFA · GCFE · GCIH — find training for these on the DFIR Training Finder.





