** Full-time/salaried position - Requires working onsite 3 days/week **
Overview:
The core focus of this position is to develop and deliver the strategies, plans and execution support for the Information Security Training and Awareness Program. This role will develop and deliver awareness and training materials through various means including in-person, online learning, newsletters, and email. This person will work closely with functional Tech and business leads to align awareness deliverables to the highest risk activities and behaviors. The successful candidate will ensure the information security awareness program communicates security policies and requirements in a manner that is clear, action oriented and measurable.
This position will play a key role in our teams' efforts to build and support a defensible environment where we are able to detect, contain and respond quickly to data security threats and compromise in ways that serve to enable the business needs of a highly collaborative organization. The environment is fast-paced and commonly on the leading edge of technology, including early adoption of various cloud services along with the challenges of integrating those services into our security practices.
Responsibilities:
- Lead an information security awareness program that effectively engages employees resulting in measurable improvements in behavior.
- Partner with key teams such as Service Desk, HR Learning, Privacy and Compliance, to develop training to support the security awareness and data protection efforts.
- Proactively identify current security events, determine applicability to company, and develop appropriate communications.
- Collaborate with Information Risk Management teams to create and distribute training or awareness communication for security programs.
- Effectively communicate Policies & Standards to the IT team, broader Agency, and cross-functional stakeholders.
- Develop and implement real-time awareness capabilities triggered at the point of risky behaviors identified in incident response or other technology workflows.
- In coordination with Tech functional owners and the user community, provide solutions to reduce risk of sensitive information workflows and developing risk mitigations and training plans.
- Plan and administer information security and privacy training through online learning management systems and in person methods.
- Prepare and deliver targeted awareness campaigns (cybersecurity month, phishing simulations, security newsletter).
- Develop and maintain metrics measuring the results of individual campaigns and overall program effectiveness.
- Play an active role in identifying and mitigating information security threats and incident response efforts.
Skills & Experience:
- 8+ years of Information Security experience
- 3+ years' experience leading large scale Cybersecurity training/education programs
- Demonstrated experience working with enterprise-level companies
- Deep knowledge of data security best practices and data privacy standards such as PCI, GDPR
- Strong writing skills, able to research and prepare high quality and clearly written training materials
- Proactive and self-motivated, taking the lead on security awareness and training activities
- Ability to communicate complex messages in a clear and concise manner with stakeholders at all levels
- Excellent organizational skills and ability to communicate with internal/external entities and executives
- Effective leadership skills with demonstrated ability to coordinate projects/activities cross-functionally
- Ability to work in a flexible environment where requirements and procedures continuously evolve
- Ability to work in team environment sharing responsibilities
Education & Training:
- (Required) Bachelor's degree in a relevant field (Cybersecurity, Engineering, IT, etc.)
- (Preferred) Relevant industry certifications, such as CISSP, CISM, GIAC, etc.
Other Nice-to-Haves:
- Industry experience in Entertainment, Media, or Technology
- Graphic design skills for creating education/training materials
- Marketing or Communications experience