Dow Jones

GRC Training and Awareness Manager

Dow Jones$125K — $145K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in Cyber Security, Technology Risk, or GRC fields with emphasis on Training and Awareness
  • Demonstrated experience in cyber governance, risk, and compliance in complex environments
  • Strong working knowledge of industry frameworks such as NIST CSF, PCI-DSS, and ISO 27001
  • Exceptional communication skills to convey complex cyber risks to varied stakeholders
  • Ability to manage multiple projects and improve processes proactively
  • Experience with security awareness platforms like KnowBe4 or PhishMe
  • Proven skills in content creation and employee communication.

Responsibilities

  • Drive the global cybersecurity awareness program and develop training materials
  • Ensure training content is aligned with regulatory requirements and evolving threats
  • Create and refresh cybersecurity awareness materials in collaboration with various teams
  • Lead phishing simulation programs and analyze metrics for improvement
  • Design targeted training for high-risk user groups based on their specific threats
  • Educate employees on global data protection laws and privacy requirements
  • Manage relationships with external vendors for security awareness tools.

Benefits

  • Collaborative and innovative global work environment
  • Opportunity to pioneer new culture and compliance integration methods
  • Variety of work with exposure to global operations and teams
  • Comprehensive benefits package covering health, retirement, and wellbeing options
  • Flexible compensation to attract top talent.
Full Job Description

Job Description :

Position: Cybersecurity - GRC Training and Awareness Manager

Location: Lawrenceville NJ

Type : Hybrid 3 days a week in office

Salary Range: $125,000 - $145,000 + Bonus

About the Role

We are looking for a dynamic Cyber Security Training and Awareness Manager to bridge the human element of Cybersecurity with the requirements of our global Cyber Governance, Risk, and Compliance (GRC) program.

You will lead our cybersecurity awareness initiatives while simultaneously serving as a key contributor to the maintenance and maturity of our global GRC framework.

This role requires a unique balance of communication and engagement skills to influence security culture, combined with the analytical rigor required to collaboratively support the management of cyber risks, compliance requirements, and cyber policies & standards.

What You Will Do

Security Awareness Program Leadership:

Drive the global cyber security awareness program, including the annual development, review, and promotion of training materials and training roadmap.

Ensure training content remains current and aligned with the evolving threat landscape (e.g., AI/Emerging threats, Social Engineering, Phishing), company policies & standards, and varying regulatory requirements (e.g., PCI-DSS, SOX, SOC TypeII, NIST CSF).

Lead the creation, sourcing, and annual refresh of cyber awareness materials, partnering closely with our global Cyber Security, Compliance, Legal, Privacy, and BISO teams to ensure our content continuously adapts to evolving threats while remaining impactful and engaging.

Lead the organization's phishing simulation program by running a regular schedule of company wide phishing tests, creating specialized targeted campaigns for high risk teams. Generate and analyze actionable metrics to shape future security awareness and training initiatives.

Design and deploy targeted role based training and awareness content for high impact user groups (including Executive Leadership, Executive Assistants, Finance, HR, Developers, and Privileged Users) to directly address their specific risk profiles, data access levels, and unique threat landscapes specific to their role.

Partner with the Legal, Privacy, and Data teams to educate the broader workforce on the complex landscape of global data protection and privacy laws.

Transform actionable insights from daily cyber threat intelligence briefings into timely, targeted awareness communications, ensuring employees are briefed on emerging threats (e.g., active phishing campaigns, new malware strains) relevant to their specific regions and roles.

Manage relationships with external security awareness and GRC tool vendors, ensuring that platforms are effectively configured, license utilization is optimized, and roadmap features are aligned with News Corp’s internal security objectives.

GRC Program Support:

Support the maintenance of the News Corp Global Cyber GRC Program, including the support of cyber risks and compliance exceptions.

Collaboratively support the review and implementation of cybersecurity standards, guidelines, and processes to ensure compliance across the business.

Support the management of the lifecycle of security-focused documentation, including the review and approval of Knowledge Base (KB) articles and security standards, ensuring content is accurate, up-to-date, and accessible to global support teams.

Support the operationalization of security policies & standards by monitoring for deviations, investigating non-compliant activities, and delivering direct guidance to end-users to ensure adherence to corporate security policies & standards.

Compliance & Reporting:

Support internal and external stakeholders for compliance requirements (PCI DSS, NIST CSF, SOX, and Privacy).

Support the development and maintenance of key performance indicators (KPIs) that effectively track cybersecurity posture and awareness campaign metrics.

Support and review cyber risk assessments and cyber control assurance in collaboration with global technology and cyber team members.

Who You Are

You have 10+ years within Cyber Security, Technology Risk, or GRC-related fields with a specific focus on Cyber Training and Awareness.

You have demonstrated experience in cyber governance, risk, and compliance in dynamic and complex business environments.

You have a strong working knowledge of industry frameworks such as NIST CSF, PCI-DSS, , and ISO 27001.

You have exceptional communication skills with the ability to translate complex cyber risks and compliance obligations into actionable language for business stakeholders, technical SME teams, and executives.

You have the ability to work autonomously, manage multiple projects simultaneously, and take a proactive approach to continuous improvement.

You have strong critical-thinking skills with a pragmatic viewpoint on interpreting regulations and implementing security controls.

Experience with security awareness and phishing platforms (e.g., KnowBe4, PhishMe, Abnormal Security).

Proven experience in content creation, instructional design, or employee communication.

Familiarity with Learning Management Systems (LMS) administration.

Preferred Certifications

CRISC (Certified in Risk and Information Systems Control)

CISM (Certified Information Security Manager)

CGEIT (Certified in the Governance of Enterprise IT)

AI GRC Professional Certification

CompTIA Security+

What’s in it for You?

A collaborative and innovative global work environment.

The opportunity to challenge the norm and pioneer new ways of integrating culture with compliance.

Variety of work where no two days are the same, with exposure to global operations and teams.

Base Pay Range: $125,000 - $145,000 + Bonus

We’re committed to offering competitive and flexible compensation to attract top talent. This pay range reflects our good faith estimate for the role and may vary based on a candidate’s experience, skills, location, and other relevant factors.

For bonus-eligible roles, targets are determined based on multiple considerations, including market benchmarks and individual contributions.

For benefits-eligible roles, we offer a comprehensive and competitive benefits package covering health, retirement, wellbeing, and more, along with optional benefits to meet the diverse needs of our employees.

About Dow Jones

Dow Jones is a global provider of news and business information, delivering content to consumers and organizations around the world across multiple formats, including print, digital, mobile and live events. Dow Jones has produced unrivaled quality content for more than 130 years and today has one of the world?s largest news gathering operations globally. It produces leading publications and products including the flagship Wall Street Journal, America?s largest newspaper by paid circulation; Factiva, Barron?s, MarketWatch, Mansion Global, Financial News, Dow Jones Risk & Compliance, Dow Jones Newswires, and Dow Jones VentureSource.
Learn more about Dow Jones
Size
7,800 employees
Industry

Similar Jobs

More Jobs at Dow Jones

More Information Technology Jobs

Find similar GRC Training and Awareness Manager jobs: