Logo for HealthEquity

Security Awareness Senior Manager

Role overview

Qualifications

  • Bachelor’s Degree in relevant field preferred
  • 7+ years of professional experience in security awareness or related areas
  • Strong understanding of social engineering, phishing, data protection, and compliance

Responsibilities

  • Drive HealthEquity’s enterprise security awareness and human risk management strategy
  • Design, launch, and continuously improve enterprise security awareness campaigns
  • Establish metrics to assess effectiveness of security awareness programs
  • Manage and mentor a team of security awareness specialists

Key facts

Hard skills

Other skills

  • Lateral Communication
  • Program Management
  • Technical Acumen
  • Communication
  • Collaboration
  • Creativity
  • Problem Solving

About the company

HealthEquity logo

HealthEquity

Financial Services

HealthEquity is a leading administrator of Health Savings Accounts (HSAs) and other consumer-directed benefits—FSA, HRA, COBRA, and Commuter. Benefits advisors, health plans, and retirement providers partner with us to help over 13 million members work toward long-term health and financial wellbeing. Visit HealthEquity.com to see our intuitive technology and remarkable service in action.

Company details

IndustryFinancial Services
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Our Mission:

Our mission is to SAVE AND IMPROVE LIVES BY EMPOWERING HEALTHCARE CONSUMERS. Come be part of remarkable.

Overview:

How you can make a difference  

As Senior Manager, Security Awareness & GRC, you will lead HealthEquity’s enterprise human risk management and security culture strategy. This role turns complex cybersecurity, fraud, privacy, compliance, and AI governance topics into clear, engaging, behavior-focused programs that help teammates recognize risk, make safer decisions, and protect our members, clients, partners, and business.

You will own the strategy, execution, measurement, and continuous improvement of enterprise security awareness programs, including phishing simulations, required training, teammate targeted education, new hire onboarding, executive messaging, internal and external security campaigns, and targeted communications for high-risk behaviors or emerging threats. You will partner closely with Security, GRC, Fraud, Privacy, Legal, HR, Marketing, Product Security, IT, and executive leadership to ensure security expectations are understood, actionable, and embedded into how work gets done.

This role requires a strategic communicator, program builder, creative campaign designer, and cross-functional influencer who can connect risk, behavior, culture, and business outcomes. You will create scalable awareness experiences, advise leaders on human risk trends, support audit and regulatory expectations, manage vendor and platform relationships, and use data to continuously strengthen HealthEquity’s security culture.

What you’ll be doing 

  • Drive continuous improvement efforts by identifying opportunities for enhancing security governance, risk management, and compliance practices.
  • Drive HealthEquity’s enterprise security awareness and human risk management strategy, aligning teammate education, behavioral risk reduction, annual compliance expectations, and security culture priorities.
  • Design, launch, and continuously improve enterprise campaigns that drive measurable behavior change, including Cybersecurity Awareness Month, Internet Safety Month, Fraud Awareness Week, phishing awareness, AI governance education, and emerging threat communications.
  • Lead the creative development of security awareness campaigns, including campaign themes, visual concepts, messaging frameworks, presentation materials, social and intranet graphics, videos, newsletters, recognition assets, and teammate-facing engagement experiences.
  • Own the strategy and execution of phishing simulation programs, targeted learning, reporting workflows, reinforcement messaging, and recognition programs that encourage timely reporting and safer decisions.
  • Work with third party partners to create and maintain a range of security awareness educational materials, including e-learning modules, newsletters, posters, and videos, tailored to different audiences.
  • Establish metrics to assess the effectiveness of the security awareness program, including pre- and post-training evaluations, incident reports, and employee feedback.
  • Contribute in development and implementation of security metrics and key performance indicators (KPIs) to measure the effectiveness of security controls, risk mitigation strategies, and compliance efforts. Regularly analyze and report on security metrics to senior management, identifying trends, areas of improvement, and actionable insights.
  • Work closely with Security, IT, Fraud, Product, HR, Marketing, Legal, Privacy, and other departments to integrate security awareness into existing training and onboarding processes.
  • Ensure that security policies and procedures are effectively communicated and understood throughout the organization.
  • Collaborate with the Security Operations Center to provide guidance and support during security incidents, helping to educate employees on the importance of reporting suspicious activities.
  • Collaborate with security engineering organization to effectively identify and implement relevant tools and technologies to support the end to end human risk management of security awarness.
  • Lead through influence across cross-functional partners, balancing strategic program ownership with hands-on execution in a fast-paced, highly regulated environment.
  • Stay current on security threats, social engineering trends, AI risk, regulatory expectations, and awareness best practices to keep programs relevant, timely, and effective.
  • Advise leadership on human risk trends, communication risks, adoption barriers, and opportunities to improve security behavior across the enterprise.
  • Manage and mentor a team of security awareness specialists, fostering a collaborative and innovative environment.
  • As needed, participate in comprehensive risk assessments and vulnerability analyses to identify potential security risks and recommend appropriate mitigation strategies. This will require leading and influencing cross-functional teams and stakeholders at all levels of the company.
  • Manage identification and rollout of scalable innovative technologies to support security governance, including developing usage policies and guidelines, audit, and control processes.
  • Other duties as assigned.

What you will need to be successful

Education and Experience:

  • Bachelor’s Degree, in information security, information technology, communications, marketing, education, instructional design, psychology, behavioral science, business, or related discipline is preferred. Equivalent experience in security awareness, human risk management, change management, communications, or enterprise program leadership may be considered.
  • 7+ years of professional experience in security awareness, human risk management, information security GRC, IT compliance, IT audit, privacy, legal, communications, marketing, education, instructional design, change management, or enterprise program leadership, preferably in a technology setting or highly regulated industry.

