Security Awareness Program Leadership:
Drive the global cyber security awareness program, including the annual development, review, and promotion of training materials and training roadmap.
Ensure training content remains current and aligned with the evolving threat landscape (e.g., AI/Emerging threats, Social Engineering, Phishing), company policies & standards, and varying regulatory requirements (e.g., PCI-DSS, SOX, SOC TypeII, NIST CSF).
Lead the creation, sourcing, and annual refresh of cyber awareness materials, partnering closely with our global Cyber Security, Compliance, Legal, Privacy, and BISO teams to ensure our content continuously adapts to evolving threats while remaining impactful and engaging.
Lead the organization’s phishing simulation program by running a regular schedule of company wide phishing tests, creating specialized targeted campaigns for high risk teams. Generate and analyze actionable metrics to shape future security awareness and training initiatives.
Design and deploy targeted role based training and awareness content for high impact user groups (including Executive Leadership, Executive Assistants, Finance, HR, Developers, and Privileged Users) to directly address their specific risk profiles, data access levels, and unique threat landscapes specific to their role.
Partner with the Legal, Privacy, and Data teams to educate the broader workforce on the complex landscape of global data protection and privacy laws.
Transform actionable insights from daily cyber threat intelligence briefings into timely, targeted awareness communications, ensuring employees are briefed on emerging threats (e.g., active phishing campaigns, new malware strains) relevant to their specific regions and roles.
Manage relationships with external security awareness and GRC tool vendors, ensuring that platforms are effectively configured, license utilization is optimized, and roadmap features are aligned with News Corp’s internal security objectives.
Support the maintenance of the News Corp Global Cyber GRC Program, including the support of cyber risks and compliance exceptions.
Collaboratively support the review and implementation of cybersecurity standards, guidelines, and processes to ensure compliance across the business.
Support the management of the lifecycle of security-focused documentation, including the review and approval of Knowledge Base (KB) articles and security standards, ensuring content is accurate, up-to-date, and accessible to global support teams.
Support the operationalization of security policies & standards by monitoring for deviations, investigating non-compliant activities, and delivering direct guidance to end-users to ensure adherence to corporate security policies & standards.
Support internal and external stakeholders for compliance requirements (PCI DSS, NIST CSF, SOX, and Privacy).
Support the development and maintenance of key performance indicators (KPIs) that effectively track cybersecurity posture and awareness campaign metrics.
Support and review cyber risk assessments and cyber control assurance in collaboration with global technology and cyber team members.