Hightower

Cybersecurity Associate

Chicago, Illinois · Posted today

Opens jobs.dayforcehcm.com

Get a version of your resume written for this job.

Salary
Not listed
Job type
Not specified
Work mode
Not specified
Source
Dayforce (employer's hiring system)

Skills mentioned

Cybersecurity, Swift, SOC 2, ISO 27001, Penetration Testing, Incident Response, Project Management

About the role

Our Story

Founded in 2008, Hightower is a wealth management firm that provides investment, financial and retirement planning services to individuals, foundations and family offices, as well as 401(k) consulting and cash management services to corporations. Hightower’s capital solutions, operational support services, size and scale empower its vibrant community of independent-minded wealth advisors to grow their businesses and help their clients achieve their financial vision. Based in Chicago with advisors across the U.S., we operate as a registered investment advisor (RIA).

Your Future Team

Hightower’s Cybersecurity team delivers exceptional service by securing the company’s information assets, developing and implementing robust security procedures, and ensuring compliance with industry regulations. You will collaborate with cross-functional teams, managed service providers, vendors, and business stakeholders to protect the organization's information assets and strengthen its overall security posture. Responsibilities include supporting security investigations, conducting cybersecurity and vendor risk assessments, maintaining the cybersecurity risk register, tracking remediation activities, assisting with audits and compliance initiatives, and preparing risk and security reporting for management.

Additionally, you will participate in security reviews of new technologies, applications, and business initiatives, support security awareness efforts, and help ensure the effective implementation and maintenance of cybersecurity governance, risk, and compliance programs. This position involves regular interaction with internal stakeholders and external partners to promote a strong culture of cybersecurity risk management across the organization.

What You’ll Do

Cybersecurity Risk Management

Conduct cybersecurity risk assessments to identify and evaluate risks to the organization's information assets and business operations, document assessment results, and track risk mitigation efforts through remediation or formal risk acceptance.

Monitor remediation activities and collaborate with stakeholders to ensure timely mitigation of identified risks.

Assist with risk exception and risk acceptance processes, including documentation and management approvals.

Monitor cybersecurity risk metrics and key performance indicators and prepare reports for management and leadership.

Collaborate with cross-functional teams to promote effective cybersecurity risk management practices across the organization.

Participate in security reviews for new technologies, applications, cloud services, and business initiatives to identify and mitigate potential risks.

Third-Party Risk Management

Conduct third-party and vendor cybersecurity risk assessments to evaluate security controls and identify potential risks to the organization.

Support vendor due diligence, onboarding reviews, periodic reassessments, and ongoing risk monitoring activities.

Evaluate vendor security documentation, including SOC reports, security questionnaires, penetration testing results, and other assurance artifacts.

Work with internal stakeholders and external vendors to track remediation of identified security gaps and risks.

Liaise with managed services providers, cloud vendors, and third parties to ensure their security practices align with the company's cybersecurity and risk management objectives.

Governance, Risk, and Compliance (GRC)

Assist with the development, implementation, and maintenance of cybersecurity policies, standards, procedures, and governance initiatives.

Support internal and external audits by collecting evidence, coordinating stakeholder responses, and tracking corrective actions to completion.

Help ensure compliance with applicable regulatory requirements, industry standards, and cybersecurity frameworks.

Prepare reports, dashboards, and presentations for leadership on cybersecurity risk, compliance, and third-party risk activities.

Investigations and Reporting

Conduct thorough investigations of suspicious activities that pose risks to the organization's information assets, collaborating with relevant teams and providing detailed reports to safeguard the company's security infrastructure.

Security Incident Response

Ensure the protection of critical systems and data by coordinating efforts to contain, mitigate, and resolve threats effectively.

Investigate security alerts and incidents that may impact the company's security landscape.

Escalate issues to senior team members, when necessary, to ensure swift action and containment.

Security Technology Management

Support the deployment, configuration, and maintenance of security tools and technologies across the organization, ensuring all systems align with established security protocols to protect the company's digital assets.

Security Awareness and Training

Support security awareness training efforts to educate employees on cybersecurity best practices and promote a strong security culture across the organization.

What You’ll Bring

Bachelor’s degree and Security+ or related certification

1-2 years of experience in cybersecurity risk management, third-party risk management, security operations, or a related cybersecurity function.

Ability to stay informed on emerging cybersecurity trends and threats to bolster the company’s security posture.

Ability to collect, analyze, and interpret security, risk, and compliance data to support decision-making and risk management activities.

Strong interpersonal and communications (written and oral)

Self-motivated individual who can operate with minimal supervision,

Ability to think critically to effectively address and resolve IT security issues as they arise.

Prefferred

Strong organizational and project management skills with the ability to track multiple risk, remediation, and compliance initiatives simultaneously.

Experience in financial services, wealth management, or other regulated industries.

Knowledge of cybersecurity frameworks, standards, and regulatory requirements, including NIST Cybersecurity Framework (CSF), NIST 800-53, CIS Controls, ISO 27001, SOC 2, Gramm-Leach-Bliley Act (GLBA), SEC and FINRA regulations, and other applicable privacy and information security requirements.

What We Offer

Coverage on the first day of employment for medical, dental, and vision insurance

Paid parental leave (16 weeks for primary caregiver and 8 weeks for secondary caregiver)

Mother’s lounge onsite

Flexible PTO plan

In-office Monday through Thursday and work from home on Fridays

Free brand-new gym in the Chicago office

401k matching plan

HSA employer contributions

Student loan assistance

Pet insurance

Base salary of $70,000-$80,000 plus discretionary bonus (exact base salary amount will be dependent on experience)

AN EQUAL OPPORTUNITY EMPLOYER: Hightower is an equal opportunity employer and does not discriminate based upon race, color, religion, sex, sexual orientation, pregnancy, marital status, national origin, citizenship, veteran status, ancestry, age (over 40), physical or mental disability, medical condition (cancer-related), gender identity or expression, genetic information including sickle cell or hemoglobin C trait, or any other consideration made unlawful by applicable federal, state, or local law.

You are a U.S. citizen, U.S. permanent resident or possess other unrestricted U.S. work authorization and will not require sponsorship for U.S. work authorization now or anytime in the future.

Job ID df-hightower-candidateportal-8949 · Original posting ↗