Skip to content

Open nowPosted 8 days ago

Cybersecurity Associate

Hightower65 open roles

Where
Chicago, IL, USA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowCybersecurity AssociateHightower · Chicago, IL, USA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Hightower's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 8 days ago

The posting

 Our Story Founded in 2008, Hightower is a wealth management firm that provides investment, financial and retirement planning services to individuals, foundations and family offices, as well as 401(k) consulting and cash management services to corporations. Hightower’s capital solutions, operational support services, size and scale empower its vibrant community of independent-minded wealth advisors to grow their businesses and help their clients achieve their financial vision. Based in Chicago with advisors across the U.S., we operate as a registered investment advisor (RIA).   Your Future Team Hightower’s Cybersecurity team delivers exceptional service by securing the company’s information assets, developing and implementing robust security procedures, and ensuring compliance with industry regulations. You will collaborate with cross-functional teams, managed service providers, vendors, and business stakeholders to protect the organization's information assets and strengthen its overall security posture. Responsibilities include supporting security investigations, conducting cybersecurity and vendor risk assessments, maintaining the cybersecurity risk register, tracking remediation activities, assisting with audits and compliance initiatives, and preparing risk and security reporting for management.   Additionally, you will participate in security reviews of new technologies, applications, and business initiatives, support security awareness efforts, and help ensure the effective implementation and maintenance of cybersecurity governance, risk, and compliance programs. This position involves regular interaction with internal stakeholders and external partners to promote a strong culture of cybersecurity risk management across the organization.   What You’ll Do  Cybersecurity Risk Management

Conduct cybersecurity risk assessments to identify and evaluate risks to the organization's information assets and business operations, document assessment results, and track risk mitigation efforts through remediation or formal risk acceptance. Monitor remediation activities and collaborate with stakeholders to ensure timely mitigation of identified risks. Assist with risk exception and risk acceptance processes, including documentation and management approvals. Monitor cybersecurity risk metrics and key performance indicators and prepare reports for management and leadership. Collaborate with cross-functional teams to promote effective cybersecurity risk management practices across the organization. Participate in security reviews for new technologies, applications, cloud services, and business initiatives to identify and mitigate potential risks.

Third-Party Risk Management

Conduct third-party and vendor cybersecurity risk assessments to evaluate security controls and identify potential risks to the organization. Support vendor due diligence, onboarding reviews, periodic reassessments, and ongoing risk monitoring activities. Evaluate vendor security documentation, including SOC reports, security questionnaires, penetration testing results, and other assurance artifacts. Work with internal stakeholders and external vendors to track remediation of identified security gaps and risks. Liaise with managed services providers, cloud vendors, and third parties to ensure their security practices align with the company's cybersecurity and risk management objectives.

Governance, Risk, and Compliance (GRC)

Assist with the development, implementation, and maintenance of cybersecurity policies, standards, procedures, and governance initiatives. Support internal and external audits by collecting evidence, coordinating stakeholder responses, and tracking corrective actions to completion. Help ensure compliance with applicable regulatory requirements, industry standards, and cybersecurity frameworks. Prepare reports, dashboards, and presentations for leadership on cybersecurity risk, compliance, and third-party risk activities.

Investigations and Reporting

Conduct thorough investigations of suspicious activities that pose risks to the organization's information assets, collaborating with relevant teams and providing detailed reports to safeguard the company's security infrastructure.

Security Incident Response

Ensure the protection of critical systems and data by coordinating efforts to contain, mitigate, and resolve threats effectively. Investigate security alerts and incidents that may impact the company's security landscape. Escalate issues to senior team members, when necessary, to ensure swift action and containment.

Security Technology Management

Support the deployment, configuration, and maintenance of security tools and technologies across the organization, ensuring all systems align with established security protocols to protect the company's digital assets.

Security Awareness and Training

Support security awareness training efforts to educate employees on cybersecurity best practices and promote a strong security culture across the organization.

  What You’ll Bring

Bachelor’s degree and Security+ or related certification 1-2 years of experience in cybersecurity risk management, third-party risk management, security operations, or a related cybersecurity function. Ability to stay informed on emerging cybersecurity trends and threats to bolster the company’s security posture. Ability to collect, analyze, and interpret security, risk, and compliance data to support decision-making and risk management activities. Strong interpersonal and communications (written and oral) Self-motivated individual who can operate with minimal supervision, Ability to think critically to effectively address and resolve IT security issues as they arise.

  Prefferred

Strong organizational and project management skills with the ability to track multiple risk, remediation, and compliance initiatives simultaneously. Experience in financial services, wealth management, or other regulated industries. Knowledge of cybersecurity frameworks, standards, and regulatory requirements, including NIST Cybersecurity Framework (CSF), NIST 800-53, CIS Controls, ISO 27001, SOC 2, Gramm-Leach-Bliley Act (GLBA), SEC and FINRA regulations, and other applicable privacy and information security requirements.

  What We Offer

Coverage on the first day of employment for medical, dental, and vision insurance Paid parental leave (16 weeks for primary caregiver and 8 weeks for secondary caregiver) Mother’s lounge onsite Flexible PTO plan In-office Monday through Thursday and work from home on Fridays Free brand-new gym in the Chicago office 401k matching plan HSA employer contributions Student loan assistance Pet insurance Base salary of $70,000-$80,000 plus discretionary bonus (exact base salary amount will be dependent on experience)

  AN EQUAL OPPORTUNITY EMPLOYER: Hightower is an equal opportunity employer and does not discriminate based upon race, color, religion, sex, sexual orientation, pregnancy, marital status, national origin, citizenship, veteran status, ancestry, age (over 40), physical or mental disability, medical condition (cancer-related), gender identity or expression, genetic information including sickle cell or hemoglobin C trait, or any other consideration made unlawful by applicable federal, state, or local law.   You are a U.S. citizen, U.S. permanent resident or possess other unrestricted U.S. work authorization and will not require sponsorship for U.S. work authorization now or anytime in the future.    

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Hightower's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Hightower's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Hightower's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.