Our Story
Founded in 2008, Hightower is a wealth management firm that provides investment, financial and retirement planning services to individuals, foundations and family offices, as well as 401(k) consulting and cash management services to corporations. Hightower's capital solutions, operational support services, size and scale empower its vibrant community of independent-minded wealth advisors to grow their businesses and help their clients achieve their financial vision. Based in Chicago with advisors across the U.S., we operate as a registered investment advisor (RIA).
Your Future Team
The Identity & Access Management - Access Control Analyst will support the onboarding / offboarding events, membership delegation and permissions for the Hightower user base across core technology platforms.
What You'll Do
- Deliver exceptional customer service by directly engaging with end users to resolve access control-related issues and access requests in a clear, courteous, and professional manner.
- Support IAM incident and request queues : triage, troubleshoot, document, escalate, and resolve issues related to account provisioning, access entitlements, group memberships, and authentication.
- Perform user lifecycle activities, including provisioning, de-provisioning, and role changes across Active Directory, Azure AD, Okta SSO, Microsoft 365, and other business-critical platforms.
- Assist and maintain audit user and system access to ensure compliance with security policies and regulatory standards.
- Perform basic system administration in Active Directory (e.g., group membership management, OU placement) and ensure device compliance in tools such as Intune and Azure AD.
- Collaborate with stakeholders across IT and business units to improve access request workflows and document access control best practices.
- Author and maintain knowledge base articles, SOPs, and technical documentation to support, automation self-service and internal knowledge sharing.
- Participate in user access reviews, and remediation of non-compliance access.
What You'll Bring
Educational Background :Associate's degree in information technology or Cybersecurity, relevant certifications or related field preferred; or equivalent relevant experience.Certifications (Preferred) :CompTIA Security+CompTIA Network+Microsoft Certified : Identity and Access Administrator Associate.Additional certifications in Okta, Azure AD, or other IAM platforms are a plus.Experience :2-3 years of IT support or access control experience, with a focus on access provisioning, user lifecycle management, or Active Directory administration.Familiarity with access control tools such as Okta, Azure Active Directory, Microsoft Intune, and Microsoft 365.Technical Skills :Working knowledge of directory services, group policies, and SSO solutions.Basic understanding of security principles related to least privilege, Role Base Access Control - RBAC, MFA, and compliance.Proficient in documenting processes and resolving issues using ticketing systems (e.g., ServiceNow, Salesforce, Jira).Communication Skills : Excellent communication and writing skills to collaborate with teams and provide end-user support.Technical Proficiency : Ability to perform Active Directory activities.Problem-Solving Skills : Ability to troubleshoot issues and propose effective solutions.What We Offer
Coverage on the first day of employment for medical, dental, and vision insurancePaid parental leave (16 weeks for primary caregiver and 8 weeks for secondary caregiver)Mother's lounge onsiteFlexible PTO planHybrid work schedule (minimum of 3 days in office)Free brand-new gym in the Chicago office401k matching planHSA employer contributionsStudent loan assistancePet insuranceBase salary of $70,000-$80,000 plus discretionary bonus (exact base salary amount will be dependent on experience)AN EQUAL OPPORTUNITY EMPLOYER : Hightower is an equal opportunity employer and does not discriminate based upon race, color, religion, sex, sexual orientation, pregnancy, marital status, national origin, citizenship, veteran status, ancestry, age (over 40), physical or mental disability, medical condition (cancer-related), gender identity or expression, genetic information including sickle cell or hemoglobin C trait, or any other consideration made unlawful by applicable federal, state, or local law.
You are a U.S. citizen, U.S. permanent resident or possess other unrestricted U.S. work authorization and will not require sponsorship for U.S. work authorization now or anytime in the future