Chicago Board Options Exchange

Senior Security Governance Analyst

Chicago Board Options Exchange • $110K — $157K *
Finance & Insurance
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, or a related field.
  • 5+ years of experience in information security risk management or a similar role.
  • Comprehensive knowledge of security/risk management governance and compliance concepts such as NIST 800-53 and ISO.
  • Familiarity with regulatory frameworks relevant to financial market infrastructure, like SEC Regulation SCI.
  • Experience using and administrating GRC tooling.
  • Proficient with Windows and Linux, including Active Directory and EntraID.
  • Strong analytical, organizational, and communication skills, with the ability to present to all organizational levels.
  • CISSP, CRISC, CISM or other related security certifications.

Responsibilities

  • Conduct assurance and governance activities for security compliance methodologies.
  • Develop and maintain security policies, procedures, and guidelines.
  • Conduct comprehensive security risk assessments and oversee risk remediation.
  • Lead security controls testing and maintain governance of the control library.
  • Prepare regular reports on the organization’s cyber risk posture for senior management.
  • Foster partnerships and collaborate with other departments on security issues.
  • Ensure compliance with relevant industry standards and regulations.
  • Support regulatory exams by obtaining documentation and drafting responses.

Benefits

  • Generous paid time off, including vacation, personal days, and community service days.
  • Health, dental, and vision benefits, including telemedicine and mental health services.
  • 2:1 401(k) match, up to 8% match immediately upon hire.
  • Discounted Employee Stock Purchase Plan.
  • Tax Savings Accounts for health, dependent, and transportation expenses.
  • Employee referral bonus program.
  • Complimentary lunch, snacks, and coffee in any Cboe office.
  • Paid tuition assistance and education opportunities.
Full Job Description
Job Description:

To support strong partnership and team connection, this role follows a four day in office work model.

Location Overview

Cboe Global Markets operates a key office in the Overland Park Xchange (OPx), located in Overland Park, Kansas, a bustling suburb of Kansas City. The OPx business park is strategically positioned to provide convenient access to the Kansas City metropolitan area, offering modern infrastructure and a collaborative environment ideal for the financial services and technology industries. This location benefits from proximity to major highways, making it easily accessible for employees

The OPx site provides a balance of high-quality office space, advanced facilities, and an environment conducive to productivity and growth.

Role Overview

Cboe’s Cyber Governance team is hiring a Senior Specialist, Information Security Governance. The Senior Information Security Specialist is responsible for supporting enterprise-wide cyber risk management and governance activities. This role requires strong knowledge in information technology and internal controls, along with security frameworks and good experience of cybersecurity risk management practices. The individual will collaborate across global teams to assess risks, recommend and implement robust security controls, and contribute to the development and maintenance of information security policies and standards.

In this role, the Senior Information Security Specialist will also coordinate both local and global regulatory compliance efforts, including identifying control gaps and overseeing risk remediation activities. Additionally, the position plays a key role in enhancing the efficiency and effectiveness of security processes through standardization, consistency, and continuous improvement initiatives.

This role contributes to the broader mission of the Information Security function by helping protect the organization’s people, assets, and reputation through strong governance, optimized controls, and scalable security practices, under the three-lines-of-defense model.

Your responsibilities will be:

  • Conduct assurance and governance activities related to organization-specific security compliance methodologies that demonstrate our security governance to management and other key stakeholders including regulators, auditors, and boards.
  • Develop and maintain security policies, procedures, and guidelines according to industry best practices and regulatory requirements.
  • Conduct comprehensive security risk assessments to identify potential risks in the organization’s IT infrastructure and oversee the lifecycle of any security risks, ensuring that remediation is agreed, effective, and timely.
  • Lead security controls testing and maintain governance of the control library, evaluating the effectiveness of existing security controls and procedures and recommending improvements.
  • Prepare regular reports on the organization’s cyber risk posture for presentation to senior management.
  • Foster strong partnerships and collaborate regularly with other departments communicating security issues, obtaining additional information as needed, and providing status of remediation to security management.
  • Ensure compliance with relevant industry standards and regulations (e.g., NIST, DORA, Systems Safeguards, Reg-SCI, etc.).
  • Support regulatory exams by obtaining documentation, drafting responses, and helping develop security action plans.
  • Stay current with the latest cybersecurity global regulatory standards, trends, threats, and technologies, and provide recommendations for improvement.

