
## Position Overview
We are seeking a **Security Awareness & Compliance Analyst** to support enterprise cybersecurity Governance, Risk, and Compliance (GRC) initiatives. This role will be responsible for administering and enhancing the organization's Security Awareness Program, coordinating phishing simulation campaigns, analyzing security awareness metrics, supporting compliance and audit activities, and developing cybersecurity education and communication materials.
The ideal candidate will have hands-on experience with **security awareness programs, phishing simulations, cybersecurity training, compliance documentation, metrics/reporting, and GRC activities**. This position requires strong communication, analytical, organizational, and stakeholder management skills.
## Key Responsibilities
* Administer and maintain an enterprise-wide **Security Awareness Program**.
* Plan, coordinate, execute, and monitor **phishing simulation campaigns**.
* Track and analyze phishing campaign results, employee participation, training completion rates, and other security awareness metrics.
* Prepare dashboards, reports, and presentations highlighting security awareness trends and program effectiveness.
* Develop and distribute cybersecurity awareness communications, educational materials, newsletters, alerts, and training content.
* Coordinate required cybersecurity awareness and compliance training across the organization.
* Maintain program documentation, training records, campaign results, and supporting evidence for compliance and audit purposes.
* Assist with preparation of reports and documentation for regulatory requirements, internal and external audits, and management reviews.
* Identify trends and recommend improvements to security awareness initiatives based on metrics, emerging cybersecurity threats, and industry best practices.
* Support broader **Governance, Risk, and Compliance (GRC)** initiatives as needed.
* Work with business and technical stakeholders to promote cybersecurity awareness and strengthen the organization's security culture.
* Participate in continuous improvement activities supporting the overall cybersecurity and information security program.
* Perform additional information security and compliance-related responsibilities as assigned.
## Required Qualifications
* Professional experience administering or supporting an enterprise **Security Awareness Program**.
* Hands-on experience planning and executing **phishing simulation campaigns**.
* Experience with security awareness or phishing simulation platforms such as **KnowBe4, Proofpoint, Cofense, Microsoft Attack Simulation Training, Mimecast, or similar tools**.
* Experience developing cybersecurity awareness communications and educational/training materials.
* Experience tracking and analyzing security awareness and phishing-related metrics.
* Knowledge of cybersecurity fundamentals and information security awareness principles.
* Experience maintaining documentation and evidence in support of **compliance and audit requirements**.
* Experience assisting with regulatory, audit, compliance, or management reporting.
* Understanding of **Governance, Risk, and Compliance (GRC)** concepts and practices.
* Strong analytical skills with the ability to identify trends and translate data into actionable recommendations.
* Strong written and verbal communication skills.
* Ability to communicate cybersecurity concepts effectively to both technical and non-technical audiences.
* Strong organizational skills with the ability to coordinate multiple campaigns, projects, and training activities simultaneously.
* Ability to establish productive working relationships with employees, leadership, technical teams, and other stakeholders.
## Preferred Qualifications
* Experience working within an enterprise, government, healthcare, financial services, or other regulated environment.
* Experience supporting cybersecurity audits, risk assessments, or regulatory compliance initiatives.
* Familiarity with common cybersecurity frameworks and standards such as **NIST, CIS Controls, ISO 27001, or similar frameworks**.
* Experience developing dashboards, executive reports, or security program metrics.
* Relevant cybersecurity, security awareness, risk, compliance, or information security certifications are a plus.
## Ideal Candidate
The ideal candidate combines **cybersecurity knowledge with strong communication and program management skills**. This person should be comfortable running phishing campaigns, analyzing results, developing engaging cybersecurity awareness content, maintaining compliance documentation, and communicating security risks and recommendations to a diverse audience.
This is an excellent opportunity for an information security professional interested in working at the intersection of **Cybersecurity Awareness, Governance, Risk, Compliance, Training, and Security Program Management**.
## Work Requirements
Candidates must be able to work a **hybrid schedule consisting of three days onsite per week in Harrisburg, PA and two days remotely**.
Candidates must also comply with applicable information security and government equipment requirements, including restrictions regarding the use or transportation of government-issued equipment outside the United States.

Since 1995, FutureSoft Consulting Inc. has provided strategic IT Consulting and Staff Augmentation to Fortune 5000 and Inc. 5000 companies. Our expertise spans cloud, cybersecurity, AI, DevOps, and enterprise applications, supported by AI-driven solutions and a one-week performance guarantee.
With nearly 30 years of proven experience, we are a trusted partner helping enterprises reduce costs, accelerate innovation, and achieve digital transformation.