- Company Name
- Asenium
- Job Title
- Security Awareness & Training Specialist
- Job Description
-
**Job Title:** Security Awareness & Training Specialist
**Role Summary:**
Lead the design, delivery, and continuous improvement of the organization’s cybersecurity awareness and training program. Report functionally to the GRC Team Leader and work closely with the Cybersecurity Director and GRC leadership to strengthen security culture, reduce human‑related risk, and support compliance across all business units.
**Expectations:**
- Develop and execute a comprehensive awareness strategy aligned with GRC objectives.
- Conduct engaging workshops, webinars, and communication campaigns in English (and French if needed).
- Measure program effectiveness through key metrics and drive iterative improvements.
- Foster an active internal cybersecurity community.
**Key Responsibilities:**
- Create, launch, and manage ongoing phishing, smishing, and social‑engineering simulation campaigns.
- Produce diverse learning content (presentations, infographics, short videos) using tools such as Canva, PowerPoint, CapCut, Storyline/Articulate.
- Analyze training data (click‑through rates, completion rates, risk segmentation) to identify high‑risk groups and tailor interventions.
- Maintain and nurture a corporate cybersecurity community of practice.
- Collaborate with IT, HR, and business units to embed security best practices (password hygiene, MFA, secure collaboration tools).
- Track and report awareness KPIs to senior leadership; recommend enhancements.
- Support risk assessments using the EBIOS RM methodology and, where applicable, operate GRC platforms (e.g., TENACY).
**Required Skills:**
- Strong knowledge of common cyber threats: phishing, smishing, ransomware, shadow IT, etc.
- Solid understanding of security best practices (password management, MFA, digital hygiene).
- Excellent written and verbal communication; ability to simplify complex concepts.
- Proven content‑creation skills (Canva, advanced PowerPoint, basic video editing).
- Data‑analysis capability for training metrics and risk segmentation.
- Experience with cyber risk management (EBIOS RM) and familiarity with GRC tools (TENACY a plus).
- High level of organization, autonomy, and ability to manage multiple initiatives simultaneously.
- Team‑player with strong stakeholder‑engagement skills.
- Proficient in English (both written and spoken); French advantageous.
**Required Education & Certifications:**
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, or a related field (or equivalent professional experience).
- Relevant certifications are a plus (e.g., CISSP, CISM, CIPP, CompTIA Security+, Certified Information Privacy Professional).
- Additional training‑design certifications (e.g., ATD, Learning Experience Designer) considered advantageous.