Human Risk Management & Phishing Awareness Consultant
Project description
Join our Development Centre in Bucharest and become a member of our open-minded, progressive and professional team. In this role you will be working for one of our world-famous clients. The Chief Security Office (CSO) of our client comprises the Chief Information Security Office (CISO) and the Corporate Security unit. The CISO organization guarantees information security for our client. On top of attractive salary and benefits package, Luxoft will invest into your professional training, and allow you to grow your professional career. Our client's Security Training & Awareness function is evolving from a traditional phishing simulation programme towards a broader Human Risk Management (HRM) capability. The objective is to establish a scalable, data-driven approach that combines behavioural risk indicators, human risk intelligence, targeted interventions, and measurable risk reduction outcomes across the organisation. This evolution includes expanding beyond phishing testing into additional human risk domains, risk analytics, behavioural intelligence, and governance frameworks. We are seeking an experienced consultant to support the design, implementation, and maturation of our Human Risk Management capabilities.
Responsibilities
- Defining and implementing a Human Risk Management operating model.
- Expanding testing and behavioural assessment capabilities beyond traditional email phishing simulations
- Developing human risk intelligence, analytics, and reporting capabilities
- Designing risk-based intervention frameworks and behavioural change strategies.
- Supporting HRM platform evaluation, implementation, and optimisation.
- Creating senior management reporting and risk insights that demonstrate measurable reductions in human cyber risk.
- Design and deliver phishing simulations, developing realistic attack scenarios and maintaining campaign content, templates, and landing pages.
SKILLS
Must have
- 7+ years of experience in cyber security, behavioural risk, Human Risk Management, security culture, or security awareness.
- Demonstrated experience designing or implementing Human Risk Management programmes.
- Experience with behavioural analytics, risk intelligence, or user risk scoring approaches.
- Strong understanding of phishing, social engineering, fraud, and human-targeted cyber threats.
- Experience developing executive-level reporting and risk dashboards.
- Experience working within highly regulated industries, preferably financial services.
- Practical experience with phishing simulation design and campaign delivery, including scenario creation and campaign execution.
- Working knowledge of HTML and the ability to edit and troubleshoot email templates, landing pages, and simulation content.
Nice to have
•Experience in a multinational environment
Required Skills
Required Languages
🇬🇧 English