Information Security Awareness Lead

Unipharmedtech

Uxbridge

Hybrid

GBP 70,000 - 90,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Uniphar is seeking an Information Security Awareness Lead to own and drive our security awareness programme across regions and divisions. You will engage employees through training, phishing simulations, communications campaigns, and behavioural testing while tracking performance and driving improvements.

Collaborate with Information Security, IT, HR and Communications to deliver effective initiatives, manage the Proofpoint platform, and deliver role-specific training to high-risk functions.

Qualifications

  • Minimum 5 years’ experience in IT, Information Security, learning development or related role.
  • Proven experience delivering security awareness, training, or behavioural risk programmes.
  • Strong understanding of phishing, social engineering, and human-centric cyber risks.
  • Experience managing awareness platforms and learning delivery tools.

Responsibilities

  • Own and manage the phishing testing programme, including regular phishing simulations.
  • Deliver monthly security awareness induction training for all new starters.
  • Lead awareness campaigns, including the organisation’s October Security Awareness Month; plan, execute quizzes, games, and surveys.
  • Collaborate with IT, SecOps and HR to localise delivery and track performance metrics.
  • Design, deploy and sustain role-specific training for high-risk functions.

Skills

Information Security
Security awareness
Learning development
Phishing awareness

Tools

Proofpoint Security Awareness Platform
Workday
PhishAlarm

Job description

Locations

Citywest, Dublin, Ireland or Stockley Park, Uxbridge, UK

The Role

The Information Security Awareness Lead will own and drive Uniphar’s security awareness programme, helping reduce human-related cyber risk through engaging training, phishing simulations, communications campaigns, and behavioural testing. The role will work with Information Security, IT, HR, Communications, and business teams to deliver effective awareness initiatives, track programme performance, and continuously improve security behaviours across all regions and divisions.

Key Responsibilities
  • Security Awareness Programme Management
    • Manage all aspects of the organisation’s security awareness training programme, including mandatory quarterly training for all employees.
    • Own the security awareness roadmap and annual campaign calendar, ensuring coverage of key risks and regulatory expectations.
    • Ensure awareness programme coverage across divisional and regional locations, including coordination of local delivery and site visits.
    • Manage and administer the Proofpoint Security Awareness Platform, including:
      • Training modules
      • Phishing simulations
      • Reporting and metrics
    • Work with HRIS teams to deliver quarterly and ad‑hoc security training through Workday.
    • Respond to and manage reported phishing emails via PhishAlarm, ensuring appropriate handling and feedback to users.
    • Deliver monthly security awareness induction training for all new starters.
    • Run regular awareness webinars, lunch‑and‑learn sessions, and other in‑person and virtual briefings.
    • Select, deploy, and deliver role‑specific training for specialist job functions such as IT, Finance, HR, and other high‑risk roles.
    • Run role‑specific awareness sessions, highlighting risks and attack scenarios relevant to specific job functions.
    • Propose, design, and implement novel awareness initiatives (e.g. competitions, quizzes, games) to improve engagement and effectiveness.
  • Phishing & Human Risk Testing
    • Own and manage the phishing testing programme, including:
      • Regular phishing simulations
      • Analysis of results and trends
      • Targeted follow‑up training for repeat failures
      • Escalate risky user behaviour and repeat failures to line management in line with agreed processes.
    • Work with SecOps and Incident Response teams to incorporate real‑world attack patterns into testing and training.
    • Set up and manage restrictions on access to Uniphar resources for persistent failures
  • Physical & Behavioural Security Audits
    • Conduct physical USB testing (e.g. trojan USB drops) to assess user behaviour.
    • Perform clean desk audits across office locations.
    • Conduct unattended workstation locking audits and report findings.
    • Use audit outcomes to inform targeted awareness campaigns and improvements.
  • Awareness Communications & Campaigns
    • Manage the Cybersecurity Intranet site, publishing regular security awareness updates and guidance.
    • Design, procure, and distribute physical and digital awareness media, including:
      • Posters
      • Stickers
      • Digital signage
    • Deliver regular themed security awareness campaigns across all channels (physical media, desktop messaging, training modules).
    • Lead the organisation’s October Security Awareness Month, including:
      • Campaign planning
      • Training Quizzes, games, and surveys
      • Engagement reporting
    • Metrics, KPIs & Continuous Improvement
      • Produce regular metrics and reporting on:
        • Training completion rates
        • Programme reach
        • Phishing simulation results
        • Engagement and effectiveness
      • Meet and report against defined KPIs for programme effectiveness.
      • Conduct user surveys to gather feedback and measure awareness maturity.
      • Incorporate survey results, metrics, and incident data into continuous programme improvements.
  • Collaboration & Stakeholder Engagement
    • Work closely with IT and SecOps to maximise delivery of security awareness messaging to end users, including:
      • System notifications
      • Pop‑ups and warnings
      • Desktop backgrounds and banners
    • Coordinate with divisional IT and communications teams to localise awareness delivery.
    • Carry out divisional and regional site visits to distribute materials and deliver local workshops.
Skills & Experience
  • Essential Minimum of 5 years’ experience in IT, Information Security, learning development or related role
  • Proven experience delivering security awareness, training, or behavioural risk programmes.
  • Strong understanding of phishing, social engineering, and human‑centric cyber risks.
  • Experience managing awareness platforms and learning delivery tools.
  • Strong communication and presentation skills.
  • Ability to engage effectively with both technical and non‑technical audiences.

