We are seeking a Lead Associate, Human Risk & Workplace Security to help strengthen the organization's security posture by assessing and reducing workforce-related cyber risk. In this role, you will evaluate how employee behavior, access privileges, technology controls, and business processes intersect to create security exposure, and partner across security, identity, data protection, and incident response teams to drive measurable risk reduction.
Responsibilities
- Maintain a risk-informed view of workplace technology, endpoint, collaboration, and human-risk exposure.
- Analyze how employee behavior, access privileges, data access, and technology design contribute to security risk.
- Evaluate awareness and security outcomes using behavioral, phishing, incident, near-miss, and repeat-event data.
- Identify high-risk populations, workflows, and business processes for targeted risk-reduction initiatives.
- Evaluate risks associated with social engineering, impersonation, deepfakes, and AI-enabled deception.
- Partner with identity and access management (IAM), data security, cyber defense, and incident response teams to address material risks.
- Track remediation activities and corrective actions through evidence-based resolution.
Minimum Qualifications
- Experience in workplace security, endpoint security, collaboration security, cybersecurity awareness, human-risk management, or a related cybersecurity discipline.
- Understanding of social engineering, phishing, impersonation, and emerging AI-enabled threat techniques.
- Experience assessing both technical and human-centered security controls.
- Ability to analyze behavioral and operational data to measure control effectiveness and risk outcomes.
- Strong written and verbal communication skills with the ability to influence stakeholders and challenge assumptions constructively.
- Sound judgment regarding employee privacy, legal considerations, and investigation boundaries.
Preferred Qualifications
- Experience identifying and prioritizing workforce risk using behavioral, exposure, or incident-based data.
- Proven ability to improve security programs through evidence-based decision making.
- Experience evaluating workplace security controls across productivity and collaboration platforms.
- Familiarity with governance, risk management, and cross-functional security programs.