Overview
Reporting to the CAA Deputy CISO, this is a hands-on security leadership position working within the Information Risk Management (IRM) group and delivering solutions to the company at large. The core focus of this position is to develop and deliver the strategies, plans, and execution support for the Information Security Training and Awareness Program. This role will develop and deliver awareness and training materials through in-person sessions, online learning modules, newsletters, and email. It works closely with functional technology and business leads to align awareness deliverables with the highest risk activities and behaviors. The successful candidate will ensure the information security awareness program communicates security policies and requirements in a clear, action-oriented, and measurable manner. The position requires a self-driven individual who has mastery of security awareness, a passion for data protection, personal information security, and communications. Broad cybersecurity experience and the ability to convert technical signals into security awareness opportunities is desired. In a highly end-user centric environment the candidate must identify relevant awareness communications and distribute them promptly, and play a key role in building and supporting a defensible environment.
Responsibilities
- Lead an information security awareness program that effectively engages employees, resulting in measurable improvements in behavior.
- Partner with key teams such as Service Desk, HR Learning, privacy and compliance to develop training that supports security awareness and data protection efforts.
- Proactively identify current security events, determine applicability to CAA, and develop appropriate communications.
- Collaborate with other IRM team members to create and distribute training or awareness communication for IRM programs.
- Effectively communicate CAA policies and standards to the technology team and broader agency and cross-functional stakeholders.
- Develop and implement real-time awareness capabilities triggered at the point of risky behaviors identified in incident response or other technology workflows.
- Coordinate with CAA technology functional owners and the user community to provide solutions to reduce risk of sensitive information workflows and develop risk mitigations and training plans.
- Plan and administer information security and privacy training through online learning management systems and in-person methods.
- Prepare and deliver targeted awareness campaigns (cybersecurity month, phishing simulations, security newsletter).
- Develop and maintain metrics that measure the results of individual campaigns and overall program effectiveness.
- Play an active role in CAA's security incident response efforts, working to identify and mitigate information security threats.
Qualifications
- At least 8 years of information security experience with a bachelor degree.
- At least 3 years of experience in a security awareness function.
- Experience in a leadership or managerial position.
- Marketing or communications experience is a plus.
- Ability to communicate complex messages clearly and concisely to stakeholders at all levels.
- Excellent organizational skills and the ability to communicate with internal/external entities and executives.
- Effective leadership skills with demonstrated ability to coordinate people and teams to project/activity completion.
- Ability to work in a team environment sharing responsibilities.
- Ability to work in a flexible environment where requirements and procedures continuously evolve.
- Experience with contractual and regulatory standards such as PCI, GDPR.
- Preferred certifications in information security (CISSP, CISM, GIAC, or equivalent).
- Capable professional writer, able to research and prepare high quality, clearly written awareness and training materials.
Equal Opportunity Employer
Creative Artists Agency (CAA) is committed to promoting equal opportunities in employment and creating a workplace culture in which diversity and inclusion is valued and everyone is treated with dignity and respect. As part of our zero-tolerance approach to discrimination in any form, you and any job applicants will receive equal treatment regardless of age, disability, gender reassignment, marital or civil partnership status, pregnancy or maternity, race, colour, nationality, ethnic or national origin, religion or belief, sex or sexual orientation, or any other legally recognised protected basis under UK law.