Security Specialist
Confirmed live in the last 24 hours
Focus Financial Partners
Job Description
Role Overview
This Security Specialist role will serve as a lead for cybersecurity awareness & training program responsible for the execution and continuous improvement of the firm’s cybersecurity awareness and training program across all Focus firms. This role serves as the primary owner for delivering engaging, effective, and risk‑based cybersecurity training to employees at all levels of the organization.
Reporting to the Head of Cybersecurity Governance, this individual‑contributor role works in close partnership with Legal, Privacy, Regulatory Compliance, HR, IT, and Security teams to ensure training content aligns with regulatory requirements, internal policies, and evolving cyber threats. The role plays a critical part in strengthening the firm’s security culture and reducing human‑driven cyber risk.
This role is hybrid with 3 days per week onsite in our St. Louis office
Key Responsibilities
Cybersecurity Awareness & Training Program Delivery
- Execute the firm‑wide cybersecurity awareness and training program across all Focus firms.
- Deliver mandatory annual security training, role‑based training, and targeted campaigns addressing key cyber risks (e.g., phishing, social engineering, data protection).
- Manage and execute phishing simulation programs, including campaign design, delivery, analysis, and follow‑up education.
- Coordinate training rollouts, schedules, and communications to ensure consistent adoption across diverse business units.
Content Development & Continuous Improvement
- Develop, maintain, and refresh cybersecurity training content to ensure relevance, clarity, and engagement.
- Tailor training materials for different audiences, including employees, advisors, leadership, and specialized roles.
- Incorporate lessons learned from incidents, phishing results, regulatory feedback, and emerging threat trends into training content.
- Balance regulatory requirements with practical, user‑friendly messaging that supports business productivity.
Regulatory, Legal & Compliance Partnership
- Work closely with Legal, Privacy, and Regulatory Compliance teams to ensure training content aligns with applicable laws, regulations, and contractual obligations.
- Support regulatory examinations, audits, and client due diligence efforts by providing training materials, metrics, and evidence.
- Maintain documentation demonstrating compliance with cybersecurity training and awareness requirements.
- Monitor regulatory expectations related to security awareness and adjust training accordingly.
Measurement, Reporting & Risk Reduction
- Define and track key training and awareness metrics (e.g., completion rates, phishing susceptibility, behavioral improvements).
- Analyze trends and results to identify risk areas and inform targeted training initiatives.
- Provide regular reporting and insights to the Head of Cybersecurity Governance and other stakeholders.
- Demonstrate the effectiveness of training programs in reducing human‑driven cyber risk.
Cross‑Functional Collaboration
- Partner closely with Cybersecurity Risk, Engineering, and Operations teams to align training with real‑world threats and controls.
- Coordinate with HR and Communications teams to support onboarding, policy acknowledgment, and change‑management initiatives.
- Serve as a trusted advisor to business teams on security awareness best practices.
Qualifications & Experience
- 5–8+ years of experience in cybersecurity awareness, training, GRC, or related security roles.
- Hands‑on experience delivering cybersecurity training programs in a regulated or complex environment.
- Strong understanding of common cybersecurity risks, user behavior factors, and awareness best practices.
- Experience partnering with Legal, Privacy, and Compliance teams on regulatory or audit‑driven initiatives.
- Excellent communication and content‑development skills, with the ability to explain security concepts to non‑technical audiences.
- Highly organized and self‑directed, with the ability to manage multiple initiatives across a distributed organization.
Preferred Qualifications
- Experience in financial services or similarly regulated industries.
- Familiarity with cybersecurity frameworks and regulatory requirements (e.g., NIST CSF, NYDFS, GLBA).
- Experience with phishing simulation and training platforms.
- Professional certifications such as CISSP, CISM, Security+, or relevant security awareness credentials
#LI-KJ2
This position is an exempt position. The annualized base pay range for this role is expected to be between $140,000–$160,000 base salary compensation range. Actual base pay may vary based on factors including, but not limited to, experience, subject matter expertise, geographic location where work will be performed, and the applicant’s skill set. The base pay is just one component of the total compensation package. Other rewards may include an annual cash bonus and a comprehensive benefits package, including but not limited to medical, dental, vision, life insurance, and 401(k). Please note that the job title is subject to change based on the selected candidate’s experience and education.
About Focus Financial Partners
Focus is a leading financial services firm comprised of integrated wealth management, family office, and business management services. Blending deep expertise and expansive resources with a boutique, client-first fiduciary philosophy, Focus helps individuals, families, and institutions navigate complex financial situations with highly personalized solutions tailored to their unique needs. To learn more about Focus, visit www.focusfinancialpartners.com or follow the company on LinkedIn.
Focus is an equal opportunity employer and bases its employment decisions on the employee or candidate’s skillset, and without regard to an employee or candidate’s race, color, religion, sex (including pregnancy), gender identity, sexual orientation, national origin, age, disability, genetic information, veteran status, or any other characteristic protected by local, state and/or federal law.
Focus complies with federal and state disability laws and makes reasonable accommodations for applicants and employees with disabilities. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact careers@focuspartners.com.
The following language is for US based roles only
For California Applicants: Information on your California privacy rights can be found here
For Indiana Applicants: It is unlawful for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component.
For Maryland Applicants: I UNDERSTAND THAT UNDER MARYLAND LAW, AN EMPLOYER MAY NOT REQUIRE OR DEMAND, AS A CONDITION OF EMPLOYMENT, PROSPECTIVE EMPLOYMENT OR CONTINUED EMPLOYMENT, THAT ANY INDIVIDUAL SUBMIT TO OR TAKE A POLYGRAP OR SIMILAR TEST. AN EMPLOYER WHO VIOLATES THIS LAW IS GUILTY OF A MISDEMEANOR AND SUBJECT TO A FINE NOT EXCEEDING $100.
For Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this shall be subject to criminal penalties and civil liability.
For Montana Applicants: If hired, the employment relationship is governed by the Wrongful Discharge from Employment Act. Mont. Code Ann. Section 39-2-901.
For Rhode Island Applicants: Focus is subject to Chapters 29-38 of Title 28 of the General Laws of Rhode Island and is therefore covered by the state’s workers’ compensation law. If you willfully provide false information about your ability to perform the essential functions of the job, with or without reasonable accommodations, you may be barred from filing a claim under the provisions of the Workers’ Compensation Act of the State of Rhode Island if the false information is directly related to the personal injury that is the basis for the new claim for compensation. The Company complies fully with the Americans with Disabilities Act.
Similar Jobs
Capital Rx
Benefit Configuration Specialist
Capital Rx
Benefit Operations Specialist
Scout Motors
Specialist, Learning Management System Administrator
Zscaler
Principal Specialist Sales Engineer - Data Security - Northern Europe
Zscaler
Principal Specialist Sales Engineer - Data Security - DACH
ePlus Technology