Human Risk Manager / Cybersecurity Awareness Professional SME
Location: On site, Washington, DC
About the Role
You will lead the cybersecurity awareness and human-risk program for a federal civilian agency. You will design the curriculum, run monthly phishing exercises and lunch & learns, teach in person, and measure whether behavior actually changes. You will lead one awareness specialist.
What You’ll Do
- Assess, design and build training scenarios, approaches, objectives, plans, tools, job aids and curricula.
- Develop and revise training courses.
- Train staff through formal classroom courses, workshops and seminars, in person when the customer asks.
- Run the customer’s awareness and training program, which covers role-based training, annual awareness training, phishing and other social engineering training, and ad hoc training.
- Track, analyze and trend completion of every type of training, and report on it.
- Run monthly and ad hoc phishing and social engineering exercises, then build and analyze the reports.
- Run monthly and ad hoc cybersecurity lunch & learns, and report on attendance and feedback.
- Review the training program for gaps and recommend fixes.
- Run an annual gap analysis of the awareness program and report on its maturity.
- Administer the KnowBe4 platform: campaigns, phish-prone metrics, training assignments and reports.
- Align training with FISMA, NIST SP 800-50 and SP 800-16, and customer requirements.
- Build targeted training from incident, vulnerability and POA&M trends, and give extra training to repeat clickers and high-risk roles such as executives, privileged users and OT/manufacturing staff.
- Supervise and mentor the Awareness Journeyman.
Required Qualifications
- Bachelor’s degree in computer science, business or IT
- 8+ years leading a security awareness training program, not only delivering training
- Experience designing curricula and teaching classroom courses, workshops and seminars
- Has run phishing or social engineering simulation programs and reported their metrics
- Information security training experience under FISMA and the NIST SP 800 series
- U.S. citizen, able to pass a High Risk background investigation
- Able to work on site in Washington, DC during core hours, 8:00 AM-4:00 PM
- Requires no certification for this role.
Desired Qualifications
- KnowBe4 administration
- SANS Security Awareness Professional, CompTIA Security+, CISSP or a similar certification
- Experience with a federal role-based training program
- Behavior-change measurement: phish-prone trends, reporting rates, risk scoring
- Has trained staff in a manufacturing, OT or industrial environment
- Instructional design tools and LMS administration
- Active Tier 5 or Top Secret investigation