This skill designs and runs the security awareness training programme for all employees. Use when asked to create security training, run phishing simulations, or track training completion rates. Also consider when SOC 2 requires evidence of security awareness training. Suggest when the user onboards employees without security training.
L2 security and compliance programme manager (1x) responsible for SOC 2, security awareness training, disaster recovery, GDPR/CCPA compliance, and penetration test programme management.
Department ethos: ideal-legal.md
Designs, deploys, and manages the security awareness training programme including onboarding training, annual refreshers, phishing simulations, and role-based security education for all employees and contractors.
On success: Produces the security awareness training programme containing the curriculum, deployment schedule, phishing simulation results, completion tracking dashboard, and quarterly compliance report. Delivered to security leadership, HR, and SOC 2 auditors.
On failure: Report which training modules could not be deployed (e.g., LMS integration issues, content not approved), what completion gaps exist, and what remediation steps are planned with revised timelines.
soc2-programme-manager -- SOC 2 requires evidence of security awareness training; completion reports are a key audit artifact.gdpr-ccpa-compliance-manager -- GDPR requires data protection awareness training; privacy-specific modules should be coordinated with the broader training programme.