Program Manager, Security Awareness & Training
Employment Type: Full-Time/Direct Hire
Workplace Type: Hybrid (3 days onsite, 2 days WFH)
Location: West Los Angeles, CA
Industry: Entertainment
Compensation: $115,000 - $130,000 + Discretionary Bonus
SUMMARY:
Reporting to the Deputy CISO this is a hands-on security position working within the Information Risk Management (IRM) group and delivering solutions to the company at large. The core focus of this position is to develop and deliver the strategies, plans and execution support for the Information Security Training and Awareness Program. This role will develop and deliver awareness and training materials through various means including in-person, online learning, newsletters, and email. This person will work closely with functional Tech and business leads to align awareness deliverables to the highest risk activities and behaviors. The successful candidate will ensure the information security awareness program communicates security policies and requirements in a manner that is clear, action oriented and measurable.
RESPONSIBILITIES:
- Deliver an information security awareness program that effectively engages employees resulting in measurable improvements in behavior
- Partner with key teams such as Service Desk, HR Learning, Privacy and Compliance, to develop training to support the security awareness and data protection efforts.
- Proactive identification of current security events, determine applicability, and develop appropriate communications
- In collaboration with other IRM team members, create and distribute training or awareness communication for IRM programs
- Effective communication of organizational-wide Policies and Standards to the Tech team and broader Agency and cross functional stakeholders
- Develop and implement real-time awareness capabilities triggered at the point of risky behaviors identified in incident response or other technology workflows
- In coordination with the organization's technology leaders and the user community, provide solutions to reduce risk of sensitive information workflows and developing risk mitigations and training plans
- Coordinate and administer information security and privacy training through online learning management systems and in person methods.
- Prepare and deliver targeted awareness campaigns (cybersecurity month, phishing simulations, security newsletter)
- Develop and maintain metrics measuring the results of individual campaigns and overall program effectiveness
- Play an active role in organization's security incident response efforts, working to identify and mitigate information security threats
REQUIREMENTS:
- Bachelor's Degree in Information Security, Cybersecurity, Information Assurance, Information Technology, Computer Science or related fields
- Minimum 3 years' experience in a Security Awareness function
- Marketing or Communications experience a plus
- Prior expeirnece defining, developing, implementing, and managing Security Awareness Programs, conducting training for security awareness, research emerging trends & best practices for security awareness.
- Experience conducting phishing simulations across an enterprise organization
- Strong understanding of phishing targeted groups, phishing metrics, and educating users on phishing
- Ability to communicate complex messages in a clear and concise manner with stakeholders at all levels
- Excellent organizational skills and ability to communicate with internal/external entities and executives
- Effective leadership skills with demonstrated ability to coordinate people and teams to project/activity completion
- Ability to work in team environment sharing responsibilities
- Ability to work in a flexible environment where requirements and procedures continuously evolve
- Strong working knowledge of security and compliance frameworks such as PCI, GDPR, and NIST
- Relevant Information/Cyber Security certifications such as CompTIA Security+, Certified Ethical Hacker, CISSP, CISM, GIAC, or equivalent (preferred)
- Strong professional writer, able to research and prepare high quality, clearly written awareness, and training materials
- Proactive and self-motivated, taking the lead on security awareness and training activities
All qualified applicants will receive consideration for employment without regard to race, color, national origin, age, ancestry, religion, sex, sexual orientation, gender identity, gender expression, marital status, disability, medical condition, genetic information, pregnancy, or military or veteran status. We consider all qualified applicants, including those with criminal histories, in a manner consistent with state and local laws, including the California Fair Chance Act, City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, and Los Angeles County Fair Chance Ordinance. For unincorporated Los Angeles county, to the extent our customers require a background check for certain positions, the Company faces a significant risk to its business operations and business reputation unless a review of criminal history is conducted for those specific job positions.