
Principal Security Awareness, Human Risk Engineer
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in United States, +1 more country.
• Take charge of enhancing the global security awareness and education program, which includes annual training, onboarding for new employees, role-specific content, targeted initiatives, executive sessions, and microlearning modules.
• Oversee the phishing simulation program from start to finish — including design, implementation, analysis, and follow-up actions tailored to specific needs.
• Utilize behavior change strategies to promote secure habits and tackle critical risk behaviors.
• Foster a strong security culture through learning campaigns, Security Awareness Month activities, and continuous engagement with stakeholders.
• Create diverse multimedia content for awareness and educational purposes, such as videos.
• Manage the training and phishing platforms, taking responsibility for program data and comprehensive reporting.
• Establish and present performance metrics to Security Assurance leadership.
• Manage vendor relationships related to phishing initiatives, secure coding (OWASP) training, and video production.
• Conduct market and competitor assessments, make renewal recommendations, and negotiate costs, advocating for in-house solutions when external options fall short.
• Collaborate on and uphold security policies, standards, and procedures.
• Organize audit evidence and demonstrate the effectiveness of controls.
• Monitor the resolution of identified gaps until closure.
• At least 10 years of experience in developing or expanding global awareness and human-risk programs within a large, internationally distributed organization, with demonstrable outcomes; experience in regulated industries is preferred.
• SANS Security Awareness Professional (SSAP) certification, or equivalent proven expertise in establishing, maintaining, and evaluating a mature awareness program.
• Proven experience managing enterprise-level phishing initiatives and organization-wide awareness campaigns.
• A history of assessing, selecting, consolidating, or replacing security training vendors, encompassing cost and value analysis.
• Strong instructional design skills.
• Familiarity with developing security policies, supporting audits, and providing control evidence.
• Ability to influence enterprise strategy across both technical and non-technical teams without formal authority.
• Capability to present complex security topics in a practical and engaging manner within a fully remote organization.
• Proven experience in onboarding, managing, and negotiating with third-party vendors.
• Benefits to support your health, finances, and well-being
• Flexible Paid Time Off
• Team Member Resource Groups
• Equity Compensation & Employee Stock Purchase Plan
• Growth and Development Fund
• Parental Leave
Primer
Akamai Technologies
Mashreq
Alice
Get handpicked remote jobs straight to your inbox weekly.