Risk Specialist

Focus Financial Partners

New York (NY)

On-site

USD 100,000 - 130,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Annual bonus
Medical, dental, vision insurance
Life insurance
401(k)

Job summary

Focus Financial Partners seeks a proactive Senior Risk Operations Specialist to bolster our Cybersecurity program, focusing on vulnerability and third-party risk management and policy development. Based in New York or St. Louis, you’ll work with cross-functional teams to manage risk across partner firms.

The role emphasizes governance, incident handling, and dashboarding of KPIs/KRIs, with base pay and bonus potential reflecting market norms for a consumer-focused financial services firm.

Qualifications

  • 3–5 years of experience in cybersecurity risk management, vulnerability management, third-party risk management, or a related cybersecurity discipline.
  • Experience analyzing vulnerabilities, conducting vendor security assessments, and managing remediation efforts across technical and business stakeholders.
  • Knowledge of the vulnerability management lifecycle, including discovery, validation, prioritization, remediation, verification, exception management, and risk acceptance.
  • Familiarity with cybersecurity frameworks such as NIST CSF, ISO 27001, or similar industry standards.
  • Experience with vulnerability and exposure management platforms such as Rapid7, Tenable, Qualys, CrowdStrike, or similar tools.
  • Knowledge of financial services regulations and security requirements, including SEC, FINRA, Regulation S-P, GDPR, and CCPA.
  • Strong analytical, communication, and relationship management skills with the ability to influence technical and non-technical stakeholders.
  • Ability to manage multiple priorities in a fast-paced, highly collaborative environment.
  • Industry certifications such as CISSP, CISM, or GIAC certifications are preferred.
  • Prior experience in a financial services or multi-partner environment is preferred.

Responsibilities

  • Analyze vulnerability assessments and third-party security reviews, considering environmental, procedural, and business risk factors—not just technical severity scores.
  • Partner with Infrastructure, Security Engineering, Enterprise Risk Management, Vendor Management, Legal, Compliance, Procurement, and business stakeholders to identify, assess, and mitigate cybersecurity risk.
  • Manage the lifecycle of vulnerabilities and third-party risks by tracking findings, driving remediation efforts, facilitating risk acceptance, and validating issue resolution.
  • Conduct cybersecurity due diligence for new and existing vendors, evaluate security controls, and recommend practical risk mitigation strategies and compensating controls.
  • Develop and maintain third-party risk management (TPRM) policies, procedures, vendor assessment questionnaires, and governance processes.
  • Drive remediation initiatives for end-of-life and unsupported technologies, vendor security gaps, and other identified cyber risks.
  • Assist in developing threat intelligence and exposure management processes to identify emerging risks affecting the organization and its third-party ecosystem.
  • Develop, track, and report cybersecurity and third-party risk metrics, including Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs), to leadership.
  • Support regulatory, audit, and compliance initiatives by ensuring cybersecurity and third-party risk practices align with applicable regulations and industry frameworks.
  • Build strong relationships with internal stakeholders and third-party partners to promote effective risk management and continuous improvement across the cybersecurity program.

Skills

Cybersecurity risk management
Vulnerability management
Vendor risk assessment
Policy writing
Stakeholder communication
Threat intelligence
KPI/KRI reporting

Tools

Rapid7
Tenable
Qualys
CrowdStrike

Job description

Job Description Summary

Focus Financial Partners is seeking a proactive and detail-oriented Senior Risk Operations Specialist to support and strengthen our organization’s Cybersecurity program. This role is responsible for supporting key risk pillars: Vulnerability Management and Risk Management. A successful candidate will have knowledge of one or more of these areas and be able to assist with writing policy and process, supporting deployment of technology and handling incident response in a variety of environments. The candidate will also manage and maintain cybersecurity dashboards to track key performance indicators (KPIs) across all partner firms.

This role can be based in New York, NY or St Louis, MO.

Primary Responsibilities
  • Analyze vulnerability assessments and third-party security reviews, considering environmental, procedural, and business risk factors—not just technical severity scores.
  • Partner with Infrastructure, Security Engineering, Enterprise Risk Management, Vendor Management, Legal, Compliance, Procurement, and business stakeholders to identify, assess, and mitigate cybersecurity risk.
  • Manage the lifecycle of vulnerabilities and third-party risks by tracking findings, driving remediation efforts, facilitating risk acceptance, and validating issue resolution.
  • Conduct cybersecurity due diligence for new and existing vendors, evaluate security controls, and recommend practical risk mitigation strategies and compensating controls.
  • Develop and maintain third-party risk management (TPRM) policies, procedures, vendor assessment questionnaires, and governance processes.
  • Drive remediation initiatives for end-of-life and unsupported technologies, vendor security gaps, and other identified cyber risks.
  • Assist in developing threat intelligence and exposure management processes to identify emerging risks affecting the organization and its third-party ecosystem.
  • Develop, track, and report cybersecurity and third-party risk metrics, including Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs), to leadership.
  • Support regulatory, audit, and compliance initiatives by ensuring cybersecurity and third-party risk practices align with applicable regulations and industry frameworks.
  • Build strong relationships with internal stakeholders and third-party partners to promote effective risk management and continuous improvement across the cybersecurity program.
Qualifications
  • 3–5 years of experience in cybersecurity risk management, vulnerability management, third-party risk management, or a related cybersecurity discipline.
  • Experience analyzing vulnerabilities, conducting vendor security assessments, and managing remediation efforts across technical and business stakeholders.
  • Knowledge of the vulnerability management lifecycle, including discovery, validation, prioritization, remediation, verification, exception management, and risk acceptance.
  • Familiarity with cybersecurity frameworks such as NIST CSF, ISO 27001, or similar industry standards.
  • Experience with vulnerability and exposure management platforms such as Rapid7, Tenable, Qualys, CrowdStrike, or similar tools.
  • Knowledge of financial services regulations and security requirements, including SEC, FINRA, Regulation S-P, GDPR, and CCPA.
  • Strong analytical, communication, and relationship management skills with the ability to influence technical and non-technical stakeholders.
  • Ability to manage multiple priorities in a fast-paced, highly collaborative environment.
  • Industry certifications such as CISSP, CISM, or GIAC certifications are preferred.
  • Prior experience in a financial services or multi-partner environment is preferred.

