View All Jobs

Human Risk Manager / Cybersecurity Awareness Professional SME

REMOTE | AssurIT
  • Apply
Job Description

Human Risk Manager / Cybersecurity Awareness Professional SME

Location: On site, Washington, DC

About the Role

You will lead the cybersecurity awareness and human-risk program for a federal civilian agency. You will design the curriculum, run monthly phishing exercises and lunch & learns, teach in person, and measure whether behavior actually changes. You will lead one awareness specialist.

What You’ll Do

  • Assess, design and build training scenarios, approaches, objectives, plans, tools, job aids and curricula.
  • Develop and revise training courses.
  • Train staff through formal classroom courses, workshops and seminars, in person when the customer asks.
  • Run the customer’s awareness and training program, which covers role-based training, annual awareness training, phishing and other social engineering training, and ad hoc training.
  • Track, analyze and trend completion of every type of training, and report on it.
  • Run monthly and ad hoc phishing and social engineering exercises, then build and analyze the reports.
  • Run monthly and ad hoc cybersecurity lunch & learns, and report on attendance and feedback.
  • Review the training program for gaps and recommend fixes.
  • Run an annual gap analysis of the awareness program and report on its maturity.
  • Administer the KnowBe4 platform: campaigns, phish-prone metrics, training assignments and reports.
  • Align training with FISMA, NIST SP 800-50 and SP 800-16, and customer requirements.
  • Build targeted training from incident, vulnerability and POA&M trends, and give extra training to repeat clickers and high-risk roles such as executives, privileged users and OT/manufacturing staff.
  • Supervise and mentor the Awareness Journeyman.

Required Qualifications

  • Bachelor’s degree in computer science, business or IT
  • 8+ years leading a security awareness training program, not only delivering training
  • Experience designing curricula and teaching classroom courses, workshops and seminars
  • Has run phishing or social engineering simulation programs and reported their metrics
  • Information security training experience under FISMA and the NIST SP 800 series
  • U.S. citizen, able to pass a High Risk background investigation
  • Able to work on site in Washington, DC during core hours, 8:00 AM-4:00 PM
  • Requires no certification for this role.

Desired Qualifications

  • KnowBe4 administration
  • SANS Security Awareness Professional, CompTIA Security+, CISSP or a similar certification
  • Experience with a federal role-based training program
  • Behavior-change measurement: phish-prone trends, reporting rates, risk scoring
  • Has trained staff in a manufacturing, OT or industrial environment
  • Instructional design tools and LMS administration
  • Active Tier 5 or Top Secret investigation
Skills & Requirements Qualifications