Cybersecurity Awareness Program Specialist
Job Description
This hybrid role focuses on strengthening cybersecurity awareness, supporting incident readiness, and helping drive compliance and third-party risk processes.
Responsibilities
- Develop and deliver cybersecurity education programs and internal communications for team members and subcontractors, enabling recognition of cyber threats, safe handling of sensitive data, and understanding of industry compliance requirements
- Design and implement cybersecurity awareness and education content for a hybrid workforce, including subcontractors and corporate staff (examples include short videos)
- Run regular phishing simulations and provide follow-up education based on results to improve awareness and response to social engineering attacks
- Monitor and respond to security threats and incidents
- Keep pace with evolving cyber threats affecting the insurance environment, including attacks on project management tools, supply chain risks, and mobile device vulnerabilities
- Lead training sessions and workshops on cybersecurity topics
- Analyze security data and create reports for senior management covering risks and potential opportunities
- Research and evaluate emerging technologies and provide recommendations for implementation
- Identify improvement opportunities and recommend changes to support compliance with security standards
- Assist in development and enforcement of security policies and procedures
- Partner with IT and business units to support secure system configuration
- Develop and support ongoing security awareness program activities
- Monitor and track remediation efforts for non-compliance issues, including managing policy exceptions and tracking policy violations to support timely resolution
- Support the Third-Party Risk Management (TPRM) program by conducting vendor risk assessments, reviewing security documentation, using tools such as Viso Trust, and collaborating with stakeholders across the vendor lifecycle
- Develop and implement policies and procedures to ensure alignment with security standards
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field
- 3+ years of experience in information security or IT operations
- Familiarity with security frameworks, such as NIST and ISO 27001
- Strong analytical and problem-solving skills
Technologies & Frameworks
- NIST
- ISO 27001
- Viso Trust
- HIPAA
- PCI-DSS
- NYDFS
Hybrid Work Location
- Hybrid role working from the West Trenton, NJ office 3 days per week and from home 2 days per week
- Work location: Hybrid remote in Ewing, NJ 08628
Compensation
- $104,686 - $131,986 per year
Preferred Qualifications
- Security certifications such as CompTIA Security+, GIAC, or SSCP
- Exposure to regulatory compliance, including HIPAA, PCI-DSS, and NYDFS
- Experience with security awareness tools