This position is an exempt position. The annualized base pay range for this role is expected to be between $100,000-$130,000 base salary compensation range. Actual base pay may vary based on factors including, but not limited to, experience, subject matter expertise, geographic location where work will be performed, and the applicant’s skill set. The base pay is just one component of the total compensation package. Other rewards may include an annual cash bonus and a comprehensive benefits package, including but not limited to medical, dental, vision, life insurance, and 401(k). Please note that the job title is subject to change based on the selected candidate’s experience and education.

Focus is a leading financial services firm comprised of integrated wealth management, family office, and business management services. Blending deep expertise and expansive resources with a boutique, client-first fiduciary philosophy, Focus helps individuals, families, and institutions navigate complex financial situations with highly personalized solutions tailored to their unique needs. To learn more about Focus, visit www.focusfinancialpartners.com or follow the company on LinkedIn.

EEO Statement: Focus is an equal opportunity employer and bases its employment decisions on the employee or candidate’s skillset, and without regard to an employee or candidate’s race, color, religion, sex (including pregnancy), gender identity, sexual orientation, national origin, age, disability, genetic information, veteran status, or any other characteristic protected by local, state and/or federal law.

Focus complies with federal and state disability laws and makes reasonable accommodations for applicants and employees with disabilities. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact careers@focuspartners.com

The following language is for US based roles only.

For California Applicants: Information on your California privacy rights can be found here.

For Indiana Applicants: It is unlawful for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component.

For Maryland Applicants: I UNDERSTAND THAT UNDER MARYLAND LAW, AN EMPLOYER MAY NOT REQUIRE OR DEMAND, AS A CONDITION OF EMPLOYMENT, PROSPECTIVE EMPLOYMENT OR CONTINUED EMPLOYMENT, THAT ANY INDIVIDUAL SUBMIT TO OR TAKE A POLYGRAP OR SIMILAR TEST. AN EMPLOYER WHO VIOLATES THIS LAW IS GUILTY OF A MISDEMEANOR AND SUBJECT TO A FINE NOT EXCEEDING $100.

For Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this shall be subject to criminal penalties and civil liability.

For Montana Applicants: If hired, the employment relationship is governed by the Wrongful Discharge from Employment Act. Mont. Code Ann. Section 39-2-901.

For Rhode Island Applicants: Focus is subject to Chapters 29-38 of Title 28 of the General Laws of Rhode Island and is therefore covered by the state’s workers’ compensation law. If you willfully provide false information about your ability to perform the essential functions of the job, with or without reasonable accommodations, you may be barred from filing a claim under the provisions of the Workers’ Compensation Act of the State of Rhode Island if the false information is directly related to the personal injury that is the basis for the new claim for compensation. The Company complies fully with the Americans with Disabilities Act.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Solutions Architect
Cybersecurity Solutions Architect

Focus Financial Partners • St. Louis (MO)

On-site
USD 150,000 - 185,000
Annual bonus
Benefits package
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Dormont Manufacturing Co • St. Louis (MO)

On-site
USD 140,000 - 160,000
Comprehensive benefits package including medical, dental, vision
401(k)
Annual cash bonus
Risk Specialist
Risk Specialist

Focus Financial Partners • St. Louis (MO)

On-site
USD 110,000 - 130,000
Annual cash bonus
Comprehensive benefits package
Risk Specialist
Risk Specialist

LE0099 Focus Operating, LLC • Clayton (MO)

On-site
USD 100,000 - 130,000
Annual cash bonus
Medical
Dental
+3
Data & Integration Ops Engineer
Data & Integration Ops Engineer

Focus Financial Partners • St. Louis (MO)

Hybrid
USD 110,000 - 130,000
Associate, Corporate Strategy
Associate, Corporate Strategy

Focus Financial Partners • San Francisco (CA)

On-site
USD 90,000 - 120,000
Senior Investment Strategist
Senior Investment Strategist

Focus Financial Partners • Chicago (IL)

Hybrid
USD 140,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+2
Senior Investment Strategist
Senior Investment Strategist

Focus Financial Partners • St. Louis (MO)

Hybrid
USD 140,000 - 160,000
Annual bonus
Benefits package (medical, dental, or
Senior Associate Wealth Advisor
Senior Associate Wealth Advisor

Focus Financial Partners • Needham (MA)

Hybrid
USD 125,000 - 140,000
Medical coverage
Dental coverage
401(k)
Senior Investment Strategist
Senior Investment Strategist

Focus Financial Partners • Boston (MA)

Hybrid
USD 140,000 - 160,000