1

Phishing Simulation Jobs in Texas (NOW HIRING)

Administer phishing simulation campaigns, security awareness training, user follow-up, and reporting; partner with IT and business leaders to improve user resilience against social engineering ...

$109K - $147K/yr

Oversee email security initiatives including mail filtering policies via Microsoft Defender for Office 365, anti-phishing controls, and user phishing simulation programs (Attack Simulation Training ...

Security Analyst I

Plano, TX · On-site

$30 - $40/hr

Support identity and access management tasks, including MFA/SSO enforcement and Entra ID conditional access reviews * Assist with security awareness training initiatives and phishing simulation ...

Support identity and access management tasks, including MFA/SSO enforcement and Entra ID conditional access reviews * Assist with security awareness training initiatives and phishing simulation ...

Support identity and access management tasks, including MFA/SSO enforcement and Entra ID conditional access reviews * Assist with security awareness training initiatives and phishing simulation ...

Security Analyst I

Plano, TX · On-site

$30 - $40/hr

Support identity and access management tasks, including MFA/SSO enforcement and Entra ID conditional access reviews * Assist with security awareness training initiatives and phishing simulation ...

The Security Analyst will perform tasks including monitoring, phishing simulation campaigns, vulnerability tracking, incident response, and security awareness training. Upholding policies, standards ...

Network & Security Engineer

Dallas, TX · On-site

$95K - $130K/yr

Set program direction and content for Citadel's cybersecurity awareness program, including training plans, phishing simulation strategy, and ongoing user education topics. Partner with the IT manager ...

Conduct internal security reviews, vulnerability scans, phishing simulations, and security testing activities. * Coordinate third-party penetration testing and cybersecurity assessments. * Track ...

Conduct internal security reviews, vulnerability scans, phishing simulations, and security testing activities. * Coordinate third-party penetration testing and cybersecurity assessments. * Track ...

Conduct internal security reviews, vulnerability scans, phishing simulations, and security testing activities. * Coordinate third-party penetration testing and cybersecurity assessments. * Track ...

next page

Showing results 1-20

Phishing Simulation information

What are some common challenges faced by professionals running phishing simulation programs, and how can they be addressed?

Professionals managing phishing simulation programs often encounter challenges such as employee resistance, maintaining engagement, and ensuring simulations stay relevant to evolving threats. To address these, it's important to communicate the purpose of simulations clearly, provide timely feedback and education, and regularly update campaigns to reflect current phishing tactics. Collaborating closely with IT, HR, and leadership teams helps foster a culture of security awareness and ensures the program's effectiveness.

What is a phishing simulation?

A phishing simulation is a cybersecurity exercise where organizations send fake phishing emails to employees to test their ability to recognize and report malicious messages. The goal is to raise awareness about phishing tactics and improve employees' responses to real threats. These simulations help identify vulnerabilities within the organization and guide future training efforts to reduce the risk of successful phishing attacks.

What is the difference between Phishing Simulation vs Security Analyst?

AspectPhishing SimulationSecurity Analyst
CredentialsCertifications like CEH, CompTIA Security+Certifications like CISSP, CISA, CEH
Work EnvironmentTypically in cybersecurity teams, focusing on training and awarenessIn IT/security departments, analyzing threats and implementing security measures
Employer & IndustryUsed by organizations to test employee awareness in cybersecurityEmployed by organizations to protect IT infrastructure and respond to security incidents

While both roles are part of cybersecurity, Phishing Simulation focuses on testing and training employees against phishing attacks, whereas Security Analysts monitor, analyze, and respond to security threats within an organization.

What are the key skills and qualifications needed to thrive as a phishing simulation specialist, and why are they important?

To thrive as a Phishing Simulation Specialist, you need a solid understanding of cybersecurity principles, social engineering tactics, and experience with security awareness training programs, usually backed by a degree in information security or related certifications like CEH or CISSP. Familiarity with phishing simulation platforms (e.g., KnowBe4, Cofense), email security systems, and data analytics tools is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for designing realistic scenarios and educating users. These skills and qualifications are essential for helping organizations identify vulnerabilities, reduce human risk, and strengthen their overall security posture.
What job categories do people searching Phishing Simulation jobs in Texas look for? The top searched job categories for Phishing Simulation jobs in Texas are:
What cities in Texas are hiring for Phishing Simulation jobs? Cities in Texas with the most Phishing Simulation job openings:

IT Security Analyst II

Audubon Companies

Houston, TX • On-site

Full-time

Re-posted 26 days ago


Job description

JOB DESCRIPTION:

The IT Security Analyst II is responsible for monitoring, analyzing, and remediating security threats across the organization's IT environment. This role supports day-to-day security operations while also taking ownership of recurring security processes, incident investigation, control administration, compliance documentation, and security improvement initiatives. The analyst will work closely with IT, the Security Operations Center (SOC), business stakeholders, and external partners to strengthen email security, endpoint protection, identity and access management, cloud productivity platform security, security awareness, and audit readiness.