The ideal candidate has:

  • Bachelor's degree in Cybersecurity, Computer Science, or a related field.
  • 5+ years of experience in information security risk management or similar role.
  • Comprehensive knowledge with a wide range of security/risk management governance, guidance, compliance concepts and documentation such as NIST 800-53, NIST Cybersecurity Framework (CSF), ISO or equivalent.
  • Familiarity with regulatory frameworks relevant to financial market infrastructure, such as SEC Regulation SCI, Systems Safeguards, as applicable.
  • Experience using and administrating GRC tooling.
  • Proficient with Windows and Linux, including Active Directory and EntraID.
  • Strong analytical, good organizational, effective communication, and strong presentation skills with ability to present and respond to questions at all levels of the organization.
  • Flexibility in work given and ability to actively research how to perform new tasks.
  • Proficient in using Microsoft Teams, Excel, PowerPoint, Word and AI tools (Copilot, ChatGPT and others).
  • Proficient with GenAI coding assistance and leveraging AI to improve processes.
  • CISSP, CRISC, CISM or other related security certifications.

Benefits and Perks of working for Cboe Global Markets

We value the total wellbeing of our people – including health, financial, personal and social wellness. We believe standard benefits like health insurance and fair pay are a given at any organization. Still, you should know we offer:

  • Fair and competitive salary and incentive compensation packages with an upside for overachievement 
  • Generous paid time off, including vacation, personal days, sick days and annual community service days  
  • Health, dental and vision benefits, including access to telemedicine and mental health services 
  • 2:1 401(k) match, up to 8% match immediately upon hire 
  • Discounted Employee Stock Purchase Plan  
  • Tax Savings Accounts for health, dependent and transportation 
  • Employee referral bonus program  
  • Volunteer opportunities to help you give back to your communities  

Some of our associates’ favorite benefits and perks include: 

  • Complimentary lunch, snacks and coffee in any Cboe office 
  • Paid Tuition assistance and education opportunities 
  • Generous charitable giving company match 
  • Paid parental leave and fertility benefits  
  • On-site gyms and discounts to other fitness centers 

Salary Ranges (applicable for US locations only)

At Cboe, we are committed to providing a competitive, transparent, and market‑informed total rewards program. The anticipated base salary range for this role is $110,500-$157,300, with actual compensation determined by job‑related factors such as skills, relevant experience, education, internal alignment, and location.

 

 

This role may also be eligible for annual incentive compensation and, where applicable, participation in Cboe's long-term equity programs.

Additional information about Cboe's total rewards program, including benefits and other compensation components, can be found here: Total Rewards at CBOE.​
 


 

Any communication from Cboe regarding this position will only come from a Cboe recruiter who has a @cboe.com email or via LinkedIn Recruiter. Cboe does not use any other third party communication tools for recruiting purposes.

About Chicago Board Options Exchange

The Chicago Board Options Exchange, located at 433 West Van Buren Street in Chicago, is the largest U.S. options exchange with an annual trading volume of around 1.27 billion at the end of 2014. CBOE offers options on over 2,200 companies, 22 stock indices, and 140 exchange-traded funds. The Chicago Board of Trade established the Chicago Board Options Exchange in 1973. The first exchange to list standardized, exchange-traded stock options began its first day of trading on April 26, 1973, in celebration of the 125th birthday of the Chicago Board of Trade. The CBOE is regulated by the Securities and Exchange Commission and owned by Cboe Global Markets.
Learn more about Chicago Board Options Exchange
Industry
Founded
1973

Similar Jobs

More Jobs at Chicago Board Options Exchange

More Finance & Insurance Jobs

Find similar Senior Security Governance Analyst jobs: