Information Security Education & Awareness Specialist
⚲ Sandomierz
Do uzgodnienia
Opis stanowiska
Nasze wymagania:
You have at least 3 years of experience in information or cybersecurity awareness, instructional design, or training development
You have working knowledge of key security standards and frameworks such as ISO 27001, NIST CSF, GDPR, TISAX, as well as relevant regulatory requirements
You have experience creating engaging, user focused content — such as e learning modules, emails, videos, or infographics — designed for diverse, global audiences within mid to large organizations
You have hands on experience managing awareness initiatives end to end, from planning and stakeholder engagement to execution and coordination with vendors
You communicate clearly and can simplify complex topics for non technical audiences
You work well with stakeholders and feel comfortable collaborating across different teams
You have experience in instructional design and understand how adults learn
You can create engaging multimedia learning content and work with LMS platforms
You understand key information security and risk management concepts
You use data and metrics to evaluate learning effectiveness and improve initiatives
Zakres obowiązków:
Designing, implementing, and continuously improving a comprehensive Information Security Awareness and Education Program aligned with organizational risks, threat intelligence, and business priorities
Ensuring all awareness initiatives support and align with key cybersecurity standards, including ISO/IEC 27001, NIST Cybersecurity Framework, and TISAX
Creating engaging, high quality learning materials such as e learning modules, videos, communications, and phishing simulations to enhance employee understanding of cybersecurity, data protection, privacy, and compliance requirements
Keeping all educational content current, accessible, inclusive, and culturally appropriate for a global audience
Collaborating with HR, Digital, Communications, and Compliance teams to integrate security awareness into organizational processes, onboarding, and policies
Monitoring, analyzing, and reporting on program effectiveness using defined metrics (e.g., training completion rates, phishing results) and using insights to drive continuous improvement
Delivering targeted education and communication following security incidents or audit findings to strengthen organizational resilience
Acting as a subject matter expert in security awareness, advising stakeholders on effective communication strategies and methods to reduce human related security risks
Oferujemy:
Employment contract from the first day of employment (full-time)
Base salary + quarterly bonus
Flexible working hours 7:00-9:00
After the implementation period, the possibility of hybrid work
Work from the following location: Sandomierz, Warszawa, Kraków, Skierniewice, Bydgoszcz, Szczecin, Ostrołęka, Białystok
Daily contact with English-speaking customers
Opportunity for development in the area of Information Security
Training package tailored to the scope of duties and individual competencies
Working in an international environment
You have at least 3 years of experience in information or cybersecurity awareness, instructional design, or training development
You have working knowledge of key security standards and frameworks such as ISO 27001, NIST CSF, GDPR, TISAX, as well as relevant regulatory requirements
You have experience creating engaging, user focused content — such as e learning modules, emails, videos, or infographics — designed for diverse, global audiences within mid to large organizations
You have hands on experience managing awareness initiatives end to end, from planning and stakeholder engagement to execution and coordination with vendors
You communicate clearly and can simplify complex topics for non technical audiences
You work well with stakeholders and feel comfortable collaborating across different teams
You have experience in instructional design and understand how adults learn
You can create engaging multimedia learning content and work with LMS platforms
You understand key information security and risk management concepts
You use data and metrics to evaluate learning effectiveness and improve initiatives
Zakres obowiązków:
Designing, implementing, and continuously improving a comprehensive Information Security Awareness and Education Program aligned with organizational risks, threat intelligence, and business priorities
Ensuring all awareness initiatives support and align with key cybersecurity standards, including ISO/IEC 27001, NIST Cybersecurity Framework, and TISAX
Creating engaging, high quality learning materials such as e learning modules, videos, communications, and phishing simulations to enhance employee understanding of cybersecurity, data protection, privacy, and compliance requirements
Keeping all educational content current, accessible, inclusive, and culturally appropriate for a global audience
Collaborating with HR, Digital, Communications, and Compliance teams to integrate security awareness into organizational processes, onboarding, and policies
Monitoring, analyzing, and reporting on program effectiveness using defined metrics (e.g., training completion rates, phishing results) and using insights to drive continuous improvement
Delivering targeted education and communication following security incidents or audit findings to strengthen organizational resilience
Acting as a subject matter expert in security awareness, advising stakeholders on effective communication strategies and methods to reduce human related security risks
Oferujemy:
Employment contract from the first day of employment (full-time)
Base salary + quarterly bonus
Flexible working hours 7:00-9:00
After the implementation period, the possibility of hybrid work
Work from the following location: Sandomierz, Warszawa, Kraków, Skierniewice, Bydgoszcz, Szczecin, Ostrołęka, Białystok
Daily contact with English-speaking customers
Opportunity for development in the area of Information Security
Training package tailored to the scope of duties and individual competencies
Working in an international environment
🔍 Dekoder Ogłoszenia
🟡
working knowledge of key security standards and frameworks such as ISO 27001, NIST CSF, GDPR, TISAX, as well as relevant regulatory requirements
Oczekiwana jest znajomość tych standardów, ale niekoniecznie głębokie, praktyczne wdrożenie lub audytowanie.
🟡
experience creating engaging, user focused content — such as e learning modules, emails, videos, or infographics — designed for diverse, global audiences within mid to large organizations
Może oznaczać tworzenie treści od zera, ale też adaptację lub redagowanie istniejących materiałów.
🟡
hands on experience managing awareness initiatives end to end, from planning and stakeholder engagement to execution and coordination with vendors
Może oznaczać samodzielne prowadzenie projektów, ale też koordynowanie pracy innych osób lub zespołów.
🔴
You communicate clearly and can simplify complex topics for non technical audiences
Oczekiwana jest umiejętność tłumaczenia skomplikowanych zagadnień IT na język zrozumiały dla każdego, co może być wyzwaniem.
🟡
Designing, implementing, and continuously improving a comprehensive Information Security Awareness and Education Program aligned with organizational risks, threat intelligence, and business priorities
Może oznaczać tworzenie programu od podstaw lub rozwijanie istniejącego, z naciskiem na dopasowanie do bieżących potrzeb firmy.