PRIMARY RESPONSIBILITIES:

  • Monitor, triage, and investigate reported phishing attempts, suspicious emails, account activity, endpoint events, and other user-reported or system-generated security incidents; coordinate containment, remediation, and escalation as required.
  • Review and analyze alerts from SOC services, SIEM platforms, endpoint protection tools, identity systems, Microsoft 365 security controls, and threat intelligence sources; identify trends, false positives, recurring risks, and opportunities for improved detection.
  • Tune and maintain email security controls, including spam, phishing, impersonation, and malware filtering; recommend and implement rule changes to reduce risk while minimizing business disruption.
  • Administer phishing simulation campaigns, security awareness training, user follow-up, and reporting; partner with IT and business leaders to improve user resilience against social engineering threats.
  • Administer and support endpoint protection, internet security, zero-trust desktop controls, and related security platforms; assist with configuration reviews, exception handling, policy updates, and troubleshooting.
  • Monitor Microsoft 365 user account security, email activity, conditional access signals, risky sign-ins, and related security posture indicators; support remediation of compromised or high-risk accounts.
  • Support vulnerability management and security hygiene activities by reviewing findings, coordinating remediation with IT teams, validating corrective actions, and documenting risk exceptions where appropriate.
  • Maintain ISMS records, evidence repositories, control documentation, incident records, and audit support materials for ISO 27001 and other compliance or customer-driven security requirements.
  • Participate in incident response activities, risk assessments, tabletop exercises, process improvement initiatives, and security projects; contribute practical recommendations that reduce operational risk and improve security maturity.
  • Prepare recurring metrics, status updates, and management-level summaries related to security incidents, user awareness, control effectiveness, compliance activities, and open remediation items.
  • Provide security guidance to IT staff and non-technical users, balancing risk reduction with business continuity and practical user support.

Health, Safety, and Environmental Responsibilities:

  • All employees are responsible for supporting Audubon Companies' Health, Safety, and Environmental (HSE) policies and procedures. This includes:
  • Performing duties in a manner that protects personal and team health and safety
  • Participating in required HSE training, meetings, and reporting activities
  • Identifying and reporting hazards, near misses, and unsafe conditions
  • Following safe work practices and complying with applicable regulatory requirements

EXPERIENCE AND SKILL REQUIREMENTS:

  • Bachelor's degree in Information Security, Computer Science, Engineering, Information Technology, or related field, or equivalent combination of education, training, and experience.
  • Three to five years of experience in IT security, cybersecurity operations, infrastructure security, identity administration, incident response, or a closely related IT role.
  • Hands-on experience with security tools and platforms such as SIEM, endpoint detection and response, endpoint protection, email security, identity and access management, vulnerability management, and Microsoft 365 security administration.
  • Working knowledge of phishing analysis, incident triage, endpoint investigation, identity-related threats, cloud productivity platform security, and common attack techniques.
  • Experience administering or supporting Okta, Microsoft 365, endpoint protection, internet security, and zero-trust or conditional access controls preferred.
  • Understanding of ISMS practices, security policies, risk management, audit evidence collection, and compliance frameworks such as ISO 27001.
  • Ability to analyze security events, document findings clearly, prioritize risk-based remediation activities, and communicate practical recommendations to technical and non-technical audiences.
  • Strong written and verbal communication skills in English; Spanish proficiency is a plus but is not required.
  • Ability to work independently, manage recurring security responsibilities, collaborate across teams, and support occasional after-hours incident response or planned security activities when business needs require.
  • Relevant certifications such as CompTIA Security+, CySA+, SSCP, GSEC, CISSP, CISM, or Microsoft security certifications are preferred.

No Recruiters, please!

Equal Opportunity Employer/Veterans/Disabled