Epicareer Might not Working Properly
Learn More

Manager, Security Awareness & Education

Salary undisclosed

Checking job availability...

Original
Simplified


Manager, Information Security Awareness & Education


Employment Type: Full-Time/Direct Hire


Workplace Type:


Location: Century City, CA


Industry: Entertainment


Salary: $140,000 - $160,000



SUMMARY



Reporting to the Deputy CISO this is a hands-on security leadership position working within the Information Risk Management (IRM) group and delivering solutions to the company at large. The core focus of this position is to develop and deliver the strategies, plans and execution support for the Information Security Training and Awareness Program. This role will develop and deliver awareness and training materials through various means including in-person, online learning, newsletters, and email. This person will work closely with functional Tech and business leads to align awareness deliverables to the highest risk activities and behaviors. The successful candidate will ensure the information security awareness program communicates security policies and requirements in a manner that is clear, action oriented and measurable.



We are looking for candidates who are self-driven and possess a mastery of security awareness and have a passion for data protection, personal information security and communications. Broad cybersecurity experience, and ability to correlate and convert technical signals into security awareness opportunities is desired. In a highly end-user centric environment, candidate must identify relevant awareness communications and distribute them promptly.



The candidate will play a key role in our teams' efforts to build and support a defensible environment where we are able to detect, contain and respond quickly to data security threats and compromise in ways that serve to enable the business needs of a highly collaborative organization. The environment is fast-paced and commonly on the leading edge of technology, including early adoption of various cloud services along with the challenges of integrating those services into our security practices.



RESPONSIBILITIES:




  • Lead an information security awareness program that effectively engages employees resulting in measurable improvements in behavior

  • Partner with key teams such as Service Desk, HR Learning, Privacy and Compliance, to develop training to support the security awareness and data protection efforts

  • Proactive identification of current security events, determine applicability, and develop appropriate communications

  • In collaboration with other IRM team members, create and distribute training or awareness communication for IRM programs

  • Effective communication of Policies and Standards to the Tech team and broader Agency and cross functional stakeholders

  • Develop and implement real-time awareness capabilities triggered at the point of risky behaviors identified in incident response or other technology workflows

  • In coordination with technology functional owners and the user community, provide solutions to reduce risk of sensitive information workflows and developing risk mitigations and training plans

  • Plan and administer information security and privacy training through online learning management systems and in person methods.

  • Prepare and deliver targeted awareness campaigns (cybersecurity month, phishing simulations, security newsletter)

  • Develop and maintain metrics measuring the results of individual campaigns and overall program effectiveness

  • Play an active role in security incident response efforts, working to identify and mitigate information security threats



REQUIRED SKILLS & EXPERIENCE:




  • Minimum 8 years of Information Security experience with a Bachelor's Degree

  • Minimum 3 years experience in a Security Awareness function

  • Experience in a leadership or managerial position is required

  • Ability to communicate complex messages in a clear and concise manner with stakeholders at all levels

  • Excellent organizational skills and ability to communicate with internal/external entities and executives

  • Effective leadership skills with demonstrated ability to coordinate people and teams to project/activity completion

  • Ability to work in team environment sharing responsibilities

  • Ability to work in a flexible environment where requirements and procedures continuously evolve

  • Experience with contractual and regulatory standards such as PCI, GDPR, and NIST

  • Strong professional writing skills, able to research and prepare high quality, clearly written awareness, and training materials

  • Proactive and self-motivated, taking the lead on security awareness and training activities



PREFERED SKILLS & EXPERIENCE:



  • Marketing or Communications experience

  • Certification in information security (CISSP, CISM, GIAC, or equivalent)



All qualified applicants will receive consideration for employment without regard to race, color, national origin, age, ancestry, religion, sex, sexual orientation, gender identity, gender expression, marital status, disability, medical condition, genetic information, pregnancy, or military or veteran status. We consider all qualified applicants, including those with criminal histories, in a manner consistent with state and local laws, including the California Fair Chance Act, City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, and Los Angeles County Fair Chance Ordinance. For unincorporated Los Angeles county, to the extent our customers require a background check for certain positions, the Company faces a significant risk to its business operations and business reputation unless a review of criminal history is conducted for those specific job positions.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Report this job


