CapTrust

Security Specialist

CapTrust$120K — $160K *
US-AnywhereRemote in Saint Louis, MO
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-8+ years of experience in cybersecurity awareness, training, governance, risk, and compliance roles.
  • Proven skill in delivering cybersecurity training in regulated environments.
  • In-depth knowledge of cybersecurity risks and user behavior factors.
  • Experience working with legal and compliance teams on regulatory initiatives.
  • Exceptional communication skills to translate complex concepts for non-technical staff.
  • Self-motivated with strong organizational skills to handle multiple projects.

Responsibilities

  • Execute and oversee the firm-wide cybersecurity awareness and training program.
  • Deliver mandatory and role-based security training addressing key cyber risks.
  • Manage phishing simulation campaigns from design to follow-up education.
  • Develop and update engaging training content tailored for various audiences.
  • Integrate lessons from incidents and regulatory feedback into training.
  • Collaborate with Legal and Compliance to ensure content meets regulations.
  • Track training metrics and analyze data to identify risk areas.

Benefits

  • Hybrid work model with 3 days in the office.
  • Comprehensive health benefits including medical, dental, and vision coverage.
  • 401(k) plan to support retirement savings.
  • Access to an annual cash bonus based on performance.
  • Opportunities for professional development and certifications.
Full Job Description
Job Description Summary:
This Security Specialist role will serve as a lead for cybersecurity awareness & training program responsible for the execution and continuous improvement of the firm's cybersecurity awareness and training program across all Focus firms. This role serves as the primary owner for delivering engaging, effective, and risk-based cybersecurity training to employees at all levels of the organization.

Reporting to the Head of Cybersecurity Governance, this individual-contributor role works in close partnership with Legal, Privacy, Regulatory Compliance, HR, IT, and Security teams to ensure training content aligns with regulatory requirements, internal policies, and evolving cyber threats. The role plays a critical part in strengthening the firm's security culture and reducing human-driven cyber risk.

This role is hybrid with 3 days per week in our St. Louis office.

Job Description:

Primary Responsibilities

Cybersecurity Awareness & Training Program Delivery
  • Execute the firm-wide cybersecurity awareness and training program across all Focus firms.
  • Deliver mandatory annual security training, role-based training, and targeted campaigns addressing key cyber risks (e.g., phishing, social engineering, data protection).
  • Manage and execute phishing simulation programs, including campaign design, delivery, analysis, and follow-up education.
  • Coordinate training rollouts, schedules, and communications to ensure consistent adoption across diverse business units.

Content Development & Continuous Improvement
  • Develop, maintain, and refresh cybersecurity training content to ensure relevance, clarity, and engagement.
  • Tailor training materials for different audiences, including employees, advisors, leadership, and specialized roles.
  • Incorporate lessons learned from incidents, phishing results, regulatory feedback, and emerging threat trends into training content.
  • Balance regulatory requirements with practical, user-friendly messaging that supports business productivity.

Regulatory, Legal & Compliance Partnership
  • Work closely with Legal, Privacy, and Regulatory Compliance teams to ensure training content aligns with applicable laws, regulations, and contractual obligations.
  • Support regulatory examinations, audits, and client due diligence efforts by providing training materials, metrics, and evidence.
  • Maintain documentation demonstrating compliance with cybersecurity training and awareness requirements.
  • Monitor regulatory expectations related to security awareness and adjust training accordingly.

Measurement, Reporting & Risk Reduction
  • Define and track key training and awareness metrics (e.g., completion rates, phishing susceptibility, behavioral improvements).
  • Analyze trends and results to identify risk areas and inform targeted training initiatives.
  • Provide regular reporting and insights to the Head of Cybersecurity Governance and other stakeholders.
  • Demonstrate the effectiveness of training programs in reducing human-driven cyber risk.

Cross-Functional Collaboration
  • Partner closely with Cybersecurity Risk, Engineering, and Operations teams to align training with real-world threats and controls.
  • Coordinate with HR and Communications teams to support onboarding, policy acknowledgment, and change-management initiatives.
  • Serve as a trusted advisor to business teams on security awareness best practices.


Qualifications & Experience
  • 5-8+ years of experience in cybersecurity awareness, training, GRC, or related security roles.
  • Hands-on experience delivering cybersecurity training programs in a regulated or complex environment.
  • Strong understanding of common cybersecurity risks, user behavior factors, and awareness best practices.
  • Experience partnering with Legal, Privacy, and Compliance teams on regulatory or audit-driven initiatives.
  • Excellent communication and content-development skills, with the ability to explain security concepts to non-technical audiences.
  • Highly organized and self-directed, with the ability to manage multiple initiatives across a distributed organization.

Preferred Qualifications
  • Experience in financial services or similarly regulated industries.
  • Familiarity with cybersecurity frameworks and regulatory requirements (e.g., NIST CSF, NYDFS, GLBA).
  • Experience with phishing simulation and training platforms.
  • Professional certifications such as CISSP, CISM, Security+, or relevant security awareness credentials


This position is an exempt position. The annualized base pay range for this role is expected to be between $120,000-$160,000 base salary compensation range. Actual base pay may vary based on factors including, but not limited to, experience, subject matter expertise, geographic location where work will be performed, and the applicant's skill set. The base pay is just one component of the total compensation package. Other rewards may include an annual cash bonus and a comprehensive benefits package, including but not limited to medical, dental, vision, life insurance, and 401(k). Please note that the job title is subject to change based on the selected candidate's experience and education.

About CapTrust

CapTrust is a financial services firm that provides investment advisory, fiduciary, and consulting services to institutional investors, retirement plan sponsors, and high net worth individuals. The company was founded in 1997 and is headquartered in Raleigh, North Carolina. CapTrust has over 800 employees and manages over $50 billion in assets. The company's services include investment consulting, fiduciary services, financial planning, and wealth management. CapTrust has been recognized as one of the fastest-growing RIAs in the country and has received numerous awards for its growth and client service.
Learn more about CapTrust
Size
800 employees
Industry
Founded
1989

Similar Jobs

More Jobs at CapTrust

More Information Technology Jobs

Find similar Security Specialist jobs: