CybersecurityJobs.io
← Back to all jobs

Job Description

HighTower Advisors offers a hybrid work model in Chicago with a strong focus on protecting information assets, strengthening security procedures, and supporting compliance in a regulated wealth environment. You will join a cybersecurity team responsible for investigations, risk management, incident response support, third-party risk oversight, and governance activities.

In this role, you will help assess and manage cybersecurity risk across internal systems and vendors, track remediation to completion, and support reporting for management and leadership. The position also emphasizes security awareness efforts to build and maintain a durable security culture.

Responsibilities

  • Conduct cybersecurity risk assessments to identify and evaluate risks to information assets and business operations, documenting results and tracking mitigation through remediation or formal risk acceptance.
  • Monitor remediation activities and collaborate with stakeholders to support timely mitigation of identified risks.
  • Assist with risk exception and risk acceptance processes, including documentation and management approvals.
  • Monitor cybersecurity risk metrics and key performance indicators, and prepare reports for management and leadership.
  • Collaborate with cross-functional teams to promote effective cybersecurity risk management practices across the organization.
  • Participate in security reviews for new technologies, applications, cloud services, and business initiatives to identify and mitigate potential risks.
  • Perform third-party and vendor cybersecurity risk assessments to evaluate security controls and identify potential organizational risks.
  • Support vendor due diligence, onboarding reviews, periodic reassessments, and ongoing risk monitoring activities.
  • Evaluate vendor security documentation, including SOC reports, security questionnaires, penetration testing results, and other assurance artifacts.
  • Work with internal stakeholders and external vendors to track remediation of identified security gaps and risks.
  • Liaise with managed services providers, cloud vendors, and third parties to ensure alignment with cybersecurity and risk management objectives.
  • Assist with development, implementation, and maintenance of cybersecurity policies, standards, procedures, and governance initiatives.
  • Support internal and external audits by collecting evidence, coordinating stakeholder responses, and tracking corrective actions to completion.
  • Help ensure compliance with applicable regulatory requirements, industry standards, and cybersecurity frameworks.
  • Prepare reports, dashboards, and presentations for leadership on cybersecurity risk, compliance, and third-party risk activities.
  • Conduct investigations of suspicious activities that may impact the organization’s information assets, collaborating with relevant teams and producing detailed reports.
  • Support containment, mitigation, and resolution efforts to protect critical systems and data.
  • Investigate security alerts and incidents and escalate issues to senior team members when necessary for swift action and containment.
  • Support deployment, configuration, and maintenance of security tools and technologies to ensure alignment with established security protocols.
  • Support security awareness training efforts to educate employees on cybersecurity best practices and strengthen security culture.

Requirements

  • Bachelor’s degree and Security+ or related certification.
  • 1 to 2 years of experience in cybersecurity risk management, third-party risk management, security operations, or a related cybersecurity function.
  • Ability to stay informed on emerging cybersecurity trends and threats to bolster the company’s security posture.
  • Ability to collect, analyze, and interpret security, risk, and compliance data to support decision-making and risk management activities.
  • Strong interpersonal and communication skills (written and oral).
  • Self-motivated individual who can operate with minimal supervision.
  • Ability to think critically to address and resolve IT security issues as they arise.

Technologies and Frameworks

  • Security+
  • NIST Cybersecurity Framework (CSF)
  • NIST 800-53
  • CIS Controls
  • ISO 27001
  • SOC 2
  • Gramm-Leach-Bliley Act (GLBA)
  • SEC and FINRA regulations

Benefits

  • Coverage on the first day of employment for medical, dental, and vision insurance
  • Paid parental leave: 16 weeks for primary caregiver and 8 weeks for secondary caregiver
  • Mother’s lounge onsite
  • Flexible PTO plan
  • In-office Monday through Thursday and work from home on Fridays
  • Free brand-new gym in the Chicago office
  • 401k matching plan
  • HSA employer contributions
  • Student loan assistance
  • Pet insurance
  • Base salary of $70,000-$80,000 plus discretionary bonus (exact base salary dependent on experience)

What You’ll Do

  • Security Incident Response
  • Security Technology Management
  • Security Awareness and Training

Preferred

  • Strong organizational and project management skills with the ability to track multiple risk, remediation, and compliance initiatives simultaneously.
  • Experience in financial services, wealth management, or other regulated industries.
  • Knowledge of cybersecurity frameworks, standards, and regulatory requirements, including NIST Cybersecurity Framework (CSF), NIST 800-53, CIS Controls, ISO 27001, SOC 2, Gramm-Leach-Bliley Act (GLBA), SEC and FINRA regulations, and other applicable privacy and information security requirements.

Company Overview

HighTower Advisors was founded in 2008 and is a wealth management firm providing investment, financial and retirement planning services to individuals, foundations and family offices, along with 401(k) consulting and cash management services to corporations.

Based in Chicago with advisors across the U.S., HighTower operates as a registered investment advisor (RIA). The cybersecurity team secures the company’s information assets, develops and implements robust security procedures, and ensures compliance with industry regulations. The team partners with cross-functional groups, managed services providers, vendors, and business stakeholders to protect information assets and strengthen overall security posture, supporting investigations, risk assessments, remediation tracking, audit and compliance initiatives, and leadership reporting.

Similar Jobs