The Security Awareness Training (SAT) Engineer will work to deliver computer-based security awareness programs to third-party clients using an e-learning platform and phishing simulation tools. This role focuses on developing and managing online training solutions that help clients improve their cybersecurity posture by educating their employees on key threats, security best practices, and compliance requirements.
The ideal candidate will collaborate with clients to design tailored e-learning training programme, manage phishing simulations, and continuously assess training effectiveness.
Key Responsibilities:
- Collaborate with external clients to understand their cybersecurity awareness needs and develop customized e-learning programs.
- Design and deliver engaging, computer-based training content using e-learning platforms, including interactive modules, videos, quizzes, and assessments.
- Set up and manage phishing simulation campaigns for clients, helping them identify employee vulnerabilities.
- Analyze phishing simulation results, and provide recommendations to clients for improving their security awareness programs.
- Continuously update e-learning content to reflect the latest cybersecurity threats, vulnerabilities, and compliance standards.
- Track the effectiveness of security awareness programs through analytics, feedback, and phishing simulation performance.
- Provide ongoing support and guidance to clients in the use of the e-learning platform and phishing simulations.
- Ensure that all training content complies with industry regulations, including RMIT, ISO 27001, PDPA, Cybersecurity Act 2024, PCI-DSS and NIST.
Qualifications:
- Bachelor’s degree in Cybersecurity, Computer Science or a related field, or equivalent work experience.
- Minimum of 3 years of experience in cybersecurity training or e-learning development, ideally within a client-focused environment.
- Fresh graduates will also be considered but will start as platform engineers assisting senior SAT engineers.
- Experience managing phishing simulations and e-learning platforms for external clients.
- Strong knowledge of cybersecurity principles, including threat detection, phishing prevention, and incident response.
- Proficiency with e-learning platforms, Learning Management Systems (LMS), and phishing simulation tools.
- Understanding of security threats such as phishing, malware, social engineering, and insider threats.
- Familiarity with security compliance frameworks (RMIT, ISO 27001, NIST) and their application in training.
- Strong communication skills, with the ability to explain technical concepts clearly and concisely through written materials and online content.
- Excellent project management and organizational skills, with the ability to manage multiple client projects and deadlines.
- Analytical mindset to assess training effectiveness and refine content based on client needs and performance data.
- Self-motivated and able to work independently in a fully remote environment.
- Certifications (preferred but not required): Certified Security Awareness Practitioner (CSAP); SANS Security Awareness Professional (SSAP); Certified Information Systems Security Professional (CISSP); Certified Information Security Manager (CISM); Certified Ethical Hacker (CEH); CompTIA Security+
Job Types: Full-time, Fresh graduate
Pay: RM2,500.00 - RM5,000.00 per month
Benefits:
- Dental insurance
- Maternity leave
- Opportunities for promotion
- Professional development
Application Question(s):
- Have you administered or supported any Security Awareness Training (SAT), phishing simulation, LMS, email security, or similar SaaS platform? If yes, please state the platforms used and briefly describe your responsibilities.
- A customer launches a phishing simulation to 2,000 employees, but some users do not receive the simulated phishing email. How would you troubleshoot the issue?
- What information would you need from a new customer before setting up their Security Awareness Training and phishing simulation programme?
- Are you comfortable working directly with customers, including explaining technical requirements to their IT team, conducting onboarding sessions, troubleshooting issues, and presenting campaign results? Please provide an example of similar customer-facing work you have done.
- A phishing simulation shows that 18% of employees clicked the phishing link and 7% submitted credentials. What would you recommend the customer do next?