Third-Party Cyber Risk Specialist
$76.5k - $108.9kCboe Global Markets
Job Description:
Building trusted markets — powered by our people
At Cboe Global Markets, we inspire our people to solve complex challenges together because what we do matters. We provide the financial infrastructure that powers the global economy. As a leading provider of market infrastructure and tradable products, Cboe delivers cutting-edge trading, clearing and investment solutions to market participants around the world.
We’re building meaningful ways to support professional and personal development while strengthening the trust we’ve earned as a global market leader. Our teams are empowered to share ideas, actively pursue them and bring on a challenge. As champions of internal mobility and access to opportunity, we encourage our people to “go for it” and equip our managers with the training to coach their teams to the next level. We strive to provide employees a safe space to network, share ideas and create opportunities.
Please note: To support strong partnership and team connection, this role follows a four day in office work model in either our Chicago or Overland Park, KS office.
Role Overview
The Global Third-Party Risk Management Team is seeking a Third-Party Risk Management Specialist to assist in executing the risk management program for third-party vendors and service providers. This position includes conducting comprehensive risk assessments, ensuring compliance with Cboe and industry security standards, monitoring vendor relationships, and addressing client due diligence inquiries to mitigate potential risks to the organization. Cboe’s Third Party Risk Management Specialist will specifically focus on cyber threats and vulnerabilities within the third-party ecosystem. Candidates must be able to quickly adjust to changing priorities and adapt to an evolving business environment.
Your responsibilities will be:
Manage incoming client requests (such as assessments, questionnaires, etc.), prioritize and triage requests to appropriate teams, and validate non-disclosure agreements.
Facilitate communication between business, legal, technology, and information security teams to validate questionnaire responses and fulfill general requests related to controls defined by Cboe’s standards and policies.
Serve as a point of contact for internal stakeholders for client due diligence inquiries, ensuring timely and accurate responses.
Function as the subject matter expert for the response management software used for managing and responding precisely and quickly to client due diligence questionnaires.
Manage and maintain a standardized library of responses for client due diligence questionnaires, ensuring accuracy and consistency.
Collaborate with internal experts to update and refine responses as needed.
Assist team with onboarding new vendor relationships.
Collect, review, and process information and documentation from third party vendors/suppliers.
Conduct third-party risk assessments and due diligence reviews. Analyze security information to identify significant control or security gaps and report findings to senior team members.
Perform comprehensive security reviews of potential and existing third-party vendors using questionnaires and security tools to evaluate their cybersecurity controls and identify potential risks.
Analyze identified risks from third parties and prioritize them based on their potential impact and likelihood of occurrence; create remediation plans accordingly.
Continuously monitor third-party vendors' security posture through regular assessments, vulnerability scans, and incident reporting to maintain a consistent level of security.
Coordinate with internal security team to respond to cyber incidents involving third-party vendors, providing necessary support for investigation and remediation.
Assist with regulatory exams by obtaining documentation and drafting responses to regulator inquiries.
Perform additional activities as needed.
The ideal candidate has
Bachelor’s Degree or equivalent work experience in a relevant field.
3+ years’ experience in third-party risk management, vendor management, security incident response, cyber management or comparable field required.
Strong understanding of cybersecurity principles, including application security, access control, and incident response. Knowledge of compliance and regulatory frameworks (e.g., NIST, SOC 2, GDPR, ISO 27001).
Excellent communication and interpersonal skills, with the ability to collaborate effectively with cross-function teams.
Ability to work independently and manage multiple assignments/projects simultaneously.
Experience conducting vendor risk assessments.
Experience with third party/vendor risk management platforms is a plus.
Benefits and Perks of working for Cboe Global Markets
We value the total wellbeing of our people – including health, financial, personal and social wellness. We believe standard benefits like health insurance and fair pay are a given at any organization. Still, you should know we offer:
Fair and competitive salary and incentive compensation packages with an upside for overachievement
Generous paid time off, including vacation, personal days, sick days and annual community service days
Health, dental and vision benefits, including access to telemedicine and mental health services
2:1 401(k) match, up to 8% match immediately upon hire
Discounted Employee Stock Purchase Plan
Tax Savings Accounts for health, dependent and transportation
Employee referral bonus program
Volunteer opportunities to help you give back to your communities
Some of our associates’ favorite benefits and perks include:
Complimentary lunch, snacks and coffee in any Cboe office
Paid Tuition assistance and education opportunities
Generous charitable giving company match
Paid parental leave and fertility benefits
On-site gyms and discounts to other fitness centers
#LI-CP2
More About Cboe Global Markets
We’re reimagining the future of the workplace by focusing on what matters most, our people. Our journey is an inclusive one. We’re investing deeply in leadership programs and career development initiatives that ensure everyone has an equal chance to succeed.
We work with purpose, solving problems with ingenuity, collaboration, and a lot of passion. We’re an engaged and excited team connecting markets across borders and embracing growth in all its forms to achieve incredible outcomes.
Learn more about life at Cboe on our website and LinkedIn .
