Security Awareness and Culture Lead

National Physical Laboratory (NPL)

Teddington

Hybrid

GBP 60,000 - 80,000

Full time

13 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

National Physical Laboratory (NPL) is seeking a Security Culture Lead to shape and embed a strong security mindset across cyber, physical and people risk. You will design programmes, campaigns, and communications that reduce human-related risk while aligning with regulatory and customer requirements.

You will collaborate with People Team, IT and Assurance to measure impact, deliver training, and drive behavioural change, ensuring readiness for BPSS/SC clearance and hybrid work across the site in

Qualifications

  • Proven experience developing and delivering security awareness and culture programmes within a complex organisation.
  • Experience working within or closely with Government, defence, or other highly regulated environments.
  • Strong understanding of cyber security principles, physical security, and human risk factors.
  • Knowledge of behavioural science or change management methodologies to influence organisational behaviour.
  • Excellent communication skills with the ability to translate technical security concepts into clear messages for diverse audiences.
  • Experience in stakeholder engagement across multiple business functions.
  • Ability to design and measure metrics for cultural change and training effectiveness.
  • Project management skills to plan, execute, and evaluate initiatives on time and within budget.
  • Professional certifications such as CISSP, CISM, or SANS Security Awareness Professional.
  • Background in communications, psychology, or organisational development.

Responsibilities

  • Develop and implement a security culture strategy aligned with NPL values, business objectives, and security risk priorities.
  • Champion a security-first mindset by leading initiatives, campaigns, and communications that make security relatable and actionable.
  • Design and deliver continuous security awareness programmes, including e-learning, workshops, campaigns, and executive briefings.
  • Identify gaps in security knowledge and develop targeted interventions to address these risks effectively.
  • Tailor training and awareness activities for different roles and risk profiles across the organisation.
  • Create and track metrics to measure effectiveness of initiatives and drive positive behavioural change.
  • Collaborate with corporate functions and major programmes to align messaging and priorities.
  • Act as a trusted advisor on embedding security into processes and culture.
  • Provide subject matter expertise on human risk management, social engineering awareness, and behavioural change.
  • Stay informed on best practices in security culture development and learning methodologies.

Skills

Security awareness programs
Stakeholder engagement
Change management
Excellent communication
Project management

Education

Communications/psychology/organisational development background

Tools

Security certifications (CISSP, CISM, SANS)

Job description

Responsible for shaping and embedding a strong security culture in cyber, physical and people across NPL. Lead initiatives that influence behaviour and reduce human-related risk in compliance with regulatory and customer requirement, ensuring all colleagues have the appropriate level of awareness, knowledge, and skills to manage security risks in alignment with our programmes security values and policies.

Key responsibilities
  • Develop and implement a security culture strategy aligned with NPL values, business objectives, and security risk priorities.
  • Champion a security-first mindset by leading initiatives, campaigns, and communications that make security relatable, actionable, and embedded in everyday work.
  • Design and deliver continuous security awareness programmes, including e-learning, workshops, campaigns, and executive briefings. Complement annual mandatory training with “just-in-time” learning resources to keep colleagues informed, engaged and mitigate risk of security breaches through best practice.
  • Identify gaps in security knowledge and behaviours and develop targeted interventions to address these risks effectively.
  • Tailor training and awareness activities for different roles and risk profiles across the organisation.
  • Create and track metrics to measure effectiveness of initiatives and drive positive behavioural change.
  • Collaborate with corporate functions and major programmes (People Team, Communications, IT, Assurance, etc.) to align messaging and priorities.
  • Act as a trusted advisor on embedding security into processes, procedures, and organisational culture.
  • Provide subject matter expertise on human risk management, social engineering awareness, and behavioural change.
  • Stay informed on best practices in security culture development, learning methodologies, and behavioural science.
  • Responsible for taking reasonable duty of care for Health & Safety of themselves and of other persons who may be affected by their acts or omissions at work and always follow direct instructions given with regards to Health & Safety.
About You
  • Proven experience in developing and delivering security awareness and culture programmes within a complex organisation.
  • Experience working within or closely with Government, defence, or other highly regulated environments.
  • Strong understanding of cyber security principles, physical security, and human risk factors.
  • Knowledge of behavioural science or change management methodologies to influence organisational behaviour.
  • Excellent communication skills with the ability to translate technical security concepts into clear, engaging messages for diverse audiences.
  • Experience in stakeholder engagement and collaboration across multiple business functions.
  • Ability to design and measure metrics for cultural change and training effectiveness.
  • Project management skills to plan, execute, and evaluate initiatives on time and within budget.
  • Professional certifications such as CISSP, CISM, or certifications in security awareness (e.g., SANS Security Awareness Professional).
  • Background in communications, psychology, or organisational development.
Personal Attributes
  • Collaborative communicator who builds strong relationships and influences others.
  • Customer-focused with an ability to align security culture to organisational needs.
  • Innovative and curious, bringing creative ideas to engage colleagues.
  • Decisive and informed, confident in making evidence-based decisions.Driven and adaptable, committed to continuous improvement and learning.

We actively recruit citizens of all backgrounds, but the nature of our work in specific departments means that nationality, residency and security requirements can be more tightly defined than others. You will be asked about this throughout the recruitment process. To work at NPL, you will need to obtain BPSS security clearance.

You will need to have an SC clearance with no restrictions, or you must have the ability to obtain an SC clearance.

This is a hybrid working role, and is split between 3 days on‐site and 2 days WFH.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Personnel Security Advisor
Senior Personnel Security Advisor

National Physical Laboratory (NPL) • Teddington

On-site
GBP 65,000 - 90,000
Flexible working
Benefits package
Security Adviser
Security Adviser

National Physical Laboratory (NPL) • Teddington

On-site
GBP 55,000 - 85,000
Hybrid Security Culture & Awareness Lead
Hybrid Security Culture & Awareness Lead

National Physical Laboratory (NPL) • Teddington

Hybrid
GBP 60,000 - 80,000
Security Advisor
Security Advisor

National Physical Laboratory (NPL) • Teddington

On-site
GBP 60,000 - 80,000
Security Assurance Lead
Security Assurance Lead

Motability Operations Ltd • Greater London

On-site
GBP 70,000 - 100,000
Group Leader
Group Leader

National Physical Laboratory (NPL) • Teddington

Hybrid
GBP 90,000 - 120,000
Flexible working
Health & wellbeing benefits
Strategy and Engagement Manager - AI
Strategy and Engagement Manager - AI

National Physical Laboratory (NPL) • Teddington

On-site
GBP 60,000 - 90,000
Physical Security Assurance Lead (2LD)
Physical Security Assurance Lead (2LD)

Sizewell C • Greater London

Hybrid
GBP 74,000 - 90,000
Annual leave 28 days + 2
5% annual bonus
Pension: up to 15% employer contrib.
+1
Naimuri - Information Security Officer
Naimuri - Information Security Officer

QinetiQ Limited • Salford

Hybrid
GBP 42,000 - 62,000
Flexible/Hybrid working
Performance bonus
Company bonus
+4
26-080 Information Security Officer
26-080 Information Security Officer

NSG Environmental Ltd • Chorley

On-site
GBP 55,000 - 75,000
Life Assurance 3x Salary
Private Healthcare package
Pension - Company contributes 5% and 4
+3