Please note that Uniphar is an equal‑opportunity employer; we do not discriminate and welcome all responses.

Our Work Experience is the combination of everything that's unique about us: our culture, our core values, our company meetings, our commitment to sustainability, our recognition programs, but most importantly, it's our people. Our employees are self‑disciplined, hard working, curious, trustworthy, humble, and truthful. They make choices according to what is best for the team, they live for opportunities to collaborate and make a difference, and they make us the #1 Top Workplace in the area. #uniphargroup

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Awareness Lead
Information Security Awareness Lead

Unipharmedtech • Greater London

Hybrid
GBP 65,000 - 95,000
Security Awareness Lead: Phishing & Training Champion
Security Awareness Lead: Phishing & Training Champion

Unipharmedtech • Uxbridge

Hybrid
GBP 70,000 - 90,000
Security Awareness Lead: Elevate Phishing Readiness
Security Awareness Lead: Elevate Phishing Readiness

Unipharmedtech • Greater London

Hybrid
GBP 65,000 - 95,000
Security Awareness Analyst (Human Risk)
Security Awareness Analyst (Human Risk)

Saepio Information Security • High Wycombe

Hybrid
GBP 30,000 - 50,000
25 days annual leave
BUPA Premium Health Insurance
Life Insurance
+5
Security Awareness Analyst (Human Risk)
Security Awareness Analyst (Human Risk)

Saepio • High Wycombe

Hybrid
GBP 40,000 - 55,000
25 days annual leave
BUPA Premium Health Insurance
Life Insurance
+5
Head of Cyber Culture and Awareness
Head of Cyber Culture and Awareness

Cyber UK • Greater London

Hybrid
GBP 80,000 - 100,000
25 days’ holiday
Enhanced pension and life insurance
Private medical insurance
+2
Expanded Access Program Coordinator – Multilingual
Expanded Access Program Coordinator – Multilingual

Uniphar Group • Uxbridge

Hybrid
GBP 32,000 - 45,000
Expanded Access Program Coordinator – Multilingual
Expanded Access Program Coordinator – Multilingual

Unipharmedtech • Greater London

Hybrid
GBP 32,000 - 48,000
Information Security Specialist
Information Security Specialist

deciphex • Kidlington, Exeter

On-site
GBP 70,000 - 110,000
Embedded Security Education & Awareness Programme Consultant
Embedded Security Education & Awareness Programme Consultant

Control Risks Group • Greater London

On-site
GBP 90,000 - 130,000