Security Awareness Senior Manager
Job description
Our Mission
Our mission is to SAVE AND IMPROVE LIVES BY EMPOWERING HEALTHCARE CONSUMERS. Come be part of remarkable.
Overview
How you can make a difference
As Senior Manager, Security Awareness & GRC, you will lead HealthEquity’s enterprise human risk management and security culture strategy. This role turns complex cybersecurity, fraud, privacy, compliance, and AI governance topics into clear, engaging, behavior-focused programs that help teammates recognize risk, make safer decisions, and protect our members, clients, partners, and business.
You will own the strategy, execution, measurement, and continuous improvement of enterprise security awareness programs, including phishing simulations, required training, teammate targeted education, new hire onboarding, executive messaging, internal and external security campaigns, and targeted communications for high-risk behaviors or emerging threats. You will partner closely with Security, GRC, Fraud, Privacy, Legal, HR, Marketing, Product Security, IT, and executive leadership to ensure security expectations are understood, actionable, and embedded into how work gets done.
This role requires a strategic communicator, program builder, creative campaign designer, and cross-functional influencer who can connect risk, behavior, culture, and business outcomes. You will create scalable awareness experiences, advise leaders on human risk trends, support audit and regulatory expectations, manage vendor and platform relationships, and use data to continuously strengthen HealthEquity’s security culture.
What you’ll be doing
- Drive continuous improvement efforts by identifying opportunities for enhancing security governance, risk management, and compliance practices.
- Drive HealthEquity’s enterprise security awareness and human risk management strategy, aligning teammate education, behavioral risk reduction, annual compliance expectations, and security culture priorities.
- Design, launch, and continuously improve enterprise campaigns that drive measurable behavior change, including Cybersecurity Awareness Month, Internet Safety Month, Fraud Awareness Week, phishing awareness, AI governance education, and emerging threat communications.
- Lead the creative development of security awareness campaigns, including campaign themes, visual concepts, messaging frameworks, presentation materials, social and intranet graphics, videos, newsletters, recognition assets, and teammate-facing engagement experiences.
- Own the strategy and execution of phishing simulation programs, targeted learning, reporting workflows, reinforcement messaging, and recognition programs that encourage timely reporting and safer decisions.
- Work with third party partners to create and maintain a range of security awareness educational materials, including e-learning modules, newsletters, posters, and videos, tailored to different audiences.
- Establish metrics to assess the effectiveness of the security awareness program, including pre- and post-training evaluations, incident reports, and employee feedback.
- Contribute in development and implementation of security metrics and key performance indicators (KPIs) to measure the effectiveness of security controls, risk mitigation strategies, and compliance efforts. Regularly analyze and report on security metrics to senior management, identifying trends, areas of improvement, and actionable insights.
- Work closely with Security, IT, Fraud, Product, HR, Marketing, Legal, Privacy, and other departments to integrate security awareness into existing training and onboarding processes.
- Ensure that security policies and procedures are effectively communicated and understood throughout the organization.
- Collaborate with the Security Operations Center to provide guidance and support during security incidents, helping to educate employees on the importance of reporting suspicious activities.
- Collaborate with security engineering organization to effectively identify and implement relevant tools and technologies to support the end to end human risk management of security awarness.
- Lead through influence across cross-functional partners, balancing strategic program ownership with hands-on execution in a fast-paced, highly regulated environment.
- Stay current on security threats, social engineering trends, AI risk, regulatory expectations, and awareness best practices to keep programs relevant, timely, and effective.
- Advise leadership on human risk trends, communication risks, adoption barriers, and opportunities to improve security behavior across the enterprise.
- Manage and mentor a team of security awareness specialists, fostering a collaborative and innovative environment.
- As needed, participate in comprehensive risk assessments and vulnerability analyses to identify potential security risks and recommend appropriate mitigation strategies. This will require leading and influencing cross-functional teams and stakeholders at all levels of the company.
- Manage identification and rollout of scalable innovative technologies to support security governance, including developing usage policies and guidelines, audit, and control processes.
- Other duties as assigned.
What you will need to be successful
Education and Experience:
- Bachelor’s Degree, in information security, information technology, communications, marketing, education, instructional design, psychology, behavioral science, business, or related discipline is preferred. Equivalent experience in security awareness, human risk management, change management, communications, or enterprise program leadership may be considered.
- 7+ years of professional experience in security awareness, human risk management, information security GRC, IT compliance, IT audit, privacy, legal, communications, marketing, education, instructional design, change management, or enterprise program leadership, preferably in a technology setting or highly regulated industry.
Specialized Knowledge, Skills, and Abilities:
- Proven experience leading enterprise security awareness, human risk management, or security culture programs in a regulated environment.
- Strong ability to translate technical, regulatory, and risk concepts into clear business and teammate-facing communications.
- Experience designing behavior-focused campaigns, executive communications, training programs, newsletters, videos, intranet content, and internal engagement strategies.
- Strong creative direction skills, including the ability to turn complex security, fraud, privacy, compliance, and AI governance topics into memorable campaign themes, branded visuals, executive-ready materials, and teammate experiences that drive action.
- Experience using phishing simulation data, training metrics, reporting trends, and engagement insights to measure program effectiveness.
- Experience with O365 applications (Word, PowerPoint, Excel).
- Additional Education/Certification preferred but not required, e.g. CIPP or CIPM, CDPSE, CISSP, CISM, CISA, CCSA.
