Cybersecurity Training Specialist
BuzzClan
Job Description
Position: Security Communications And Training Specialist
Location: Calgary, AB (Hybrid)
Contract (Initial term of 9+ month with possibility of extension)
Role summary:
The Social Engineering Lead is responsible for establishing and leading enterprise human risk reduction capability. This role defines the strategy, operating model, and measurement of a scalable, intelligence-driven Social Engineering Program that integrates multi-channel simulation, targeted awareness, and executive-level risk insight. The role addresses rapidly evolving, AI-enabled threats by strengthening employee decision-making, reducing human-driven risk, and enabling data-driven visibility into organizational security behavior.
Qualifications:
- Strong experience in social engineering, security awareness, cybersecurity and risk management.
- Proven ability to design and scale enterprise programs and operating models.
- Strong analytical skills with the ability to interpret behavioral data and translate insights into action.
- Excellent communication skills, including the ability to distill complex threats into clear, executive-level messaging.
- Experience working across multiple stakeholders and teams in a complex, fast-paced environment.
Program Strategy & Capability Development:
- Establish and mature an enterprise-wide human risk reduction capability aligned to evolving threat landscapes.
- Define and implement the Social Engineering Program strategy, operating model, and governance framework.
- Standardize program design, execution, and measurement across Enterprise Security and supporting teams.
- Continuously evolve program capabilities to address emerging threats, including AI-enabled and multi-channel attacks.
Simulation Design & Execution:
- Lead end-to-end planning and execution of social engineering simulations across phishing, vishing, smishing, and emerging channels (e.g., deepfakes).
- Develop realistic, role-based scenarios reflecting current attacker techniques and business-relevant risks.
- Ensure simulations are intelligence-driven, risk-based, and aligned to organizational priorities.
Program Operations & Coordination:
- Coordinate day-to-day delivery of simulation activities across tools, vendors, and internal stakeholders.
- Ensure consistency, quality, and compliance with enterprise standards, policies, and processes.
- Drive efficiency and scalability through standardized execution models and vendor alignment.
- Evaluate any related incidents and ensure proper reporting and remediations are incorporated into social engineering or other relevant programs
Awareness & Behavior Reinforcement:
- Integrate simulation outcomes with targeted awareness and training initiatives to drive behavior change.
- Support development of focused interventions for high-risk user groups and behaviors.
- Reinforce a culture of security awareness through continuous, real-world exposure to threats.
Metrics, Analytics & Reporting:
- Develop and maintain standardized metrics to measure human risk, program performance, and behavioral trends.
- Analyze simulation data (e.g., click rates, reporting behavior, response patterns) to generate actionable insights.
- Deliver executive-level reporting and dashboards that provide clear visibility into human risk across the enterprise.
- Improve the quality, consistency, and reliability of human risk data for decision-making.
Stakeholder & Cross-Functional Alignment:
- Partner with Detection & Response, Privacy, HR, and Corporate Communications to align simulations with incident response, policy, and messaging.
- Engage stakeholders across the organization to embed program objectives and drive adoption.
- Provide subject matter expertise on social engineering risk to leadership and enterprise partners.