Security Specialist
Saint Louis, MI - USA
Job Summary
Role Overview
ThisSecuritySpecialist role will serve as a lead for cybersecurity awareness & training program responsible for the execution and continuous improvement of the firms cybersecurity awareness and training program across all Focus firms. This role serves as the primary owner for delivering engaging effective and riskbased cybersecurity training to employees at all levels of the organization.
Reporting to the Head of Cybersecurity Governance this individualcontributor role works in close partnership with Legal Privacy Regulatory Compliance HR IT andSecurityteams to ensure training content aligns with regulatory requirements internal policies and evolving cyber threats. The role plays a critical part in strengthening the firmssecurityculture and reducing humandriven cyber risk.
This role is hybrid with 3 days per week onsite in our St. Louis office
Key Responsibilities
Cybersecurity Awareness & Training Program Delivery
- Execute the firmwide cybersecurity awareness and training program across all Focus firms.
- Deliver mandatory annualsecuritytraining rolebased training and targeted campaigns addressing key cyber risks (e.g. phishing social engineering data protection).
- Manage and execute phishing simulation programs including campaign design delivery analysis and followup education.
- Coordinate training rollouts schedules and communications to ensure consistent adoption across diverse business units.
Content Development & Continuous Improvement
- Develop maintain and refresh cybersecurity training content to ensure relevance clarity and engagement.
- Tailor training materials for different audiences including employees advisors leadership and specialized roles.
- Incorporate lessons learned from incidents phishing results regulatory feedback and emerging threat trends into training content.
- Balance regulatory requirements with practical userfriendly messaging that supports business productivity.
Regulatory Legal & Compliance Partnership
- Work closely with Legal Privacy and Regulatory Compliance teams to ensure training content aligns with applicable laws regulations and contractual obligations.
- Support regulatory examinations audits and client due diligence efforts by providing training materials metrics and evidence.
- Maintain documentation demonstrating compliance with cybersecurity training and awareness requirements.
- Monitor regulatory expectations related tosecurityawareness and adjust training accordingly.
Measurement Reporting & Risk Reduction
- Define and track key training and awareness metrics (e.g. completion rates phishing susceptibility behavioral improvements).
- Analyze trends and results to identify risk areas and inform targeted training initiatives.
- Provide regular reporting and insights to the Head of Cybersecurity Governance and other stakeholders.
- Demonstrate the effectiveness of training programs in reducing humandriven cyber risk.
CrossFunctional Collaboration
- Partner closely with Cybersecurity Risk Engineering and Operations teams to align training with realworld threats and controls.
- Coordinate with HR and Communications teams to support onboarding policy acknowledgment and changemanagement initiatives.
- Serve as a trusted advisor to business teams onsecurityawareness best practices.
Qualifications & Experience
- 58 years of experience in cybersecurity awareness training GRC or relatedsecurityroles.
- Handson experience delivering cybersecurity training programs in a regulated or complex environment.
- Strong understanding of common cybersecurity risks user behavior factors and awareness best practices.
- Experience partnering with Legal Privacy and Compliance teams on regulatory or auditdriven initiatives.
- Excellent communication and contentdevelopment skills with the ability to explainsecurityconcepts to nontechnical audiences.
- Highly organized and selfdirected with the ability to manage multiple initiatives across a distributed organization.
Preferred Qualifications
- Experience in financial services or similarly regulated industries.
- Familiarity with cybersecurity frameworks and regulatory requirements (e.g. NIST CSF NYDFS GLBA).
- Experience with phishing simulation and training platforms.
- Professional certifications such as CISSP CISMSecurity or relevantsecurityawareness credentials
#LI-KJ2
This position is an exempt position. The annualized base pay range for this role is expected to be between $140000$160000 base salary compensation range. Actual base pay may vary based on factors including but not limited to experience subject matter expertise geographic location where work will be performed and the applicants skill set. The base pay is just one component of the total compensation package. Other rewards may include an annual cash bonus and a comprehensive benefits package including but not limited to medical dental vision life insurance and 401(k). Please note that the job title is subject to change based on the selected candidates experience and education.
About Focus Financial Partners
Focus is a leading financial services firm comprised of integrated wealth management family office and business management services. Blending deep expertise and expansive resources with a boutique client-first fiduciary philosophy Focus helps individuals families and institutions navigate complex financial situations with highly personalized solutions tailored to their unique needs. To learn more about Focus visit follow the company onLinkedIn.
Focus is an equal opportunity employer and bases its employment decisions on the employee or candidates skillset and without regard to an employee or candidates race color religion sex (including pregnancy) gender identity sexual orientation national origin age disability genetic information veteran status or any other characteristic protected by local state and/or federal law.
Focus complies with federal and state disability laws and makes reasonable accommodations for applicants and employees with disabilities. If reasonable accommodation is needed to participate in the job application or interview process to perform essential job functions and/or to receive other benefits and privileges of employment please contact .
The following language is for US based roles only
For California Applicants:Information on your California privacy rights can be found here
For Indiana Applicants: It is unlawful for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States a member of the Indiana National Guard or a member of a reserve component.
For Maryland Applicants: I UNDERSTAND THAT UNDER MARYLAND LAW AN EMPLOYER MAY NOT REQUIRE OR DEMAND AS A CONDITION OF EMPLOYMENT PROSPECTIVE EMPLOYMENT OR CONTINUED EMPLOYMENT THAT ANY INDIVIDUAL SUBMIT TO OR TAKE A POLYGRAP OR SIMILAR TEST. AN EMPLOYER WHO VIOLATES THIS LAW IS GUILTY OF A MISDEMEANOR AND SUBJECT TO A FINE NOT EXCEEDING $100.
For Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this shall be subject to criminal penalties and civil liability.
For Montana Applicants: If hired the employment relationship is governed by the Wrongful Discharge from Employment Act. Mont. Code Ann. Section.
For Rhode Island Applicants: Focus is subject to Chapters 29-38 of Title 28 of the General Laws of Rhode Island and is therefore covered by the states workers compensation law. If you willfully provide false information about your ability to perform the essential functions of the job with or without reasonable accommodations you may be barred from filing a claim under the provisions of the Workers Compensation Act of the State of Rhode Island if the false information is directly related to the personal injury that is the basis for the new claim for compensation. The Company complies fully with the Americans with Disabilities Act.
Required Experience:
IC