- Experience interacting with and working directly with/for internal/external business partners.
- Able to work collaboratively in a fast-paced technology environment, where willingness to learn and adapt is critical.
- Strong level of knowledge in at least one of industry standards and best practices such as SOC1, SOC2 Type II, ISO/IEC 27001 Certification, HIPAA Compliance, HITRUST, and PCI/DSS.
- Strong understanding of social engineering, phishing, data protection, AI governance, privacy, fraud risk, incident reporting, and secure behavior principles.
- Ability to operate independently, prioritize competing requests, and drive large-scale programs with limited resources.
- Excellent storytelling, change management, and stakeholder communication skills.
- Experience influencing others to take action.
Certifications, Licenses, Registrations:
CompTIA CYSA or comparable certification
#LI-Remote
This is a remote position.
Salary Range
$120500.00 To $157000.00 / yearBenefits & Perks
The actual compensation offer is determined based on job-related knowledge, education, skills, experience, and work location. This position will be eligible for performance-based incentives as part of the total compensation package, in addition to a full range of benefits including:
- Medical, dental, and vision
- HSA contribution and match
- Dependent care FSA match
- Uncapped paid time off
- Paid parental leave
- 401(k) match
- Personal and healthcare financial literacy programs
- Ongoing education & tuition assistance
- Gym and fitness reimbursement
- Wellness program incentives
Onboarding & Travel
This is a remote role, with an in-person onboarding training component. New team members must participate in Trailhead, HealthEquity’s immersive onboarding experience Trailhead is designed to foster meaningful connections, support your integration into the organization, and equip you with a strong understanding of our business. Trailhead participation is a key expectation of this role. Trailhead is held onsite at our headquarters once per quarter. HealthEquity covers all required travel and accommodations.
This role may begin with a virtual, self-paced onboarding experience, followed by a mandatory onsite Trailhead session at a later date.
HealthEquity is committed to providing reasonable accommodations to team members with qualifying disabilities. Should you be selected for this role and require an accommodation, we will put you in touch with our Benefits Team so you can begin the accommodation request process.
Why work with HealthEquity
HealthEquity has a vision that by 2030 we will make HSAs as wide-spread and popular as retirement accounts. We are passionate about providing a solution that allows American families to connect health and wealth. Join us and discover a work experience where the person is valued more than the position. Click here to learn more.
You belong at HealthEquity!
HealthEquity, Inc. is an equal opportunity employer, and we are committed to being an employer where no matter your background or identity – you feel welcome and included. We ensure equal opportunity for all applicants and employees without regard to race, age, color, religion, sex, sexual orientation, gender identity, national origin, status as a qualified individual with a disability, veteran status, or other legally protected characteristics. HealthEquity is a drug-free workplace. For more information about our EEO policy, or about HealthEquity’s applicant disability accommodation, drug-free-workplace, background check, and E-Verify policies, please visit our Careers page.
HealthEquity uses Microsoft Copilot to transcribe screening interviews between candidates and their direct Talent Partner for note taking and interview summaries. By scheduling a screening interview with us, you consent to Microsoft Copilot’s AI technology recording and transcribing your interview with your Talent Partner. This information will be reviewed for accuracy and then used by HealthEquity to summarize the interview, ensure accuracy, and facilitate our hiring process. We take privacy seriously. You have the option to opt out. If you wish to opt out of this Microsoft Copilot transcription, please notify your Talent Partner in advance of the interview. If we do not receive an opt-out request from you, we will assume that you consent to the use of Microsoft Copilot.
At HealthEquity, our goal is to save and improve lives by empowering healthcare consumers. This shared purpose inspires everything we do, including how we approach hiring. Our process is designed to get to know the real you: your skills, experiences, and potential to make a difference. We value honesty, originality, and the courage to do the right thing, even when it is not the easiest path. Showing up as your authentic self reflects these values and helps us build something truly remarkable together.
As AI is becoming a common tool throughout the application process, we want to be clear about its appropriate use at HealthEquity. Using AI to support resume writing, research, or interview preparation is perfectly acceptable, provided the content is accurate and genuinely represents your qualifications and skills. For other key parts of our interview process, however, it is important that the ideas, communication, and work you share reflect your own voice, experiences, and thinking. We ask that you participate in our live interviews and complete any assessments without AI assistance unless instructions explicitly indicate otherwise or a specific exception is discussed and approved in advance. This approach ensures fairness, celebrates your individuality, and allows your authentic perspective to shine. Behaviors that do not align with these guidelines may result in disqualification from the hiring process or termination of employment if later discovered. We appreciate your understanding and look forward to learning about the unique contributions only you can bring to HealthEquity.
HealthEquity is committed to your privacy as an applicant for employment. For information on our privacy policies and practices, please visit HealthEquity Privacy.
Skills mentioned

HealthEquity is a leading health savings account (HSA) administrator, providing services that empower consumers to make health care benefits more personal. We help individuals accumulate savings for qualified medical expenses while guiding employers in creating efficient benefit plans. Founded in 2002, HealthEquity focuses on delivering innovative health benefit solutions. Our technology and service teams are dedicated to providing exceptional support. Our goal is to inspire consumers to take control of their health care spending and savings.
Apply for this job
Use the application link supplied with this listing to apply to HealthEquity. Check the destination before entering personal information.
