> Markdown version of [/jobs/ext/2448043-cyber-defense-response-analyst-ii](https://www.wearedevelopers.com/jobs/ext/2448043-cyber-defense-response-analyst-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Defense Response Analyst II - **Company:** CME Group - **Location:** Chicago, IL, United States - **Experience:** Experienced - **Salary:** $93,900.0 - $156,500.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Data Analysis, Microsoft Azure, Cloud Computing, Cyber Security, Computer Programming, Computer Networks, Computer Forensics, Digital Forensics, Forensics Tools (Digital Forensics Software), Python (Programming Language), ArcSight SIEM Tool, Security Information and Event Management, Forensic Toolkit, Data Processing, Google Cloud, Multi-Cloud, Malware, Pandas, Information Technology, IDA Pro, Cybercrime, Encase, Restful APIs, Splunk - **Published:** August 28, 2026 - **Apply:** https://www.dice.com/job-detail/e45b8376-0aaf-4442-becf-1d731a52bc2b ## About the Role * Innate Curiosity: An exceptional level of curiosity and a track record of self-teaching advanced technical concepts. * Highly Innovative: You have a consistent record of taking unorthodox approaches to challenges and a demonstrated ability to innovate within information technology domains. * A "Researcher" Mindset: A passion for collecting facts, debating details, and diving into "rabbit holes" to solve complex problems. * Adept at High-Pressure Communication: Ability to deal effectively at all levels of the organization and translate technical research into clear, actionable intelligence for leadership. * Highly Detail Oriented: Very strong attention to detail; you notice things others often don't. * Impactfully Collaborative: You excel at technical collaboration and helping teams deliver high-impact. Preferred Technical Qualifications: * DFIR Background: 2+ years of practical experience with Digital Forensics, Incident Handling, and/or Malware Analysis. * SIEM/Data Analysis: 2+ years of experience with Q Radar, Sentinel, Splunk, Chronicle, ArcSight, or similar log management technologies. * Experience using leading forensics tools: 2+ years of experience using tools such as KAPE, EnCase, Cellebrite, FTK, Magnet Axiom, and Autopsy, plus comfort with malware analysis tools like Ghidra, Ida Pro, PEStudio, and x64dbg. * Strong IT Fundamentals: Strong understanding of computer networking, operating systems, and their intersection with Cybersecurity. * Programming Skills: Development experience with Python, specifically for data manipulation (Pandas) and interacting with REST APIs. * Cloud Experience: Practical experience with AWS, Google Cloud Platform, or Azure. Education & Certifications: * Education: BA/BS in Engineering, Computer Science, or Information Security (non-tech degrees acceptable with appropriate levels of Information Security job experience and/or certifications) * Certifications: GCIH, GCFE, GCFA, OSCP, Sec+, and similar cyber-oriented certifications are desired ## Description * Digital Forensics and Incident Response: Drive the full incident response lifecycle from initial triage to remediation, confidently applying specialty skills like endpoint forensics and malware analysis. Be ready to operate in a multi-cloud environment. * Threat Hunting:Conduct regular threat hunts to identify misconfigurations, detection gaps, and other anomalies. * Automation & Engineering: Use AI, Python and REST APIs to build/integrate security tools for incident response needs, while working with automation engineers to develop heavy-duty solutions for advanced use-cases. * Tabletop Exercises (TTX): Lead regular tabletop exercises to improve team readiness. * Technical Documentation: Contribute continuously to our internal knowledge base of incident response runbooks and playbooks, keeping it exhaustive, accurate, and reflective of the latest workflows. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Advanced Typing in TypeScript](https://www.wearedevelopers.com/videos/496-advanced-typing-in-typescript) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Data Science on Software Data](https://www.wearedevelopers.com/videos/162-data-science-on-software-data) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Getting to Know Your Legacy (System) with AI-Driven Software Archeology](https://www.wearedevelopers.com/videos/1437-getting-to-know-your-legacy-system-with-ai-driven-software-archeology) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud)