Hightower
Cybersecurity Associate
Chicago, Illinois · Posted today
Opens jobs.dayforcehcm.com
Get a version of your resume written for this job.
- Salary
- Not listed
- Job type
- Not specified
- Work mode
- Not specified
- Source
- Dayforce (employer's hiring system)
Skills mentioned
Cybersecurity, Swift, SOC 2, ISO 27001, Penetration Testing, Incident Response, Project Management
About the role
Our Story
Founded in 2008, Hightower is a wealth management firm that provides investment, financial and retirement planning services to individuals, foundations and family offices, as well as 401(k) consulting and cash management services to corporations. Hightower’s capital solutions, operational support services, size and scale empower its vibrant community of independent-minded wealth advisors to grow their businesses and help their clients achieve their financial vision. Based in Chicago with advisors across the U.S., we operate as a registered investment advisor (RIA).
Your Future Team
Hightower’s Cybersecurity team delivers exceptional service by securing the company’s information assets, developing and implementing robust security procedures, and ensuring compliance with industry regulations. You will collaborate with cross-functional teams, managed service providers, vendors, and business stakeholders to protect the organization's information assets and strengthen its overall security posture. Responsibilities include supporting security investigations, conducting cybersecurity and vendor risk assessments, maintaining the cybersecurity risk register, tracking remediation activities, assisting with audits and compliance initiatives, and preparing risk and security reporting for management.
Additionally, you will participate in security reviews of new technologies, applications, and business initiatives, support security awareness efforts, and help ensure the effective implementation and maintenance of cybersecurity governance, risk, and compliance programs. This position involves regular interaction with internal stakeholders and external partners to promote a strong culture of cybersecurity risk management across the organization.
What You’ll Do
Cybersecurity Risk Management
Conduct cybersecurity risk assessments to identify and evaluate risks to the organization's information assets and business operations, document assessment results, and track risk mitigation efforts through remediation or formal risk acceptance.
Monitor remediation activities and collaborate with stakeholders to ensure timely mitigation of identified risks.
Assist with risk exception and risk acceptance processes, including documentation and management approvals.
Monitor cybersecurity risk metrics and key performance indicators and prepare reports for management and leadership.
Collaborate with cross-functional teams to promote effective cybersecurity risk management practices across the organization.
Participate in security reviews for new technologies, applications, cloud services, and business initiatives to identify and mitigate potential risks.
Third-Party Risk Management
Conduct third-party and vendor cybersecurity risk assessments to evaluate security controls and identify potential risks to the organization.
Support vendor due diligence, onboarding reviews, periodic reassessments, and ongoing risk monitoring activities.
Evaluate vendor security documentation, including SOC reports, security questionnaires, penetration testing results, and other assurance artifacts.
Work with internal stakeholders and external vendors to track remediation of identified security gaps and risks.
Liaise with managed services providers, cloud vendors, and third parties to ensure their security practices align with the company's cybersecurity and risk management objectives.
Governance, Risk, and Compliance (GRC)
Assist with the development, implementation, and maintenance of cybersecurity policies, standards, procedures, and governance initiatives.
Support internal and external audits by collecting evidence, coordinating stakeholder responses, and tracking corrective actions to completion.
Help ensure compliance with applicable regulatory requirements, industry standards, and cybersecurity frameworks.
Prepare reports, dashboards, and presentations for leadership on cybersecurity risk, compliance, and third-party risk activities.
Investigations and Reporting
Conduct thorough investigations of suspicious activities that pose risks to the organization's information assets, collaborating with relevant teams and providing detailed reports to safeguard the company's security infrastructure.
Security Incident Response
Ensure the protection of critical systems and data by coordinating efforts to contain, mitigate, and resolve threats effectively.
Investigate security alerts and incidents that may impact the company's security landscape.
Escalate issues to senior team members, when necessary, to ensure swift action and containment.
Security Technology Management
Support the deployment, configuration, and maintenance of security tools and technologies across the organization, ensuring all systems align with established security protocols to protect the company's digital assets.
Security Awareness and Training
Support security awareness training efforts to educate employees on cybersecurity best practices and promote a strong security culture across the organization.
What You’ll Bring
Bachelor’s degree and Security+ or related certification
1-2 years of experience in cybersecurity risk management, third-party risk management, security operations, or a related cybersecurity function.
Ability to stay informed on emerging cybersecurity trends and threats to bolster the company’s security posture.
Ability to collect, analyze, and interpret security, risk, and compliance data to support decision-making and risk management activities.
Strong interpersonal and communications (written and oral)
Self-motivated individual who can operate with minimal supervision,
Ability to think critically to effectively address and resolve IT security issues as they arise.
Prefferred
Strong organizational and project management skills with the ability to track multiple risk, remediation, and compliance initiatives simultaneously.
Experience in financial services, wealth management, or other regulated industries.
Knowledge of cybersecurity frameworks, standards, and regulatory requirements, including NIST Cybersecurity Framework (CSF), NIST 800-53, CIS Controls, ISO 27001, SOC 2, Gramm-Leach-Bliley Act (GLBA), SEC and FINRA regulations, and other applicable privacy and information security requirements.
What We Offer
Coverage on the first day of employment for medical, dental, and vision insurance
Paid parental leave (16 weeks for primary caregiver and 8 weeks for secondary caregiver)
Mother’s lounge onsite
Flexible PTO plan
In-office Monday through Thursday and work from home on Fridays
Free brand-new gym in the Chicago office
401k matching plan
HSA employer contributions
Student loan assistance
Pet insurance
Base salary of $70,000-$80,000 plus discretionary bonus (exact base salary amount will be dependent on experience)
AN EQUAL OPPORTUNITY EMPLOYER: Hightower is an equal opportunity employer and does not discriminate based upon race, color, religion, sex, sexual orientation, pregnancy, marital status, national origin, citizenship, veteran status, ancestry, age (over 40), physical or mental disability, medical condition (cancer-related), gender identity or expression, genetic information including sickle cell or hemoglobin C trait, or any other consideration made unlawful by applicable federal, state, or local law.
You are a U.S. citizen, U.S. permanent resident or possess other unrestricted U.S. work authorization and will not require sponsorship for U.S. work authorization now or anytime in the future.
Job ID df-hightower-candidateportal-8949 · Original posting ↗
Similar jobs
Principal Product Cybersecurity Assurance EngineerNewHumanoidCambridge, Massachusetts · On-site
Director, Cybersecurity – Engineering, Operations and Incident ResponseNewUW HealthMadison, Wisconsin · Hybrid
Senior Manager, Cybersecurity Risk ManagementNewAmerican ExpressPhoenix, Arizona · Hybrid
- Associate Director, Cybersecurity, Privacy & ITNewDr. SquatchMarina Del Rey, California
- Cybersecurity AnalystNewSan Francisco, California