Third-Party Cyber Risk Specialist
$84.15k - $108.9kCboe Global Markets
Third-Party Cyber Risk Specialist
Building trusted markets — powered by our people
At Cboe Global Markets, we inspire our people to solve complex challenges together because what we do matters. We provide the financial infrastructure that powers the global economy. As a leading provider of market infrastructure and tradable products, Cboe delivers cutting-edge trading, clearing and investment solutions to market participants around the world.
We're building meaningful ways to support professional and personal development while strengthening the trust we've earned as a global market leader. Our teams are empowered to share ideas, actively pursue them and bring on a challenge. As champions of internal mobility and access to opportunity, we encourage our people to "go for it" and equip our managers with the training to coach their teams to the next level. We strive to provide employees a safe space to network, share ideas and create opportunities.
To support strong partnership and team connection, this role follows a four day in office work model in our Chicago, IL office.
Location Overview
Cboe HQ is located in the historic Old Post Office district, it's a landmark that blends classic architecture with modern amenities. The building features expansive spaces with high ceilings and large windows, offering an abundance of natural light and panoramic views of the city skyline and the Chicago River.
With its prime location in the heart of downtown, the OPO Building provides easy access to major transportation hubs, including Union Station and multiple CTA lines, making it convenient for commuters. The building is home to a variety of amenities, including restaurants, a fitness center, and collaborative workspaces, creating a vibrant and dynamic work environment in one of Chicago's most iconic areas.
Role Overview
The Global Third-Party Risk Management Team is seeking a Third-Party Cyber Risk Specialist to assist in executing the risk management program for third-party vendors and service providers. This position includes conducting comprehensive risk assessments, ensuring compliance with Cboe and industry security standards, monitoring vendor relationships, and addressing client due diligence inquiries to mitigate potential risks to the organization. Cboe's Third Party Cyber Risk Specialist will specifically focus on cyber threats and vulnerabilities within the third-party ecosystem. Candidates must be able to quickly adjust to changing priorities and adapt to an evolving business environment.
This role requires four days per week on-site at our Chicago, IL office.
Your responsibilities will be:
- Manage incoming client requests (such as assessments, questionnaires, etc.), prioritize and triage requests to appropriate teams, and validate non-disclosure agreements.
- Facilitate communication between business, legal, technology, and information security teams to validate questionnaire responses and fulfill general requests related to controls defined by Cboe's standards and policies.
- Serve as a point of contact for internal stakeholders for client due diligence inquiries, ensuring timely and accurate responses.
- Function as the subject matter expert for the response management software used for managing and responding precisely and quickly to client due diligence questionnaires.
- Manage and maintain a standardized library of responses for client due diligence questionnaires, ensuring accuracy and consistency.
- Collaborate with internal experts to update and refine responses as needed.
- Assist team with onboarding new vendor relationships.
- Collect, review, and process information and documentation from third party vendors/suppliers.
- Conduct third-party risk assessments and due diligence reviews. Analyze security information to identify significant control or security gaps and report findings to senior team members.
- Perform comprehensive security reviews of potential and existing third-party vendors using questionnaires and security tools to evaluate their cybersecurity controls and identify potential risks.
- Analyze identified risks from third parties and prioritize them based on their potential impact and likelihood of occurrence; create remediation plans accordingly.
- Continuously monitor third-party vendors' security posture through regular assessments, vulnerability scans, and incident reporting to maintain a consistent level of security.
- Coordinate with internal security team to respond to cyber incidents involving third-party vendors, providing necessary support for investigation and remediation.
- Assist with regulatory exams by obtaining documentation and drafting responses to regulator inquiries.
- Perform additional activities as needed.
The ideal candidate has:
- Bachelor's Degree or equivalent work experience in a relevant field.
- 3+ years' experience in third-party risk management, vendor management, security incident response, cyber management or comparable field required.
- Strong understanding of cybersecurity principles, including application security, access control, and incident response. Knowledge of compliance and regulatory frameworks (e.g., NIST, SOC 2, GDPR, ISO 27001).
- Excellent communication and interpersonal skills, with the ability to collaborate effectively with cross-function teams.
- Ability to work independently and manage multiple assignments/projects simultaneously.
- Experience conducting vendor risk assessments.
- Experience with third party/vendor risk management platforms is a plus.