Manager, Information Security Awareness & Education


Employment Type: Full-Time/Direct Hire


Workplace Type:


Location: Century City, CA


Industry: Entertainment


Salary: $140,000 - $160,000



SUMMARY



Reporting to the Deputy CISO this is a hands-on security leadership position working within the Information Risk Management (IRM) group and delivering solutions to the company at large. The core focus of this position is to develop and deliver the strategies, plans and execution support for the Information Security Training and Awareness Program. This role will develop and deliver awareness and training materials through various means including in-person, online learning, newsletters, and email. This person will work closely with functional Tech and business leads to align awareness deliverables to the highest risk activities and behaviors. The successful candidate will ensure the information security awareness program communicates security policies and requirements in a manner that is clear, action oriented and measurable.



We are looking for candidates who are self-driven and possess a mastery of security awareness and have a passion for data protection, personal information security and communications. Broad cybersecurity experience, and ability to correlate and convert technical signals into security awareness opportunities is desired. In a highly end-user centric environment, candidate must identify relevant awareness communications and distribute them promptly.



The candidate will play a key role in our teams' efforts to build and support a defensible environment where we are able to detect, contain and respond quickly to data security threats and compromise in ways that serve to enable the business needs of a highly collaborative organization. The environment is fast-paced and commonly on the leading edge of technology, including early adoption of various cloud services along with the challenges of integrating those services into our security practices.



RESPONSIBILITIES:




  • Lead an information security awareness program that effectively engages employees resulting in measurable improvements in behavior

  • Partner with key teams such as Service Desk, HR Learning, Privacy and Compliance, to develop training to support the security awareness and data protection efforts

  • Proactive identification of current security events, determine applicability, and develop appropriate communications

  • In collaboration with other IRM team members, create and distribute training or awareness communication for IRM programs

  • Effective communication of Policies and Standards to the Tech team and broader Agency and cross functional stakeholders

  • Develop and implement real-time awareness capabilities triggered at the point of risky behaviors identified in incident response or other technology workflows

  • In coordination with technology functional owners and the user community, provide solutions to reduce risk of sensitive information workflows and developing risk mitigations and training plans

  • Plan and administer information security and privacy training through online learning management systems and in person methods.

  • Prepare and deliver targeted awareness campaigns (cybersecurity month, phishing simulations, security newsletter)

  • Develop and maintain metrics measuring the results of individual campaigns and overall program effectiveness

  • Play an active role in security incident response efforts, working to identify and mitigate information security threats



REQUIRED SKILLS & EXPERIENCE:




  • Minimum 8 years of Information Security experience with a Bachelor's Degree

  • Minimum 3 years experience in a Security Awareness function

  • Experience in a leadership or managerial position is required

  • Ability to communicate complex messages in a clear and concise manner with stakeholders at all levels

  • Excellent organizational skills and ability to communicate with internal/external entities and executives

  • Effective leadership skills with demonstrated ability to coordinate people and teams to project/activity completion

  • Ability to work in team environment sharing responsibilities

  • Ability to work in a flexible environment where requirements and procedures continuously evolve

  • Experience with contractual and regulatory standards such as PCI, GDPR, and NIST

  • Strong professional writing skills, able to research and prepare high quality, clearly written awareness, and training materials

  • Proactive and self-motivated, taking the lead on security awareness and training activities



PREFERED SKILLS & EXPERIENCE:



  • Marketing or Communications experience

  • Certification in information security (CISSP, CISM, GIAC, or equivalent)



All qualified applicants will receive consideration for employment without regard to race, color, national origin, age, ancestry, religion, sex, sexual orientation, gender identity, gender expression, marital status, disability, medical condition, genetic information, pregnancy, or military or veteran status. We consider all qualified applicants, including those with criminal histories, in a manner consistent with state and local laws, including the California Fair Chance Act, City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, and Los Angeles County Fair Chance Ordinance. For unincorporated Los Angeles county, to the extent our customers require a background check for certain positions, the Company faces a significant risk to its business operations and business reputation unless a review of criminal history is conducted for those specific job positions.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Report this job