Sr. Vulnerability Analyst

Cedar Cares, Inc

Chicago (IL)

Hybrid

USD 122,000 - 157,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Hybrid work
Health, dental and vision benefits
401(k) match
Employee stock purchase plan
Paid time off
Tuition assistance
Volunteer opportunities

Job summary

Cboe Global Markets is seeking a senior security professional to lead the Vulnerability Management program in a hybrid Chicago-based role. You will manage risk across global IT infrastructure, drive automation, and mentor junior staff.

The ideal candidate has 5+ years in security (or 3+ years plus core IT experience), hands-on tool experience (Qualys, Tenable, Rapid7, Wiz), and strong Python skills. The role supports a 4-day in-office model in Chicago with on-call flexibility.

Qualifications

  • Senior-level information security experience; 5+ years, or 3+ years with core IT roles.
  • Hands-on vulnerability management with cloud/SaaS tooling.
  • Strong Python scripting to automate security operations.
  • Excellent written and spoken English communication.
  • Mentor junior staff and participate in 24/7 on-call rotation.

Responsibilities

  • Reduce risk to Cboe’s global IT infrastructure through vulnerability management.
  • Analyze scan results and coordinate remediation with global teams.
  • Act as senior escalation point for vulnerability tickets and guidance on risk.
  • Design, operate, and maintain vulnerability scanning infrastructure.
  • Drive automation to improve detection, remediation tracking, and reporting.
  • Integrate data from multiple security tools for analysis and response.
  • Partner with cross-functional teams to improve remediation and controls.
  • Evaluate new vulnerabilities and technologies for relevance and impact.
  • Lead security discussions and present risks to management and executives.
  • Mentor staff and document standards and procedures.

Skills

Vulnerability management
Cloud/SaaS security
Python
AI tooling
Security scripting
Jira/Confluence
Power BI

Education

Bachelor's degree in Cybersecurity

Tools

Qualys
Tenable
Rapid7
Wiz
Reco
Obsidian
AppOmni
Aqua

Job description

Job Description

Building trusted markets — powered by our people At Cboe Global Markets, we inspire our people to solve complex challenges together because what we do matters. We provide the financial infrastructure that powers the global economy. As a leading provider of market infrastructure and tradable products, Cboe delivers cutting‑edge trading, clearing and investment solutions to market participants around the world. We’re building meaningful ways to support professional and personal development while strengthening the trust we’ve earned as a global market leader. Our teams are empowered to share ideas, actively pursue them and bring on a challenge. As champions of internal mobility and access to opportunity, we encourage our people to “go for it” and equip our managers with the training to coach their teams to the next level. We strive to provide employees a safe space to network, share ideas and create opportunities. To support strong partnership and team connection, this role follows a four day in office work model.

Location Overview

Cboe HQ is located in the historic Old Post Office district, it’s a landmark that blends classic architecture with modern amenities. The building features expansive spaces with high ceilings and large windows, offering an abundance of natural light and panoramic views of the city skyline and the Chicago River. With its prime location in the heart of downtown, the OPO Building provides easy access to major transportation hubs, including Union Station and multiple CTA lines, making it convenient for commuters. The building is home to a variety of amenities, including restaurants, a fitness centre, and collaborative workspaces, creating a vibrant and dynamic work environment in one of Chicago’s most iconic areas.

Responsibilities
  • Reducing risk to Cboe’s global IT infrastructure by executing and continuously improving the Vulnerability Management Program using a risk‑based vulnerability management (RBVM) approach.
  • Analyzing vulnerability scan results, assessing risk within the context of the enterprise environment, and coordinating remediation with global infrastructure and application teams.
  • Serving as a senior technical escalation point for vulnerability‑related security tickets, providing authoritative guidance on prioritization, remediation, and risk acceptance.
  • Designing, operating, and maintaining the vulnerability scanning and assessment infrastructure, ensuring comprehensive coverage, reliability, and alignment with security architecture standards.
  • Driving automation and integration efforts to improve the efficiency, scalability, and accuracy of vulnerability detection, analysis, remediation tracking, and reporting.
  • Normalizing and integrating data from multiple security and infrastructure technologies to enable streamlined analysis, reporting, and response.
  • Partnering cross‑functionally with infrastructure, application, and platform teams to ensure effective vulnerability remediation, policy compliance, and continuous improvement of security controls.
  • Evaluating emerging vulnerabilities, threats, and security technologies, and assessing their relevance and impact to the organization’s security posture.
  • Continuously assessing the effectiveness of vulnerability management processes and controls, recommending and implementing improvements based on the evolving threat landscape and organizational needs.
  • Leading vulnerability management discussions with technical stakeholders and presenting risk, trends, and escalation items to management and executive audiences.
  • Acting as a senior technical leader within the security team by mentoring and coaching junior staff, documenting standards and procedures, and sharing deep technical and organizational knowledge.
Ideal Candidate
  • Senior‑level experience in information security, with a minimum of 5 years in security, or 3 years in security plus 2–3 years in core IT roles such as system or network administration, and a strong emphasis on engineering and operational security.
  • Hands‑on expert level experience with vulnerability management and cloud/SaaS security tooling, including platforms such as Qualys, Tenable, Rapid7, Wiz, Reco, Obsidian, AppOmni, and Aqua, with the ability to install, configure, and operate platforms of this type in an enterprise environment.
  • Strong, practically‑used scripting and automation skills, using Python to automate security operations, integrate tools, and perform data analysis.
  • Advanced AI usage skills to supercharge productivity including chatbots such as Copilot or ChatGPT, but also demonstrated success with code and workflow creation tooling like Claude Code, Cursor, N8N Solid systems and identity administration background, including Linux/Unix and Windows environments, Active Directory, and Entra ID, as well as experience with managed network devices.
  • Familiarity with the Microsoft Security stack, including Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, Purview DLP, and Intune.
  • Deep understanding of security vulnerabilities, threats, and attack techniques, with at least 2 years of experience in vulnerability monitoring, threat detection, event monitoring, or incident response.
  • Experience using Atlassian Jira and Confluence, including workflow design and automation, to track vulnerabilities, remediation efforts, and security initiatives.
  • Experience creating reporting visualizations using tools such as Power BI, Sigma, Snowflake.
  • Strong English communication skills, with the ability to clearly and professionally convey technical risk, remediation guidance, and impact analysis to both technical teams and key stakeholders.
  • Demonstrated ability and willingness to mentor junior team members, sharing technical expertise, operational knowledge, and best practices.
  • Availability to participate in a 24/7 on‑call rotation and periodic flexibility in working hours to accommodate collaboration with a global team.
You’ll really stand out with
  • Bachelor's degree in Cybersecurity, Computer Science, Engineering or other technical field.
  • Centralized System Administration experience in Windows, Linux, Network or Firewall management.
  • Proven ability to script and automate tasks.
  • Information security certifications such as GPEN, Security+, CISSP, OSCP, CEH, LPT.
  • Experience writing and leveraging AI tooling to solve problems creatively and efficiently.
Benefits and Perks of working for Cboe Global Markets
  • We value the total wellbeing of our people – including health, financial, personal and social wellness.
  • We believe standard benefits like health insurance and fair pay are a given at any organization. Still, you should know we offer: Fair and competitive salary and incentive compensation packages with an upside for overachievement.
  • Generous paid time off, including vacation, personal days, sick days and annual community service days.
  • Flexible, hybrid work environment.
  • Health, dental and vision benefits, including access to telemedicine and mental health services 2:1 401(k) match, up to 8% match immediately upon hire.
  • Discounted Employee Stock Purchase Plan.
  • Tax Savings Accounts for health, dependent and transportation.
  • Employee referral bonus program.
  • Volunteer opportunities to help you give back to your communities.
  • Some of our associates’ favorite benefits and perks include: Complimentary lunch, snacks and coffee in any Cboe office.
  • Paid Tuition assistance and education opportunities.
  • Generous charitable giving company match.
  • Paid parental leave and fertility benefits.
  • On‑site gyms and discounts to other fitness centers.
  • Paid Time Off.
More About Cboe Global Markets

We’re reimagining the future of the workplace by focusing on what matters most, our people. Our journey is an inclusive one. We’re investing deeply in leadership programs and career development initiatives that ensure everyone has an equal chance to succeed. We work with purpose, solving problems with ingenuity, collaboration, and a lot of passion. We’re an engaged and excited team connecting markets across borders and embracing growth in all its forms to achieve incredible outcomes. Learn more about life at Cboe on our website and LinkedIn.