Specialized Knowledge, Skills, and Abilities:

  • Proven experience leading enterprise security awareness, human risk management, or security culture programs in a regulated environment.
  • Strong ability to translate technical, regulatory, and risk concepts into clear business and teammate-facing communications.
  • Experience designing behavior-focused campaigns, executive communications, training programs, newsletters, videos, intranet content, and internal engagement strategies.
  • Strong creative direction skills, including the ability to turn complex security, fraud, privacy, compliance, and AI governance topics into memorable campaign themes, branded visuals, executive-ready materials, and teammate experiences that drive action.
  • Experience using phishing simulation data, training metrics, reporting trends, and engagement insights to measure program effectiveness.
  • Experience with O365 applications (Word, PowerPoint, Excel).
  • Additional Education/Certification preferred but not required, e.g. CIPP or CIPM, CDPSE, CISSP, CISM, CISA, CCSA.
  • Experience interacting with and working directly with/for internal/external business partners.
  • Able to work collaboratively in a fast-paced technology environment, where willingness to learn and adapt is critical.
  • Strong level of knowledge in at least one of industry standards and best practices such as SOC1, SOC2 Type II, ISO/IEC 27001 Certification, HIPAA Compliance, HITRUST, and PCI/DSS.
  • Strong understanding of social engineering, phishing, data protection, AI governance, privacy, fraud risk, incident reporting, and secure behavior principles.
  • Ability to operate independently, prioritize competing requests, and drive large-scale programs with limited resources.
  • Excellent storytelling, change management, and stakeholder communication skills.
  • Experience influencing others to take action.

Certifications, Licenses, Registrations:

CompTIA CYSA or comparable certification

#LI-Remote

This is a remote position.

Salary Range: $120500.00 To $157000.00 / year Benefits & Perks:

The actual compensation offer is determined based on job-related knowledge, education, skills, experience, and work location. This position will be eligible for performance-based incentives as part of the total compensation package, in addition to a full range of benefits including:

  • Medical, dental, and vision
  • HSA contribution and match
  • Dependent care FSA match
  • Uncapped paid time off
  • Paid parental leave
  • 401(k) match
  • Personal and healthcare financial literacy programs
  • Ongoing education & tuition assistance
  • Gym and fitness reimbursement
  • Wellness program incentives

Onboarding & Travel

This is a remote role, with an in-person onboarding training component. New team members must participate in Trailhead, HealthEquity’s immersive onboarding experience Trailhead is designed to foster meaningful connections, support your integration into the organization, and equip you with a strong understanding of our business. Trailhead participation is a key expectation of this role. Trailhead is held onsite at our headquarters once per quarter. HealthEquity covers all required travel and accommodations. 

This role may begin with a virtual, self-paced onboarding experience, followed by a mandatory onsite Trailhead session at a later date.

HealthEquity is committed to providing reasonable accommodations to team members with qualifying disabilities. Should you be selected for this role and require an accommodation, we will put you in touch with our Benefits Team so you can begin the accommodation request process.

Why work with HealthEquity :

HealthEquity has a vision that by 2030 we will make HSAs as wide-spread and popular as retirement accounts. We are passionate about providing a solution that allows American families to connect health and wealth. Join us and discover a work experience where the person is valued more than the position. Click here to learn more. 

You belong at HealthEquity!

HealthEquity, Inc. is an equal opportunity employer, and we are committed to being an employer where no matter your background or identity – you feel welcome and included. We ensure equal opportunity for all applicants and employees without regard to race, age, color, religion, sex, sexual orientation, gender identity, national origin, status as a qualified individual with a disability, veteran status, or other legally protected characteristics. HealthEquity is a drug-free workplace. For more information about our EEO policy, or about HealthEquity’s applicant disability accommodation, drug-free-workplace, background check, and E-Verify policies, please visit our Careers page.

HealthEquity uses Microsoft Copilot to transcribe screening interviews between candidates and their direct Talent Partner for note taking and interview summaries. By scheduling a screening interview with us, you consent to Microsoft Copilot’s AI technology recording and transcribing your interview with your Talent Partner. This information will be reviewed for accuracy and then used by HealthEquity to summarize the interview, ensure accuracy, and facilitate our hiring process. We take privacy seriously. You have the option to opt out. If you wish to opt out of this Microsoft Copilot transcription, please notify your Talent Partner in advance of the interview. If we do not receive an opt-out request from you, we will assume that you consent to the use of Microsoft Copilot.

At HealthEquity, our goal is to save and improve lives by empowering healthcare consumers. This shared purpose inspires everything we do, including how we approach hiring. Our process is designed to get to know the real you: your skills, experiences, and potential to make a difference. We value honesty, originality, and the courage to do the right thing, even when it is not the easiest path. Showing up as your authentic self reflects these values and helps us build something truly remarkable together.

As AI is becoming a common tool throughout the application process, we want to be clear about its appropriate use at HealthEquity. Using AI to support resume writing, research, or interview preparation is perfectly acceptable, provided the content is accurate and genuinely represents your qualifications and skills.  For other key parts of our interview process, however, it is important that the ideas, communication, and work you share reflect your own voice, experiences, and thinking. We ask that you participate in our live interviews and complete any assessments without AI assistance unless instructions explicitly indicate otherwise or a specific exception is discussed and approved in advance. This approach ensures fairness, celebrates your individuality, and allows your authentic perspective to shine. Behaviors that do not align with these guidelines may result in disqualification from the hiring process or termination of employment if later discovered. We appreciate your understanding and look forward to learning about the unique contributions only you can bring to HealthEquity.

HealthEquity is committed to your privacy as an applicant for employment.  For information on our privacy policies and practices, please visit HealthEquity Privacy.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

IT Security Manager Related jobs

Other jobs at HealthEquity

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.