1

Phishing Simulation Jobs (NOW HIRING)

Software Engineer, Simulation

New York, NY · On-site

$135K - $300K/yr

We're creating AI-powered phishing simulations that use large-language models and voice synthesis ... to mimic real-world threats - from hyper-personalized emails to high-fidelity "manager calls" that ...

This position also supports recurring security operations activities, including access reviews, phishing simulation reporting, security metrics collection, and audit support. All activities are ...

This position also supports recurring security operations activities, including access reviews, phishing simulation reporting, security metrics collection, and audit support. All activities are ...

This position also supports recurring security operations activities, including access reviews, phishing simulation reporting, security metrics collection, and audit support. All activities are ...

This position also supports recurring security operations activities, including access reviews, phishing simulation reporting, security metrics collection, and audit support. All activities are ...

next page

Showing results 1-20

Phishing Simulation information

See salary details

$39K

$101.3K

$144K

How much do phishing simulation jobs pay per year?

As of Aug 6, 2026, the average yearly pay for phishing simulation in the United States is $101,255.00, according to ZipRecruiter salary data. Most workers in this role earn between $78,500.00 and $129,500.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals running phishing simulation programs, and how can they be addressed?

Professionals managing phishing simulation programs often encounter challenges such as employee resistance, maintaining engagement, and ensuring simulations stay relevant to evolving threats. To address these, it's important to communicate the purpose of simulations clearly, provide timely feedback and education, and regularly update campaigns to reflect current phishing tactics. Collaborating closely with IT, HR, and leadership teams helps foster a culture of security awareness and ensures the program's effectiveness.

What is a phishing simulation?

A phishing simulation is a cybersecurity exercise where organizations send fake phishing emails to employees to test their ability to recognize and report malicious messages. The goal is to raise awareness about phishing tactics and improve employees' responses to real threats. These simulations help identify vulnerabilities within the organization and guide future training efforts to reduce the risk of successful phishing attacks.

What is the difference between Phishing Simulation vs Security Analyst?

AspectPhishing SimulationSecurity Analyst
CredentialsCertifications like CEH, CompTIA Security+Certifications like CISSP, CISA, CEH
Work EnvironmentTypically in cybersecurity teams, focusing on training and awarenessIn IT/security departments, analyzing threats and implementing security measures
Employer & IndustryUsed by organizations to test employee awareness in cybersecurityEmployed by organizations to protect IT infrastructure and respond to security incidents

While both roles are part of cybersecurity, Phishing Simulation focuses on testing and training employees against phishing attacks, whereas Security Analysts monitor, analyze, and respond to security threats within an organization.

What are the key skills and qualifications needed to thrive as a phishing simulation specialist, and why are they important?

To thrive as a Phishing Simulation Specialist, you need a solid understanding of cybersecurity principles, social engineering tactics, and experience with security awareness training programs, usually backed by a degree in information security or related certifications like CEH or CISSP. Familiarity with phishing simulation platforms (e.g., KnowBe4, Cofense), email security systems, and data analytics tools is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for designing realistic scenarios and educating users. These skills and qualifications are essential for helping organizations identify vulnerabilities, reduce human risk, and strengthen their overall security posture.
More about Phishing Simulation jobs
What cities are hiring for Phishing Simulation jobs? Cities with the most Phishing Simulation job openings:
What states have the most Phishing Simulation jobs? States with the most job openings for Phishing Simulation jobs include:
Infographic showing various Phishing Simulation job openings in the United States as of August 2026, with employment types broken down into 87% Full Time, and 13% Contract. Highlights an 100% In-person job distribution, with an average salary of $101,255 per year, or $48.7 per hour.

Security Awareness & Phishing Simulation Specialist

United IT

Manhattan, NY • On-site

Other

Posted 3 days ago

New


Job description

Security Awareness & Phishing Simulation Specialist (KnowBe4)

We are seeking a skilled Security Awareness & Phishing Simulation Specialist with hands-on experience in KnowBe4 to design, execute, and manage enterprise-wide phishing campaigns and security awareness training programs.

The role focuses on reducing human risk by improving employee security behavior through data-driven phishing simulations, training campaigns, reporting, and continuous improvement.

Key Responsibilities

Phishing Campaign Management (KnowBe4)

  • Design, configure, and execute ongoing phishing simulation campaigns using KnowBe4.
  • Customize phishing templates (emails, landing pages, attachments, URLs) based on: risk profiles, department/region, threat trends.
  • Schedule baseline, monthly, and targeted campaigns (e.g., executives, finance, IT).
  • Implement adaptive phishing and risk-based targeting.
  • Tune difficulty levels over time to align with program maturity.

Security Awareness Training

  • Plan and administer security awareness training campaigns using KnowBe4 modules.
  • Assign training based on user role, risk score, prior phishing failures.
  • Manage mandatory, remedial, and role-based training.
  • Track training completion, overdue users, and escalations.

Reporting, Metrics & KPIs

  • Generate and analyze metrics such as: phish-prone percentage (PPP), click rates, credential submission rates, reporting rates, training completion rates.
  • Deliver monthly and quarterly executive-ready reports.
  • Provide insights and recommendations to improve user behavior.
  • Maintain dashboards aligned to human risk reduction KPIs.

Integration & Automation

  • Integrate KnowBe4 with Microsoft Entra ID / Azure AD, Okta (if applicable), email gateways (O365 / Exchange / Proofpoint), SIEM / SOAR platforms (e.g., Splunk, XSOAR – optional).
  • Manage Phish Alert Button (PAB) deployment and reporting workflows.
  • Support automation for user provisioning, group sync, and reporting.

Governance & Program Support

  • Support policy-aligned security awareness programs (ISO 27001, SOC 2, NIST, PCI DSS).
  • Assist during internal audits and client assessments.
  • Coordinate with HR, IT, and Compliance teams.
  • Maintain SOPs, playbooks, and campaign calendars.
Required Technical Skills

Mandatory

  • Strong hands-on experience with KnowBe4, including phishing campaigns, training campaigns, reporting & dashboards.
  • Good understanding of phishing techniques (credential harvest, attachments, smishing basics), email security concepts.
  • Experience with Microsoft 365 / Exchange Online environments.
  • Strong Excel and reporting skills.

Good to Have

  • Integration experience with Proofpoint, Mimecast, Defender for Office 365.
  • Awareness of human risk management concepts.
  • Familiarity with NIST Security Awareness Framework.
  • Experience supporting global/multi-geo organizations.
Soft Skills
  • Strong stakeholder communication skills.
  • Ability to translate metrics into clear executive insights.
  • High attention to detail and governance mindset.
  • Self-driven and process-oriented.
Deliverables & KPIs
  • Reduction in phish-prone percentage over time.
  • Improved email reporting rate.
  • On-time completion of awareness training.
  • Accurate and consistent executive reporting.
  • Continuous improvement recommendations.