InfoSec Awareness & Engagement Lead - Banking
Xenon7
Employer Active
Posted 17 hrs ago
Send me Jobs like this
Nationality
Any Nationality
Gender
Not Mentioned
Vacancy
1 Vacancy
Job Description
Roles & Responsibilities
This role is responsible for designing, building, and running information security awareness and engagement
programme from the ground up. It is not a content creation role. It is a programme lead role combining
marketing strategy, internal communications, vendor management, and behavioural change to shift the security
culture across the bank. The lead owns the full programme: strategy, calendar, content, delivery, vendor sourcing,
measurement, and executive reporting.
Key Responsibilities:
A. Programme Strategy & Design
Design a holistic, annual InfoSec Awareness Programme covering all staff segments branch
employees, operations, technology, management, and executives.
Segment the audience and tailor content and delivery methods per segment: role-based risks, language
level, digital literacy, and regulatory obligations.
Apply behavioural science principles (nudge theory, social proof, loss aversion) to design campaigns that
change behaviour, not just increase awareness scores.
Map programme activities to security pillars, CBE Cybersecurity Framework culture requirements, and
PCI DSS awareness obligations.
Define programme KPIs: phishing simulation click rates, training completion rates, awareness survey
scores, and reported incident rates by staff.
B. Communication & Marketing Execution
Produce and distribute security awareness communications across channels: email newsletters, intranet,
digital signage, branch posters, and leadership messages.
Write copy and design briefs that translate technical security concepts into plain, compelling business
language Arabic and English.
Partner with Marketing function to ensure awareness materials align with the bank's brand guidelines and
STEP strategy visual identity.
Build and maintain an annual awareness calendar aligned to global events (Cybersecurity Awareness
Month, Safer Internet Day, World Password Day) and internal milestones.
C. Interactive Activities & Vendor Management
Source, evaluate, and manage vendors delivering awareness platform services (e.g., KnowBe4,
Proofpoint Security Awareness, Terranova, or equivalent).
Design and run phishing simulation campaigns: configure scenarios, set difficulty progression, manage
employee follow-up training, and report results.
Deliver interactive awareness sessions including workshops, tabletop scenarios, gamified learning,
escape room formats, and lunch-and-learn events.
Organise executive and board-level awareness sessions tailored to cyber risk and governance these
require different content and delivery than general staff campaigns.
Manage vendor SLAs, budgets, and delivery quality for all third-party awareness service providers.
D. Measurement & Reporting
Track programme performance metrics monthly: training completion, phishing click rates, awareness
survey results, and engagement channel reach.
Report quarterly to the Head of Engagement and CISO with trend analysis, benchmark comparisons
(industry and Egyptian banking sector), and programme adjustments.
Feed phishing click rate KRI data into the InfoSec KRI dashboard for board-level risk reporting.
Conduct an annual security culture survey and produce a report with year-on-year trend and action plan.
Desired Candidate Profile
Minimum 6 years of experience across information security, internal communications, or digital marketing
with at least 3 years specifically in security awareness programme management.
Proven track record designing and running a security awareness programme in a financial institution
must be able to show measurable outcome improvements (e.g., phishing click rate reduction, training
completion uplift).
Strong Arabic and English written communication skills content writing is a core part of this role.
Experience managing awareness platform vendors and phishing simulation tools.
Understanding of PCI DSS Requirement 12.6 (security awareness education) and CBE
culture/awareness obligations.
Preferred Certifications
SANS Security Awareness Professional (SSAP)
CompTIA Security+ or equivalent foundational security qualification
CIM Certificate/Diploma in Professional Marketing or equivalent marketing qualification
Preferred Experience
Experience in Egyptian banking or Arabic-language corporate communication environments.
Familiarity with KnowBe4, Proofpoint Security Awareness Training, or Terranova platforms.
Experience delivering executive and board-level security briefings.
Background in instructional design or adult learning principles.
Company Industry
- Internet
- E-commerce
- Dotcom
Department / Functional Area
- Finance
- Treasury
Keywords
- InfoSec Awareness & Engagement Lead - Banking
Disclaimer: Naukrigulf.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@naukrigulf.com
Similar Jobs
InfoSec Compliance & Assurance Lead - Banking
Xenon7
- 3 - 6 Years
- Cairo - Egypt
Technical Lead – Wealth, Trading & Brokerage
Dicetek LLC
- 3 - 5 Years
- Abu Dhabi - United Arab Emirates (UAE)
Technical Lead Infrastructure (Banking)
VaporVM
- 4 - 6 Years
- Dubai - United Arab Emirates
Cybersecurity Training & Awareness Specialist /Cybersecurity Awareness
BAE Systems Strategic Aerospace Services WLL, a limited liability company
- 5 - 10 Years
- Doha - Qatar
Security Apps Lead
Dimension Data / NTT ltd
- 1 - 7 Years
- Riyadh - Saudi Arabia