Equal Employment Opportunity
We're proud to be an equal opportunity employer do not discriminate against any employee or applicant for employment based on any legally protected characteristic, including race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, orVeteran status. We are committed to fostering a workplace where all individuals are valued and respected.
This position is not eligible for visa sponsorship. Candidates must be legally authorized to work in the United States without the need for employer sponsorship now or in the future.
Salary Ranges (applicable for US locations only)
At Cboe, we are committed to providing a competitive, transparent, and market‑informed total rewards program. The anticipated base salary range for this role is $76,500-$108,900, with actual compensation determined by job‑related factors such as skills, relevant experience, education, internal alignment, and location.This role may also be eligible for annual incentive compensation and, where applicable, participation in Cboe's long-term equity programs.
Additional information about Cboe's total rewards program, including benefits and other compensation components, can be found here: Total Rewards at CBOE .
Any communication from Cboe regarding this position will only come from a Cboe recruiter who has a @cboe.com email or via LinkedIn Recruiter. Cboe does not use any other third party communication tools for recruiting purposes.
$76.5k - $108.9k
...KS office. Role Overview The Global Third-Party Risk Management Team is seeking a Third-Party Risk Management Specialist to assist in executing the risk management program... ...Specialist will specifically focus on cyber threats and vulnerabilities within the third...CyberFull timeWork experience placementWork at officeImmediate start- Focus Partners Wealth is seeking a Senior Risk Operations Specialist to support our Cybersecurity program across vulnerability and third‑party risk management. The role collaborates... ...stakeholders to identify, assess, and mitigate cyber risk. Responsibilities include managing...Cyber
- Sr. Governance, Risk & Compliance (GRC)Analyst Newly created seat on a small, growing GRC... ...security provisions, and managing third-party risk. Success here requires someone who can... ...provisions for data security, breach reporting, cyber resilience, and compliance certifications...CyberContract workH1bImmediate start
$80.55k - $115k
...banking and payments. We hope you’ll join us. We can’t do it without you. This analyst serves as a key advisor within Jack Henry’s Third-Party Risk Management (TPRM) program, providing strategic oversight and subject matter expertise to ensure alignment with regulatory...SuggestedFull timeWork at officeLocal areaRemote work$100k - $130k
## Risk SpecialistApplylocations: St. Louis, Missouri: New York... ...oriented Senior Risk Operations Specialist to support and strengthen our... ...assessments and third-party security reviews, considering... ...security gaps, and other identified cyber risks.* Assist in developing...CyberWork at officeLocal area- ...The Digital Risk & Controls Specialist coordinates day-to-day activities that support the Community Foundation's governance and risk management program. This role focuses on digital controls, third-party risk management, and the systems and processes used to help identify...Full timeContract workWork at office
- CSAA Insurance Group is seeking a Senior Third Party Vendor Risk Management Specialist to assess supplier risk and ensure controls align with CSAA tolerance. The role involves profiling, assessment, and issues management using established processes to reduce risk portfolio...Remote job
$164k - $175k
...Description Job Description Obsidian Security is a global leader in cyber security protecting the SaaS and non-human identity layer... ...standard for governing what AI agents can access and do inside third-party applications. With global momentum, a growing partner...CyberRemote workWork from homeFlexible hours$51.62 per hour
Security Risk and Compliance Analyst II Location US-KS-Olathe ID 2026-3919 Category... ...include conducting detailed internal and third-party risk assessments, with a focus on how... ...County systems and data. Your expertise in cyber risk, vendor security, and hybrid architecture...CyberFull timeRemote workMonday to Friday$71.1k - $92k
...current practices or implementing new programs and process within the Risk function. Works on assignments that range from quantitative... ...communicate findings to leadership, stakeholders, and relevant parties. Develop comprehensive risk reports and deliver presentations tailored...Full timeTemporary workPart timeRemote workVisa sponsorshipShift work$93.75 per hour
...Park, KS, with options for Cary, NC or Houston, TX. This temp-to-perm role focuses on governance, risk, and compliance across data security, regulatory requirements, and cyber risk management. The candidate will assess control design and operation, promote risk awareness,...CyberHourly payPermanent employmentTemporary work$25 - $35 per hour
...quality maintenance services across multiple PRES properties and third‑party customers. Under the direction of the Director of Maintenance,... ...annually or more frequently as requested (Fair Housing, Cyber Security, Discrimination, Sexual Harassment, etc.). Personify...CyberTemporary workFor contractorsWork experience placementSeasonal workWork at officeLocal areaImmediate startFlexible hoursShift workWeekend workAfternoon shift- Governance, Risk & Compliance (GRC) Analyst Job Category: Information Technology Requisition Number: GOVER001449 Posted : July 1, 2... ...appropriately reached. Security Operations and Incident Response Assist cyber incident handling as part of the computer incident response team...CyberFull timeCasual workWork at officeWork from homeHome officeNight shiftWeekend work
- ...operations center, we will help companies build cyber resilience to grow with confidence. Our... ...build resilience from within. We blend risk strategy, digital identity, cyber defense,... ...we would rather tell you now than in the third interview. Enterprises are deploying AI...CyberWork experience placementLive inWork at officeLocal area
$93.75 per hour
...perm Overview The Sr. Analyst, Governance, Risk, and Compliance (GRC) plays an important... ...and frameworks, and assisting with third-party/supply chain risk management. The candidate... ...other responsibilities. With an emphasis on cyber, contract and regulatory compliance risk...CyberHourly payPermanent employmentFull timeContract workTemporary workPart time- ...detailed coverage analysis (CA). This position also promotes and supports accurate billing practices to be compliant with Medicare and third-party payment rules. Additionally, this position assists in streamlining research study activation and ensures compliance with federal/...Work experience placementLocal area
$50k
...of Role This role will primarily assist with CRM administration, customizations, implementations, automations, and integrating third-party applications. They will also be involved in building and designing CRM reports and visualizations. The ideal candidate is self-driven...Full timeWork at officeRemote work- ...are comfortable on both sides of a system boundary — consuming third-party APIs on the frontend and writing the backend glue that connects... ...mission-driven partner helping organizations navigate complex cyber threat landscapes. Founded by security practitioners, we’ve grown...CyberTemporary work
$50 - $75 per hour
...Job Description Job Description IT Audit & Risk Analyst Remote (100%) | 12+ Month Contract Position Summary LRS Consulting... ...-term, fully remote contract engagement. This role supports third-party risk management, ITGC testing, vendor assessments, and audit...Hourly payLong term contractPermanent employmentContract workTemporary workLocal areaRemote work$104.8k - $192.2k
...technologies. As a Senior Consultant within EY's Cyber Strategy practice, you will work with... ..., identify opportunities to strengthen risk management and governance, and develop... ...Management, Data Protection, Cloud Security, Third-Party Risk Management, or Zero Trust....CyberSummer holidayFlexible hours- ...Investments seeks a Cybersecurity Intern for an onsite 10-week summer program in Kansas City, MO. You will learn the ins and outs of the Cyber Operations security team, focusing on incident response, phishing, data loss prevention, and AI security activities within a...CyberSummer workInternship
- ...potential. Performance Contracting Group is seeking a Risk Management Analyst I for its corporate Risk & Insurance... ...Operations, Finance, Legal, Safety, Human Resources, brokers, carriers, third-party administrators, and other partners on risk-related information...Contract workFor contractorsWork at officeFlexible hours
- The FBI seeks a highly capable Special Agent in Kansas City to protect national security. You will plan and conduct investigations into cybersecurity, fraud, and other federal offenses, applying your expertise to safeguard the nation. Candidates must be a U.S. citizen, ...CyberWork at office
$103.24k - $133.2k
A federal law enforcement agency is seeking candidates for a special agent position focusing on investigations and cybersecurity. The role requires a bachelor’s degree in linguistics or a related field and emphasizes skills in critical thinking and problem-solving. The ...CyberWork at office- ...areas covering Artificial Intelligence, Cloud Migration, Custom Software Development, Data Analytics Infrastructure & Cloud Solutions, Cyber Security Services, etc. We make reasonable accommodations for clients and employees and we do not discriminate based on any...CyberRelocation
- ...Information Security Analyst for a permanent on-site position. This role involves improving the Information Security Program, conducting cyber-attack simulations, and managing security alerts. Qualified candidates will have a degree and at least 2 years of cybersecurity...CyberPermanent employment
- ...will be brought on to our team to learn the ins and outs of the Cyber Operations security team within a corporate setting. Your projects... .... Passion for gaining experience with Information Security and Risk Management. What We Offer Competitive pay and 401k eligibility...CyberCasual workInternshipWork at officeMonday to Friday
- State Street in Kansas City is seeking a Funds Transfer Business Support Specialist to govern enterprise funds transfer activities and drive risk reduction across the organization. You will work with the Funds Transfer Central Team, provide SME guidance on key initiatives...
- ...position can be performed remotely for candidates who reside in the Kansas City metro area** Essential Functions: Completes on-site risk control surveys of highly sophisticated current and prospective policyholders’ operations, including in niche markets Assesses and analyzes...Full timeTemporary workWork at officeLocal areaRemote work
$77.4k - $110.3k
Join to apply for the Analyst- Risk Management Insurance role at Wabtec Corporation . It’s not just about your career or job title... ...work closely with internal departments, brokers, insurers, and third‑party administrators to manage risk exposures and ensure proper insurance...Work experience placement
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Third-Party Cyber Risk Specialist. Be the first to apply!
- risk consultant Kansas City, MO
- risk analyst Kansas City, MO
- operational risk specialist Kansas City, MO
- operational risk consultant Kansas City, MO
- risk officer Kansas City, MO
- it risk analyst Kansas City, MO
- cyber Kansas City, MO
- risk assurance Kansas City, MO
- risk adjustment Kansas City, MO
- high risk Kansas City, MO


