Lead, Information Security Awareness and Education
Location: This role will be based in our Los Angeles, CA office, Monday – Friday; hybrid
Full Time Position
Summary:
Reporting to the client Deputy CISO this is a hands-on security leadership position working within the Information Risk Management (IRM) group and delivering solutions to the company at large. The core focus of this position is to develop and deliver the strategies, plans and execution support for the Information Security Training and Awareness Program. This role will develop and deliver awareness and training materials through various means including in-person, online learning, newsletters, and email. This person will work closely with functional Tech and business leads to align awareness deliverables to the highest risk activities and behaviours. The successful candidate will ensure the information security awareness program communicates security policies and requirements in a manner that is clear, action oriented and measurable.
We are looking for candidates who are self-driven and possess a mastery of security awareness and have a passion for data protection, personal information security and communications. Broad cybersecurity experience, and ability to correlate and convert technical signals into security awareness opportunities is desired. In a highly end-user centric environment, candidate must identify relevant awareness communications and distribute them promptly.
The candidate will play a key role in our teams' efforts to build and support a defensible environment where we are able to detect, contain and respond quickly to data security threats and compromise in ways that serve to enable the business needs of a highly collaborative organization. The environment is fast-paced and commonly on the leading edge of technology, including early adoption of various cloud services along with the challenges of integrating those services into our security practices.
Responsibilities
- Lead an information security awareness program that effectively engages employees resulting in measurable improvements in behavior
- Partner with key teams such as Service Desk, HR Learning, Privacy and Compliance, to develop training to support the security awareness and data protection efforts
- Proactive identification of current security events, determine applicability to client, and develop appropriate communications
- In collaboration with other IRM team members, create and distribute training or awareness communication for IRM programs
- Effective communication of client policies and standards to the Tech team and broader Agency and cross functional stakeholders
- Develop and implement real-time awareness capabilities triggered at the point of risky behaviours identified in incident response or other technology workflows
- In coordination with client Tech functional owners and the user community, provide solutions to reduce risk of sensitive information workflows and developing risk mitigations and training plans
- Plan and administer information security and privacy training through online learning management systems and in person methods.
- Prepare and deliver targeted awareness campaigns (cybersecurity month, phishing simulations, security newsletter)
- Develop and maintain metrics measuring the results of individual campaigns and overall program effectiveness
- Play an active role in client's security incident response efforts, working to identify and mitigate information security threats
Required Capabilities:
- Minimum 8 years of Information Security experience with a Bachelor's Degree
- Minimum 3 years experience in a Security Awareness function
- Experience in a leadership or managerial position is required
- Marketing or Communications experience a plus
- Ability to communicate complex messages in a clear and concise manner with stakeholders at all levels
- Excellent organizational skills and ability to communicate with internal/external entities and executives
- Effective leadership skills with demonstrated ability to coordinate people and teams to project/activity completion
- Ability to work in team environment sharing responsibilities
- Ability to work in a flexible environment where requirements and procedures continuously evolve
- Experience with contractual and regulatory standards such as PCI, GDPR
- Certification in information security (CISSP, CISM, GIAC, or equivalent) preferred
- A capable professional writer, able to research and prepare high quality, clearly written awareness, and training materials
- Proactive and self-motivated, taking the lead on security awareness and training activities.
Feliza LaClare
iSpace, Inc., El Segundo CA
Office: (310) ###-####
...@ispace.com
www.ispace.com
www.linkedin.com/in/feliza-laclare-a03821240/
Ranked by Inc 5000 as one of America's Fastest Growing Private Companies, 6 years in a row