Position Overview: At the University of Minnesota, we are dedicated to changing lives through education, research, and outreach. The University Information Security department (UIS) offers an environment of trust, collaboration, and mission-focused work. We seek an individual who will be responsible for increasing the University communityâ™s knowledge of their information security responsibilities by maintaining and expanding our information security awareness and education efforts through training initiatives, metrics and governance.
Job Responsibilities: Security Awareness and Training:
Develop, implement, and manage a comprehensive information security awareness training program aligning with organizational policies and regulatory requirements.
Establish and track metrics to measure the effectiveness of security awareness training initiatives, tracking of participation, identifying areas for improvement, and reporting progress to leadership
Collaborate with HR, IT, and other departments to ensure security awareness training is integrated into employee onboarding, ongoing professional development, and offboarding processes.
Lead security awareness and education efforts through the development or procurement of content for educational programs
Provide consultation with University community members to improve their knowledge of information security best practices.
Stay current with emerging cybersecurity threats, vulnerabilities, and industry best practices to enhance training content.
Promote a strong security-conscious culture throughout the organization through ongoing communication and awareness campaigns.
Training Content Procurement, Development, and Delivery
Work closely with Marketing & Communication, and Training teams and subject matter experts to maintain the Information Security web content.
Manage information security awareness content within the Universityâ™s learning management system (LMS).
Create and maintain up-to-date security awareness training content that addresses current threats (e.g., phishing, social engineering, malware, ransomware) and compliance requirements (e.g., HIPAA, GDPR, PCI DSS).
Tailor training content to various audiences and roles within the organization, considering their specific security risks and responsibilities.
Research, evaluate, and recommend third-party security awareness training platforms, content providers, and courses; including role-based security training curricula specifically designed for various IT roles (e.g., developers, system administrators, network engineers) to address their unique security responsibilities and risks.
Conduct regular training sessions (in-person or virtual) for new hires and existing employees, ensuring a high level of engagement and understanding.
Please note, this position is not eligible for H-1B or Green Card sponsorship. This position does not offer a STEM OPT training program.
Required Qualifications:
Bachelorâ™s degree and 2 years of relevant work experience or a comparable combination of education, training, and experience.
Minimum of 2 years of demonstrated experience in one or more of the following:
Regulatory compliance
Risk assessment or information technology audit
Technical writing and documentation, including writing for a less technical audience
Experience with training and/or awareness program
Change management
Strong analytical and problem-solving skills.
Excellent communication (oral, written, presentation), interpersonal, and consultative skills.
Preferred Qualifications:
Proven experience in Demonstrated experience in one or more of the following:
Information Security training and/or awareness program
Working with information security regulatory frameworks (eg. ISO 27001/27002, NIST)
Data analytics, dashboarding, and developing key performance indicators (KPIs) for program effectiveness reporting.
Designing, recommending, and/or implementing information security controls
The University of Minnesota, founded in the belief that all people are enriched by understanding, is dedicated to the advancement of learning and the search for truth; to the sharing of this knowledge through education for a diverse community; and to the application of this knowledge to benefit the people of the state, the nation, and the world.