Equal Employment Opportunity

We’re proud to be an equal opportunity employer do not discriminate against any employee or applicant for employment based on any legally protected characteristic, including race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, or Veteran status. We are committed to fostering a workplace where all individuals are valued and respected. Cboe Global Markets is an Equal Opportunity Employer. For more information, please click the following links: Equal Employment Opportunity is The Law (in English) Equal Employment Opportunity is The Law (in Spanish) Equal Employment Opportunity is The Law (Supplement) E-Verify Participation Poster (English & Spanish) Right to Work Poster (English) Right to Work Poster (Spanish)

Contact

If you have further questions, please reach out to the Cboe HR team at cboehr@cboe.com

Salary Ranges (applicable for US locations only)

At Cboe, we are committed to providing a competitive, transparent, and market‑informed total rewards program. The anticipated base salary range for this role is $121,550-$157,300, with actual compensation determined by job‑related factors such as skills, relevant experience, education, internal alignment, and location. This role may also be eligible for annual incentive compensation and, where applicable, participation in Cboe's long‑term equity programs. Additional information about Cboe's total rewards program, including benefits and other compensation components, can be found here: Total Rewards at CBOE.

#LI-CP1

#LI-CP1

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Information Security Engineer (Systems Engineer)
Sr. Information Security Engineer (Systems Engineer)

Cedar Cares, Inc • Overland Park (KS)

On-site
USD 119,000 - 154,000
Health, dental, vision benefits
2:1 401(k) match up to 8%
Employee stock purchase plan
+3
Senior Engineer - Threat Hunting
Senior Engineer - Threat Hunting

Cedar Cares, Inc • Chicago (IL)

On-site
USD 131,000 - 169,000
Salary & incentives
Paid time off
Health benefits
+1
Software Engineer
Software Engineer

Cedar Cares, Inc • Chicago (IL)

On-site
USD 108,000 - 139,000
Health insurance
401(k) match
Tuition assistance
+1
Sr. Detection Engineer
Sr. Detection Engineer

Cedar Cares, Inc • Chicago (IL)

Hybrid
USD 131,000 - 169,000
Hybrid work environment
Health, dental and vision benefits
401(k) match
+1
Sr IT Financial Analyst
Sr IT Financial Analyst

Cedar Cares, Inc • Chicago (IL)

On-site
USD 103,000 - 133,000
Health insurance
401(k) match
Tuition assistance
+1
Third-Party Cyber Risk Specialist
Third-Party Cyber Risk Specialist

Cedar Cares, Inc • Chicago (IL)

Hybrid
USD 77,000 - 109,000
Health benefits
401(k) match
Paid time off
Principal Software Engineer
Principal Software Engineer

Cedar Cares, Inc • Chicago (IL)

On-site
USD 182,000 - 236,000
Health benefits
Generous PTO
401(k) matching
Principal Software Engineer at Cboe Global Markets
Principal Software Engineer at Cboe Global Markets

Cboe Global Markets • Chicago (IL)

On-site
USD 182,000 - 236,000
Sr Specialist, Marketing
Sr Specialist, Marketing

Cboe Global Markets • Chicago (IL)

Hybrid
USD 98,000 - 127,000
Flexible, hybrid work environment
Health, dental and vision benefits
401(k) match
+4
Sr Info Security Engineer
Sr Info Security Engineer

Cedar Cares, Inc • Overland Park (KS)

On-site
USD 92,000 - 154,000