Senior Security Governance Analyst

Cboe Global Markets•Overland Park, MO
•Hybrid

About The Position

Building trusted markets — powered by our people At Cboe Global Markets, we inspire our people to solve complex challenges together because what we do matters. We provide the financial infrastructure that powers the global economy. As a leading provider of market infrastructure and tradable products, Cboe delivers cutting-edge trading, clearing and investment solutions to market participants around the world. We’re building meaningful ways to support professional and personal development while strengthening the trust we’ve earned as a global market leader. Our teams are empowered to share ideas, actively pursue them and bring on a challenge. As champions of internal mobility and access to opportunity, we encourage our people to “go for it” and equip our managers with the training to coach their teams to the next level. We strive to provide employees a safe space to network, share ideas and create opportunities. To support strong partnership and team connection, this role follows a four day in office work model. Cboe’s Cyber Governance team is hiring a Senior Specialist, Information Security Governance. The Senior Information Security Specialist is responsible for supporting enterprise-wide cyber risk management and governance activities. This role requires strong knowledge in information technology and internal controls, along with security frameworks and good experience of cybersecurity risk management practices. The individual will collaborate across global teams to assess risks, recommend and implement robust security controls, and contribute to the development and maintenance of information security policies and standards. In this role, the Senior Information Security Specialist will also coordinate both local and global regulatory compliance efforts, including identifying control gaps and overseeing risk remediation activities. Additionally, the position plays a key role in enhancing the efficiency and effectiveness of security processes through standardization, consistency, and continuous improvement initiatives. This role contributes to the broader mission of the Information Security function by helping protect the organization’s people, assets, and reputation through strong governance, optimized controls, and scalable security practices, under the three-lines-of-defense model.

Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, or a related field.
  • 5+ years of experience in information security risk management or similar role.
  • Comprehensive knowledge with a wide range of security/risk management governance, guidance, compliance concepts and documentation such as NIST 800-53, NIST Cybersecurity Framework (CSF), ISO or equivalent.
  • Familiarity with regulatory frameworks relevant to financial market infrastructure, such as SEC Regulation SCI, Systems Safeguards, as applicable.
  • Experience using and administrating GRC tooling.
  • Proficient with Windows and Linux, including Active Directory and EntraID.
  • Strong analytical, good organizational, effective communication, and strong presentation skills with ability to present and respond to questions at all levels of the organization.
  • Flexibility in work given and ability to actively research how to perform new tasks.
  • Proficient in using Microsoft Teams, Excel, PowerPoint, Word and AI tools (Copilot, ChatGPT and others).
  • Proficient with GenAI coding assistance and leveraging AI to improve processes.

Nice To Haves

  • CISSP, CRISC, CISM or other related security certifications.

Responsibilities

  • Conduct assurance and governance activities related to organization-specific security compliance methodologies that demonstrate our security governance to management and other key stakeholders including regulators, auditors, and boards.
  • Develop and maintain security policies, procedures, and guidelines according to industry best practices and regulatory requirements.
  • Conduct comprehensive security risk assessments to identify potential risks in the organization’s IT infrastructure and oversee the lifecycle of any security risks, ensuring that remediation is agreed, effective, and timely.
  • Lead security controls testing and maintain governance of the control library, evaluating the effectiveness of existing security controls and procedures and recommending improvements.
  • Prepare regular reports on the organization’s cyber risk posture for presentation to senior management.
  • Foster strong partnerships and collaborate regularly with other departments communicating security issues, obtaining additional information as needed, and providing status of remediation to security management.
  • Ensure compliance with relevant industry standards and regulations (e.g., NIST, DORA, Systems Safeguards, Reg-SCI, etc.).
  • Support regulatory exams by obtaining documentation, drafting responses, and helping develop security action plans.
  • Stay current with the latest cybersecurity global regulatory standards, trends, threats, and technologies, and provide recommendations for improvement.

Benefits

  • Fair and competitive salary and incentive compensation packages with an upside for overachievement
  • Generous paid time off, including vacation, personal days, sick days and annual community service days
  • Health, dental and vision benefits, including access to telemedicine and mental health services
  • 2:1 401(k) match, up to 8% match immediately upon hire
  • Discounted Employee Stock Purchase Plan
  • Tax Savings Accounts for health, dependent and transportation
  • Employee referral bonus program
  • Volunteer opportunities to help you give back to your communities
  • Complimentary lunch, snacks and coffee in any Cboe office
  • Paid Tuition assistance and education opportunities
  • Generous charitable giving company match
  • Paid parental leave and fertility benefits
  • On-site gyms and discounts to other fitness centers
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service