Benefits and Perks of working for Cboe Global Markets
We value the total wellbeing of our people – including health, financial, personal and social wellness. We believe standard benefits like health insurance and fair pay are a given at any organization. Still, you should know we offer:
- Fair and competitive salary and incentive compensation packages with an upside for overachievement
- Generous paid time off, including vacation, personal days, sick days and annual community service days
- Health, dental and vision benefits, including access to telemedicine and mental health services
- 2:1 401(k) match, up to 8% match immediately upon hire
- Discounted Employee Stock Purchase Plan
- Tax Savings Accounts for health, dependent and transportation
- Employee referral bonus program
- Volunteer opportunities to help you give back to your communities
Some of our associates' favorite benefits and perks include:
- Complimentary lunch, snacks and coffee in any Cboe office
- Paid Tuition assistance and education opportunities
- Generous charitable giving company match
- Paid parental leave and fertility benefits
- On-site gyms and discounts to other fitness centers
Equal Employment Opportunity
We're proud to be an equal opportunity employer do not discriminate against any employee or applicant for employment based on any legally protected characteristic, including race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, or veteran status. We are committed to fostering a workplace where all individuals are valued and respected.
This position is not eligible for visa sponsorship. Candidates must be legally authorized to work in the United States without the need for employer sponsorship now or in the future.
Salary Ranges (applicable for US locations only)
At Cboe, we are committed to providing a competitive, transparent, and market-informed total rewards program. The anticipated base salary range for this role is $84,150-$108,900, with actual compensation determined by job-related factors such as skills, relevant experience, education, internal alignment, and location.
This role may also be eligible for annual incentive compensation and, where applicable, participation in Cboe's long-term equity programs.
Additional information about Cboe's total rewards program, including benefits and other compensation components, can be found here: Total Rewards at CBOE.
Any communication from Cboe regarding this position will only come from a Cboe recruiter who has a @cboe.com email or via LinkedIn Recruiter. Cboe does not use any other third party communication tools for recruiting purposes.
- Northern Trust Corp is seeking a Director of Cyber Third-Party Risk Management (CTPRM) in Chicago, IL. This role will define and execute the CTPRM strategy for North America, overseeing cyber risk assessments and developing third-party risk frameworks. Candidates should...Cyber
$95k - $143.6k
...performing information security reviews of third parties that provide services to the bank. Key... ...a third party's information security risk with a holistic lens to determine if they... ...Required Qualifications 2+ years as a cyber Assessor. Experience in Information Security...CyberShift workDay shift- Third Party Risk Analyst, Sr Job Locations US-IN-Evansville | US-MN-Lake Elmo | US-IL-Chicago Category/Function Risk/Security Position Type Regular Full-Time Requisition ID 2026-19267 Workplace Type On Site...SuggestedFull timeWork at office
$95.6k - $162.4k
Northern Trust Corp in Chicago is looking for a Senior Consultant in Third Party Risk Management. The role involves overseeing governance, ensuring compliance with risk policies, and supporting audit engagements. Candidates should possess strong analytical skills and understanding...SuggestedFull time- Overview We are seeking a detail-oriented and analytical Third-Party Risk Analyst to support our risk management program. This role is responsible for reviewing client contracts for security and compliance requirements, assessing vendor and third-party risks, and maintaining...SuggestedContract work
$86k - $101k
...bank from regulatory, operational, financial, and reputational risk through proactive compliance oversight, managing network inquiries... ...merchant violations, compliance program notifications, third‑party agent compliance, and enforcement actions to ensure timely remediation...Local areaVisa sponsorshipWork visaFlexible hours$137.4k - $240.4k
...most sophisticated clients using leading technology and exceptional service. We are seeking an experienced Director of Cyber Third-Party Risk Management (CTPRM) to lead and mature the enterprise third-party cyber risk program across North America, with a strong focus...CyberH1bFlexible hours$90k - $110k
...the largest employers in downtown Chicago looking for their next Cyber Security Analysis/Audit Lead. This person will conduct platform... ...related reports. They will serve as organization’s POC for the third party certification of security procedures and use of cyber security...CyberWork experience placementSummer work$160k - $200k
...Blackkite, a leader in cyber third-party risk intelligence, is seeking a motivated Account Executive based in the West Coast to drive new business and revenue growth within commercial and mid-market accounts. The successful candidate will manage the full sales cycle,...Cyber- ...a client in the regulatory technology space. This client is expanding their offerings into the insurance industry and are seeking a risk and compliance subject matter expert to guide their product teams. This role covers the AI vendor onboarding and ongoing oversight angle...Contract work
- ...Assessment Scheduling Automation - Automate the scheduling processes for assessments. Develop a SOR to normalize assessment data. Third Party Cyber Security Framework – Modernize the assessment solution and portal to automate manual processes. Full stack.NET developer....Cyber
$160k - $200k
Black Kite, a leader in cyber third-party risk intelligence, is looking for a motivated Account Executive to drive new business with commercial and mid-market accounts. The ideal candidate will manage the full sales cycle, from prospecting to closing deals, and collaborate...Cyber- The Canadian Imperial Bank of Commerce is seeking a strategic leader with 7-10+ years in third party risk assessment, technology, and cybersecurity. The ideal candidate will drive program evolution while communicating complex concepts clearly to diverse stakeholders. In...
- ...informed, predictive, and cost-effective risk mitigation decisions – faster. Powered... ...like NIST Risk Management Framework, NIST Cyber Security Framework, NIST Privacy... ...quality reports for clients and industry third parties like payment card brands and the PCI Security...CyberLocal areaRemote work
- ...Months Only W2 candidates are eligible for this position. Third-party or C2C candidates will not be considered Description: Client... ...Furnished Equipment (GFE) complete with all required cyber protections, software licenses and tools needed to complete the...CyberContract workFor contractorsLocal area
- ...Senior Analyst, Cybersecurity Governance, Risk and Compliance, Chicago, IL The Senior Analyst, Cybersecurity Governance Risk... ...implemented for managed systems and applications, as well as support Third Party Risk Management (TPRM) and Governance and Risk functions in...Work experience placement
$104.5k - $213.8k
...to help financial institutions stay ahead of evolving risks. We are seeking a Financial Services Cybersecurity Internal... ...Centers (SOC) Data Services and Data Governance Third Party Risk Management (TPRM) Cyber Resilience and Incident Response Infrastructure risk...CyberLocal areaWorldwide- ...participates with onsite and virtual audits and risk remediation. Support the GRC program... ...system documentation supporting usage of third party solutions in the delivery of vendor... ...or CISA certifications Security Ops, Cyber Security or programming experience Technical...Cyber
$76.4k - $138.6k
...build client trust. Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions... ...include aiding in the assessment and validation of third‑party risk assessments and ensuring that EY's security...CyberSummer holidayLocal areaFlexible hours$160k - $200k
...Come join the leader in cyber third-party risk intelligence! Black Kite gives organizations a comprehensive, real-time view into cyber ecosystem risk so they can make informed risk decisions and improve business resilience while continuously monitoring more vendors, partners...CyberRemote work- A leading cybersecurity firm is seeking a Sales Specialist - Cyber Risk Solutions in Chicago. The role involves being a trusted advisor for the sales team, focusing on the adoption of the TruRisk Platform. Responsibilities include collaborating on sales strategies, leading...Cyber
$128.1k - $239.6k
...client trust. Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions... ...for technology infrastructure, applications, and third-party dependencies. Improve compliance with security standards...CyberWork experience placementSummer holidayLocal areaFlexible hours$85k - $110k
...day‑to‑day operations of AI and Technology Risk Governance, with primary responsibility... ...governance activities across AI Systems, Cyber Security, Data Privacy (IT lens), and IT... ...Support Vendor Management in aligning with third‑party risk requirements AI Governance...CyberTemporary workWork at officeRemote workHome officeFlexible hours$325k - $350k
...operating in 64 countries. Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh and... ...by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting; making all organizations...CyberPart time- ...Cyber Security Sme Location: Chicago, IL Duration: 6-12 Months Rate: DOE Expertise in cybersecurity solutions like SOC, MDR... ...action to locate and prevent threats. Knowledge of 3rd party tools Crowdstrike, LogRythem, Netspoke, Semperis, Illumio Identity...Cyber
$84.2k - $131k
...Senior Credit Risk Analyst In this hybrid role based at our Chicago Headquarters, you will develop and review credit policies and... ...mortgage loans. Perform evaluation, implementation and monitoring of third-party and in-house scoring solutions. Perform model and strategy...Full timeTemporary workPart timeWork from home3 days per week$45 - $55 per hour
...for cash treasuries as well as Bilateral Tri-party Repo. The candidate is responsible for daily monitoring of market risk and manage obligations in the event of a clearing... ...the consultant will be directly employed by a third party vendor, which would provide pay and...Hourly payFixed term contractWorldwide- A management consulting and technology firm is seeking a Governance & Risk Analyst to support Third-Party Risk Management and Vendor Risk Assessments. The ideal candidate will have a bachelor's degree in a related field and at least 2 years of experience in IT risk management...
$91k - $321.5k
...Specialty/Competency: IFS - Risk & Quality (R&Q) Industry/Sector... ...a Risk Management - Contract Specialist - Managed Services - Senior... ...application managed services, (3) cyber managed services, or (4) risk... ...and external contract parties; - Driving process improvement...CyberFull timeContract workH1b$80k - $90k
...our infrastructure to process 100 billion risk signals daily. This isn't just growth; it... ...reimagining of how the world manages cyber risk. We build the Cyber Risk Posture... ...architects of digital resilience. In an era where third-party risk is more complex than ever, we...CyberFull timeRemote workWork from homeRelocation
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Third-Party Cyber Risk Specialist. Be the first to apply!
- transaction risk analyst Chicago, IL
- operational risk consultant Chicago, IL
- governance risk & compliance analyst Chicago, IL
- it risk analyst Chicago, IL
- information risk analyst Chicago, IL
- risk compliance officer Chicago, IL
- operational risk specialist Chicago, IL
- risk analyst Chicago, IL
- third party risk analyst Chicago, IL
- senior quantitative risk analyst Chicago, IL

