GitLab4 дня назад

Principal Security Awareness & Human Risk Engineer

16 933–22 917 ₽в месяц · до вычета
РЫНОК
15 421медиана по профессии
CISO · 26 вакансий с указанной зарплатой
6 067половина предложений: 11 227–25 344785 375
В рынке · выше 62% предложений
Remote

Обязанности

  • 01Own and evolve the global security awareness and education program, spanning annual, new-hire, role-based, targeted, executive, and microlearning content
  • 02Lead the phishing simulation program end to end — design, deployment, analysis, and targeted follow-up
  • 03Apply behavior change principles to reinforce secure habits and address priority risk behaviors
  • 04Build and sustain security culture through learning campaigns, Security Awareness Month, and ongoing engagement
  • 05Produce multimedia awareness and education content, including video
  • 06Administer the training and phishing platforms, owning program data and reporting end to end
  • 07Define and report performance indicators to Security Assurance leadership
  • 08Own vendor relationships for phishing, secure coding (OWASP) training, and video production
  • 09Lead market and competitor evaluations, renewal decisions, and cost negotiation, recommending in-house builds where commercial options underperform
  • 10Collaborate on and maintain security policies, standards, and procedures
  • 11Coordinate audit evidence and demonstrate control effectiveness
  • 12Track remediation of identified gaps to closure

Требования

  • 01A minimum of 10 years' experience building or scaling global awareness and human-risk programs in a large, globally distributed enterprise, with measurable outcomes; regulated-industry experience preferred
  • 02SANS Security Awareness Professional (SSAP) certification, or equivalent demonstrated expertise in building, maintaining, and measuring a mature awareness program
  • 03Demonstrated experience running enterprise-scale phishing programs and organization-wide awareness campaigns
  • 04Track record of evaluating, selecting, consolidating, or replacing security training vendors, including cost and value analysis
  • 05Instructional design capability
  • 06Working knowledge of security policy development, audit support, and control evidence
  • 07Ability to influence enterprise strategy across technical and non-technical teams without formal authority
  • 08Ability to make complex security topics practical and engaging in an all-remote organization
  • 09Track record of onboarding, managing, and negotiating with third party vendors

Условия

  • 01Benefits to support your health, finances, and well-being
  • 02Flexible Paid Time Off
  • 03Team Member Resource Groups
  • 04Equity Compensation & Employee Stock Purchase Plan
  • 05Growth and Development Fund
  • 06Parental Leave