Third-Party Cyber Risk Specialist

Jobtailor

Illinois

On-site

USD 85,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor in Illinois is seeking a seasoned professional to lead third-party risk management, vendor risk assessments, and client due diligence responses. The role requires coordinating across security, legal, and IT teams to validate questionnaires and maintain a library of standardized responses.

You'll apply cybersecurity knowledge, assess regulatory requirements such as NIST, SOC 2, GDPR, and ISO 27001, and drive remediation plans to strengthen vendor controls.

Qualifications

  • Bachelor’s Degree or equivalent work experience in a relevant field.
  • 3+ years’ experience in third-party risk management, vendor management, security incident response, cyber management or comparable field required.
  • Strong understanding of cybersecurity principles, including application security, access control, and incident response.
  • Knowledge of compliance and regulatory frameworks (e.g., NIST, SOC 2, GDPR, ISO 27001).
  • Excellent communication and interpersonal skills, with the ability to collaborate effectively with cross-function teams.
  • Ability to work independently and manage multiple assignments/projects simultaneously.
  • Experience conducting vendor risk assessments.
  • Experience with third party/vendor risk management platforms is a plus.

Responsibilities

  • Manage incoming client requests (assessments, questionnaires, etc.), prioritize and triage to appropriate teams, and validate non-disclosure agreements.
  • Facilitate communication between business, legal, technology, and information security teams to validate questionnaire responses and fulfill general requests related to controls defined by Cboe’s standards and policies.
  • Serve as a point of contact for internal stakeholders for client due diligence inquiries, ensuring timely and accurate responses.
  • Function as the subject matter expert for the response management software used for managing and responding precisely and quickly to client due diligence questionnaires.
  • Manage and maintain a standardized library of responses for client due diligence questionnaires, ensuring accuracy and consistency.
  • Collaborate with internal experts to update and refine responses as needed.
  • Assist team with onboarding new vendor relationships.
  • Collect, review, and process information and documentation from third party vendors/suppliers.
  • Conduct third-party risk assessments and due diligence reviews.
  • Analyze security information to identify significant control or security gaps and report findings to senior team members.
  • Perform comprehensive security reviews of potential and existing third-party vendors using questionnaires and security tools to evaluate their cybersecurity controls and identify potential risks.
  • Analyze identified risks from third parties and prioritize them based on their potential impact and likelihood of occurrence; create remediation plans accordingly.
  • Continuously monitor third-party vendors' security posture through regular assessments, vulnerability scans, and incident reporting to maintain a consistent level of security.
  • Coordinate with internal security team to respond to cyber incidents involving third-party vendors, providing necessary support for investigation and remediation.
  • Assist with regulatory exams by obtaining documentation and drafting responses to regulator inquiries.
  • Perform additional activities as needed.

Skills

Third-Party Risk Management
Vendor Management
Cybersecurity Principles
Compliance Frameworks
Security Incident Response

Education

Bachelor’s Degree or equivalent work experience

Tools

Response Management Software
Vendor Risk Management Platforms
Security Tools

Job description

  • Manage incoming client requests (such as assessments, questionnaires, etc.), prioritize and triage requests to appropriate teams, and validate non-disclosure agreements
  • Facilitate communication between business, legal, technology, and information security teams to validate questionnaire responses and fulfill general requests related to controls defined by Cboe’s standards and policies
  • Serve as a point of contact for internal stakeholders for client due diligence inquiries, ensuring timely and accurate responses
  • Function as the subject matter expert for the response management software used for managing and responding precisely and quickly to client due diligence questionnaires
  • Manage and maintain a standardized library of responses for client due diligence questionnaires, ensuring accuracy and consistency
  • Collaborate with internal experts to update and refine responses as needed
  • Assist team with onboarding new vendor relationships
  • Collect, review, and process information and documentation from third party vendors/suppliers
  • Conduct third-party risk assessments and due diligence reviews
  • Analyze security information to identify significant control or security gaps and report findings to senior team members
  • Perform comprehensive security reviews of potential and existing third-party vendors using questionnaires and security tools to evaluate their cybersecurity controls and identify potential risks
  • Analyze identified risks from third parties and prioritize them based on their potential impact and likelihood of occurrence; create remediation plans accordingly
  • Continuously monitor third-party vendors' security posture through regular assessments, vulnerability scans, and incident reporting to maintain a consistent level of security
  • Coordinate with internal security team to respond to cyber incidents involving third-party vendors, providing necessary support for investigation and remediation
  • Assist with regulatory exams by obtaining documentation and drafting responses to regulator inquiries
  • Perform additional activities as needed
Requirements
  • Bachelor’s Degree or equivalent work experience in a relevant field
  • 3+ years’ experience in third-party risk management, vendor management, security incident response, cyber management or comparable field required
  • Strong understanding of cybersecurity principles, including application security, access control, and incident response
  • Knowledge of compliance and regulatory frameworks (e.g., NIST, SOC 2, GDPR, ISO 27001)
  • Excellent communication and interpersonal skills, with the ability to collaborate effectively with cross-function teams
  • Ability to work independently and manage multiple assignments/projects simultaneously
  • Experience conducting vendor risk assessments
  • Experience with third party/vendor risk management platforms is a plus
Core Competencies

Demonstrates expertise in third-party risk management and vendor management, with a strong understanding of cybersecurity principles and compliance frameworks. Capable of effectively communicating and collaborating with cross-functional teams to ensure timely and accurate responses to client inquiries.

Highest-signal resume keywords
  • Third-Party Risk Management
  • Vendor Management
  • Cybersecurity Principles
  • Compliance Frameworks
  • Security Incident Response
ATS Optimization Keywords
Hard Skills
  • Risk Assessment
  • Vendor Risk Assessment
  • Security Review
  • Incident Response
  • Application Security
  • Access Control
  • Remediation Planning
  • Vulnerability Scanning
  • Documentation Review
  • Response Management Software
Soft Skills
  • Excellent Communication
  • Interpersonal Skills
  • Collaboration
  • Independent Work
  • Project Management
Industry Keywords
  • NIST
  • SOC 2
  • GDPR
  • ISO 27001
Tools & Technologies
  • Third-Party Risk Management Platforms
  • Security Tools
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Third Party Risk Analyst
Third Party Risk Analyst

Jobtailor • City of Norwich (NY)

On-site
USD 70,000 - 100,000
Service Provider Oversight Analyst
Service Provider Oversight Analyst

Jobtailor • Missouri

On-site
USD 105,000 - 145,000
Risk Management Analyst
Risk Management Analyst

Jobtailor • Atlanta (TX)

On-site
USD 90,000 - 130,000
Director, Third-Party Risk Management – Technical Information Security Lead
Director, Third-Party Risk Management – Technical Information Security Lead

Jobtailor • New York (NY)

On-site
USD 180,000 - 240,000
Third Party Risk Analyst
Third Party Risk Analyst

Addison Group • Chicago (IL)

On-site
USD 70,000 - 90,000
Third-Party Risk Management Specialist
Third-Party Risk Management Specialist

Cboe Global Markets • Overland Park (KS)

Hybrid
USD 76,500 - 108,900
Health insurance
401(k) match
Tuition assistance
+2
Senior Third Party Cybersecurity GRC Analyst
Senior Third Party Cybersecurity GRC Analyst

Jobtailor • Indianapolis (IN)

On-site
USD 95,000 - 130,000
Tech Risk – Third Party Risk Management
Tech Risk – Third Party Risk Management

Jobtailor • North Carolina

On-site
USD 150,000 - 190,000
(On-site) Information Security Vendor Management Analyst
(On-site) Information Security Vendor Management Analyst

Centreville Bank • Warwick (RI)

On-site
USD 70,000 - 90,000
Third Party Cyber Security Assessor
Third Party Cyber Security Assessor

Jobtailor • Colorado

On-site
USD 90,000 - 130,000