Full Job Description
Overview
How you can make a difference
As Senior Manager, Security Awareness & GRC, you will lead HealthEquity’s enterprise human risk management and security culture strategy. This role turns complex cybersecurity, fraud, privacy, compliance, and AI governance topics into clear, engaging, behavior-focused programs that help teammates recognize risk, make safer decisions, and protect our members, clients, partners, and business.
You will own the strategy, execution, measurement, and continuous improvement of enterprise security awareness programs, including phishing simulations, required training, teammate targeted education, new hire onboarding, executive messaging, internal and external security campaigns, and targeted communications for high-risk behaviors or emerging threats. You will partner closely with Security, GRC, Fraud, Privacy, Legal, HR, Marketing, Product Security, IT, and executive leadership to ensure security expectations are understood, actionable, and embedded into how work gets done.
This role requires a strategic communicator, program builder, creative campaign designer, and cross-functional influencer who can connect risk, behavior, culture, and business outcomes. You will create scalable awareness experiences, advise leaders on human risk trends, support audit and regulatory expectations, manage vendor and platform relationships, and use data to continuously strengthen HealthEquity’s security culture.
What you’ll be doing
3 Drive continuous improvement efforts by identifying opportunities for enhancing security governance, risk management, and compliance practices.
3 Drive HealthEquity’s enterprise security awareness and human risk management strategy, aligning teammate education, behavioral risk reduction, annual compliance expectations, and security culture priorities.
3 Design, launch, and continuously improve enterprise campaigns that drive measurable behavior change, including Cybersecurity Awareness Month, Internet Safety Month, Fraud Awareness Week, phishing awareness, AI governance education, and emerging threat communications.
3 Lead the creative development of security awareness campaigns, including campaign themes, visual concepts, messaging frameworks, presentation materials, social and intranet graphics, videos, newsletters, recognition assets, and teammate-facing engagement experiences.
3 Own the strategy and execution of phishing simulation programs, targeted learning, reporting workflows, reinforcement messaging, and recognition programs that encourage timely reporting and safer decisions.
3 Work with third party partners to create and maintain a range of security awareness educational materials, including e-learning modules, newsletters, posters, and videos, tailored to different audiences.
3 Establish metrics to assess the effectiveness of the security awareness program, including pre- and post-training evaluations, incident reports, and employee feedback.
3 Contribute in development and implementation of security metrics and key performance indicators (KPIs) to measure the effectiveness of security controls, risk mitigation strategies, and compliance efforts. Regularly analyze and report on security metrics to senior management, identifying trends, areas of improvement, and actionable insights.
3 Work closely with Security, IT, Fraud, Product, HR, Marketing, Legal, Privacy, and other departments to integrate security awareness into existing training and onboarding processes.
3 Ensure that security policies and procedures are effectively communicated and understood throughout the organization.
3 Collaborate with the Security Operations Center to provide guidance and support during security incidents, helping to educate employees on the importance of reporting suspicious activities.
3 Collaborate with security engineering organization to effectively identify and implement relevant tools and technologies to support the end to end human risk management of security awarness.
3 Lead through influence across cross-functional partners, balancing strategic program ownership with hands-on execution in a fast-paced, highly regulated environment.
3 Stay current on security threats, social engineering trends, AI risk, regulatory expectations, and awareness best practices to keep programs relevant, timely, and effective.
3 Advise leadership on human risk trends, communication risks, adoption barriers, and opportunities to improve security behavior across the enterprise.
3 Manage and mentor a team of security awareness specialists, fostering a collaborative and innovative environment.
3 As needed, participate in comprehensive risk assessments and vulnerability analyses to identify potential security risks and recommend appropriate mitigation strategies. This will require leading and influencing cross-functional teams and stakeholders at all levels of the company.
3 Manage identification and rollout of scalable innovative technologies to support security governance, including developing usage policies and guidelines, audit, and control processes.
3 Other duties as assigned.
What you will need to be successful
Education and Experience:
3 Bachelors Degree, in information security, information technology, communications, marketing, education, instructional design, psychology, behavioral science, business, or related discipline is preferred. Equivalent experience in security awareness, human risk management, change management, communications, or enterprise program leadership may be considered.
3 7+ years of professional experience in security awareness, human risk management, information security GRC, IT compliance, IT audit, privacy, legal, communications, marketing, education, instructional design, change management, or enterprise program leadership, preferably in a technology setting or highly regulated industry.
Specialized Knowledge, Skills, and Abilities:
3 Proven experience leading enterprise security awareness, human risk management, or security culture programs in a regulated environment.
3 Strong ability to translate technical, regulatory, and risk concepts into clear business and teammate-facing communications.
3 Experience designing behavior-focused campaigns, executive communications, training programs, newsletters, videos, intranet content, and internal engagement strategies.
3 Strong creative direction skills, including the ability to turn complex security, fraud, privacy, compliance, and AI governance topics into memorable campaign themes, branded visuals, executive-ready materials, and teammate experiences that drive action.
3 Experience using phishing simulation data, training metrics, reporting trends, and engagement insights to measure program effectiveness.
3 Experience with O365 applications (Word, PowerPoint, Excel).
3 Additional Education/Certification preferred but not required, e.g. CIPP or CIPM, CDPSE, CISSP, CISM, CISA, CCSA.
3 Experience interacting with and working directly with/for internal/external business partners.
3 Able to work collaboratively in a fast-paced technology environment, where willingness to learn and adapt is critical.
3 Strong level of knowledge in at least one of industry standards and best practices such as SOC1, SOC2 Type II, ISO/IEC 27001 Certification, HIPAA Compliance, HITRUST, and PCI/DSS.
3 Strong understanding of social engineering, phishing, data protection, AI governance, privacy, fraud risk, incident reporting, and secure behavior principles.
3 Ability to operate independently, prioritize competing requests, and drive large-scale programs with limited resources.
3 Excellent storytelling, change management, and stakeholder communication skills.
3 Experience influencing others to take action.
Certifications, Licenses, Registrations:
CompTIA CYSA or comparable certification
#LI-Remote
This is a remote position.
Salary Range$120500.00 To $157000.00 / year
Benefits & Perks
The actual compensation offer is determined based on job-related knowledge, education, skills, experience, and work location. This position will be eligible for performance-based incentives as part of the total compensation package, in addition to a full range of benefits including:
3 Medical, dental, and vision
3 HSA contribution and match
3 Dependent care FSA match
3 Uncapped paid time off
3 Paid parental leave
3 401(k) match
3 Personal and healthcare financial literacy programs
3 Ongoing education tuition assistance
3 Gym and fitness reimbursement
3 Wellness program incentives
Onboarding & Travel
This is a remote role, with an in-person onboarding training component. New team members must participate in Trailhead, HealthEquitys immersive onboarding experience Trailhead is designed to foster meaningful connections, support your integration into the organization, and equip you with a strong understanding of our business. Trailhead participation is a key expectation of this role. Trailhead is held onsite at our headquarters once per quarter. HealthEquity covers all required travel and accommodations.
This role may begin with a virtual, self-paced onboarding experience, followed by a mandatory onsite Trailhead session at a later date.