Demo

Cyber Exercise Program Manager (1.1)

CME Group
New York, NY Full Time
POSTED ON 2/16/2025
AVAILABLE BEFORE 3/15/2025
The Cyber Exercise Program Manager is a high visibility position responsible for the planning, design, and execution of strategic and operational cyber exercises (e.g., simulations, workshops, tabletops, functional exercises). The exercises test CME Group’s incident response plan and the resiliency of CME Group’s people, policies, and processes against realistic simulated cybersecurity events. Employees across functional areas (e.g., technology, business, legal, compliance) and from all levels, including senior management, participate in exercises. In addition, the Cyber Exercise Program Manager will coordinate with the Cyber Defense Resilience Manager to support CME Group participation in cyber exercises hosted by external parties (e.g., Treasury, FS-ISAC).

  • Candidates must be willing to relocate to Chicago, Illinois and may be eligible for relocation assistance.

The person in this role will coordinate internal subject matter experts to develop plausible attack scenarios informed by internally and externally researched risks and trends, turn those scenarios into well-documented plans, and lead the exercises by playing out the scenarios in real-time.

To be successful in this role, a candidate must be organized and able to create timelines, inject schedules, and handouts; meet target deadlines; build relationships across the organization; maintain program documentation; and coordinate persons from multiple areas in preparation of the exercises. The Manager in this role is expected to have working knowledge of enterprise technologies (e.g., networks, databases) and deep interest in cybersecurity topics and industry trends.

The person in this role will present to all levels of management before, during, and after exercises. The Manager must be a strong communicator and comfortable presenting to technical and non-technical stakeholders. Additionally, the person in this role must be comfortable interviewing a range of employees, workshopping ideas for new scenarios, and gaining stakeholder buy-in. During exercises, the Manager is responsible for directing the exercise and capturing key takeaways to later create recommendations for improvement and findings.

This position reports to the Executive Director of Technology Risk Management & Controls and is responsible for managing third-party consultants in support of the exercise function and developing an internal employee team. Management experience and experience managing consultants is a plus.

Primary Responsibilities

  • Coordinate subject matter experts to develop cyber exercises and create business-level scenario storylines, technical-level attack chains, exercise inject timelines, delivery structures, and logistics plans
  • Develop pre-exercise, exercise, and post-exercise materials – including presentations, scenario injects, and after-action reports
  • Lead cyber exercise engagements multiple times per year
  • Manage relationships with third-party consultants to assist in the creation, documentation, and execution of the exercises
  • Document risks and findings discovered during exercises and drive improvement
  • Assist in the maintenance and testing of internal policies and procedures
  • Potential travel up to 10%

Personal Attributes

  • Strong organizational skills and ability to work to meet deadlines
  • Effective verbal and written communication skills, and comfort presenting to large groups and senior executive leadership
  • Excellent listening and interpersonal skills, and ability to run large meetings
  • Highly self-motivated and directed with keen attention to detail
  • Ability to deal diplomatically and effectively at all levels of the organization in both technical and non-technical areas

Professional Experience

  • 5 years of relevant experience developing or supporting tabletop exercises and simulations, or relevant business continuity / disaster recovery / incident response/threat modeling experience
  • 5 years working in a cybersecurity or technology operations support role in an enterprise environment
  • Ability to communicate complex technical concepts to a non-technical audience
  • Relevant experience in financial or other highly-regulated industries
  • Successful candidates should be able to demonstrate a passion for information security through coursework, degrees, self-study, or certifications that have been completed

Education & Certifications

  • BA/BS in Business, English, Information Technology, Cybersecurity (or related work experience)
  • One or more of the following: Homeland Security Exercise and Evaluation Program (HSEEP) Certificate, Master Exercise Practitioner (MEP) certification, Certified Cyber Resilience Professional (CCRP), Certified Business Continuity Professional (CBCP)
  • One or more of the following: Security , SSCP, CISSP, GCPM, PMP, CISM, CISA (or related experience)
  • 1

CME Group is committed to offering a competitive total rewards package for our employees that recognizes their contributions to the business and reflects our long-term investment in their future. The salary range for this role is $131,200-$218,600. Actual salary offered will be dependent on a wide array of factors including but not limited to: relevant experience, skills, education and comparison to internal employees (where relevant). Our compensation program also includes an annual target bonus opportunity for all employees, as well as the opportunity to become an owner in the company through our broad-based equity program. Through our Benefits program, we strive to offer flexibility, value and choice. From comprehensive health coverage, to a retirement package that includes both a 401(k) and an active Pension Plan, to highly competitive education reimbursement provisions, paid time off and a mental health benefit, CME Group offers a holistic Benefits package for our team and their dependents.

CME Group : Where Futures are Made

CME Group is the world’s leading and most diverse derivatives marketplace. But who we are goes deeper than that. Here, you can impact markets worldwide. Transform industries. And build a career by shaping tomorrow. We invest in your success and you own it – all while working alongside a team of leading experts who inspire you in ways big and small. Problem solvers, difference makers, trailblazers. Those are our people. And we’re looking for more.

Salary : $131,200 - $218,600

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Cyber Exercise Program Manager (1.1)?

Sign up to receive alerts about other jobs on the Cyber Exercise Program Manager (1.1) career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$99,793 - $130,112
Income Estimation: 
$125,027 - $157,872
Income Estimation: 
$125,027 - $157,872
Income Estimation: 
$149,432 - $188,965
Income Estimation: 
$163,631 - $209,073
Income Estimation: 
$192,911 - $256,346
Income Estimation: 
$192,911 - $256,346
Income Estimation: 
$228,678 - $310,400
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at CME Group

CME Group
Hired Organization Address New York, NY Full Time
CME Group is currently looking for a Clearing House Risk Year-around Intern The Pricing and Valuation Analyst Interns as...
CME Group
Hired Organization Address Chicago, IL Full Time
The Global HR Operations team is looking for a Sr HR Operations Analyst in the US. The HR Operations team provides opera...
CME Group
Hired Organization Address Chicago, IL Full Time
Job Details Role is Hybrid (2 days on-site) in our Chicago office. The final round of the interview is going to be in pe...
CME Group
Hired Organization Address Chicago, IL Intern
Description CME Group is currently looking for a Clearing House Risk Quant Model Verification Year Long Internship. This...

Not the job you're looking for? Here are some other Cyber Exercise Program Manager (1.1) jobs in the New York, NY area that may be a better fit.

Technical Sales Training Program - Equipment (July, 2025) – Associate Account Manager

Equipment (July, 2025) – Associate Account Manager - Trane Technologies Careers, Little Rock, NY

Technical Sales Training Program - Controls (July, 2025) – Associate Account Manager

Controls (July, 2025) – Associate Account Manager - Trane Technologies Careers, Little Rock, NY

AI Assistant is available now!

Feel free to start your new journey!