About the Role
In this position, you will have the opportunity to build a cybersecurity culture across the organization, ensuring that cybersecurity is prioritized by all employees and leadership. You will design and implement awareness programs, training, and communication strategies while engaging executives and senior leaders. Your role will involve measuring the effectiveness of these initiatives through various metrics and ensuring alignment with compliance requirements.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Key Responsibilities
- Build a Cybersecurity Culture:
- Promote a sense of cybersecurity ownership across the workforce, emphasizing shared responsibility.
- Advocate for a cybersecurity-first mindset in daily operations.
- Collaborate with executives and senior leaders to provide visibility and active participation in security initiatives.
- Assess and report on cybersecurity culture over time.
- Design the Awareness Programme:
- Create a comprehensive cybersecurity awareness and training strategy tailored to different audiences.
- Develop and maintain awareness policies, procedures, and training rules.
- Conduct audience analyses to identify risks and preferred communication channels.
- Design Tabletop Exercises and Campaigns:
- Plan and execute realistic cybersecurity tabletop exercises for various teams, focusing on common threats like ransomware and data breaches.
- Facilitate these exercises, document lessons learned, and track improvement actions.
- Create engaging content in both Arabic and English for awareness campaigns and materials.
- Organize events to foster cybersecurity awareness.
- Deliver Role-Based Training:
- Develop and provide role-specific training for various staff groups, including new joiners and contractors.
- Manage the training content and track progress using the learning management system (LMS).
- Conduct live sessions and workshops.
- Communication:
- Disseminate security advisories during active threats in collaboration with the SOC and Corporate Communications.
- Regularly update staff on the cybersecurity program's progress and significance.
- Test and Measure Behavior:
- Implement phishing, smishing, and vishing simulations to assess and improve employee awareness.
- Analyze and report on behavioral changes and program outcomes.
- Work Across the Organization:
- Collaborate with HR for training and onboarding initiatives.
- Partner with Corporate Communications on messaging and branding.
- Develop a network of security champions to promote a culture of security across various departments.
Leadership Capabilities
- Comprehensively understand and embody the organization’s purpose and values, effectively seeking opportunities for impact.
- Show a strong commitment to personal development and help attract top talent as a brand ambassador.
- Take personal responsibility for performance and progress tracking.
- Focus on enhancing communication and relationship-building skills.
- Relate daily work to team and business objectives.
Qualifications
- 3-7 years of professional experience.
- Bachelor’s degree in communications, cybersecurity, IT, education, or a related field.
- Experience in designing and running security awareness programs and phishing simulations is ideal for senior candidates; delivering training campaigns is important for mid-level candidates.
- Familiarity with conducting cybersecurity tabletop exercises.
- Excellent writing and content creation abilities in both Arabic and English.
- Strong understanding of cyber threats and compliance requirements.
- Confident presentation skills for diverse audiences.
- Experience with phishing simulation platforms and LMS administration.
- Ability to measure security culture through surveys and behavior metrics.
- Proficient in content design (e.g., Canva, Adobe) and video editing.
- Background in behavioral science or adult learning is a plus.
- Proficiency in Arabic is advantageous.
- Relevant certifications (e.g., SANS Security Awareness Professional, CompTIA Security+, CISM) are valued.
- Knowledge of relevant frameworks (e.g., NCA ECC-2:2024, NIST guidelines, ISO/IEC standards) is beneficial.