1

Phishing Simulation Jobs in Virginia (NOW HIRING)

Apply for Position

Reston, VA · On-site

$40K - $50K/yr

Set up phishing simulations to assess and improve the organization's resilience to phishing attacks. * Educate employees about phishing risks to enhance their ability to recognize and report phishing ...

Red Team Operator

Culpeper, VA · Hybrid

$99K - $127K/yr

Be an active participant in end-to-end adversary simulations across enterprise, cloud, and hybrid ... Proficiency with common Red Team tooling, including C2 frameworks, scanners, phishing platforms ...

Red Team Operator

Manassas, VA · Hybrid

$100K - $129K/yr

Be an active participant in end-to-end adversary simulations across enterprise, cloud, and hybrid ... Proficiency with common Red Team tooling, including C2 frameworks, scanners, phishing platforms ...

Red Team Operator

Culpeper, VA · On-site

$99K - $127K/yr

Be an active participant in end-to-end adversary simulations across enterprise, cloud, and hybrid ... Proficiency with common Red Team tooling, including C2 frameworks, scanners, phishing platforms ...

Red Team Operator

Manassas, VA · Hybrid

$100K - $129K/yr

Be an active participant in end-to-end adversary simulations across enterprise, cloud, and hybrid ... Proficiency with common Red Team tooling, including C2 frameworks, scanners, phishing platforms ...

Red Team Operator

Culpeper, VA · Hybrid

$99K - $127K/yr

Be an active participant in end-to-end adversary simulations across enterprise, cloud, and hybrid ... Proficiency with common Red Team tooling, including C2 frameworks, scanners, phishing platforms ...

next page

Showing results 1-20

Phishing Simulation information

What are some common challenges faced by professionals running phishing simulation programs, and how can they be addressed?

Professionals managing phishing simulation programs often encounter challenges such as employee resistance, maintaining engagement, and ensuring simulations stay relevant to evolving threats. To address these, it's important to communicate the purpose of simulations clearly, provide timely feedback and education, and regularly update campaigns to reflect current phishing tactics. Collaborating closely with IT, HR, and leadership teams helps foster a culture of security awareness and ensures the program's effectiveness.

What is a phishing simulation?

A phishing simulation is a cybersecurity exercise where organizations send fake phishing emails to employees to test their ability to recognize and report malicious messages. The goal is to raise awareness about phishing tactics and improve employees' responses to real threats. These simulations help identify vulnerabilities within the organization and guide future training efforts to reduce the risk of successful phishing attacks.

What is the difference between Phishing Simulation vs Security Analyst?

AspectPhishing SimulationSecurity Analyst
CredentialsCertifications like CEH, CompTIA Security+Certifications like CISSP, CISA, CEH
Work EnvironmentTypically in cybersecurity teams, focusing on training and awarenessIn IT/security departments, analyzing threats and implementing security measures
Employer & IndustryUsed by organizations to test employee awareness in cybersecurityEmployed by organizations to protect IT infrastructure and respond to security incidents

While both roles are part of cybersecurity, Phishing Simulation focuses on testing and training employees against phishing attacks, whereas Security Analysts monitor, analyze, and respond to security threats within an organization.

What are the key skills and qualifications needed to thrive as a Phishing Simulation Specialist, and why are they important?

To thrive as a Phishing Simulation Specialist, you need a solid understanding of cybersecurity principles, social engineering tactics, and experience with security awareness training programs, usually backed by a degree in information security or related certifications like CEH or CISSP. Familiarity with phishing simulation platforms (e.g., KnowBe4, Cofense), email security systems, and data analytics tools is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for designing realistic scenarios and educating users. These skills and qualifications are essential for helping organizations identify vulnerabilities, reduce human risk, and strengthen their overall security posture.
What job categories do people searching Phishing Simulation jobs in Virginia look for? The top searched job categories for Phishing Simulation jobs in Virginia are:
What cities in Virginia are hiring for Phishing Simulation jobs? Cities in Virginia with the most Phishing Simulation job openings:
Infographic showing various Phishing Simulation job openings in Virginia as of July 2026, with employment types broken down into 100% Part Time. Highlights an 100% In-person job distribution.
Security Awareness Analyst Senior

Security Awareness Analyst Senior

University of Virginia

Charlottesville, VA • On-site

$91K - $168K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 23 days ago


University Of Virginia rating

7.9

Company rating: 7.9 out of 10

Based on 35 frontline employees who took The Breakroom Quiz

204th of 611 rated colleges and universities


Job description

Assist Director Information Technology Security to implement information security plan and maintain application accesses for Information Systems supported by UVa Health System Computing Services.
This position requires to be on site once or twice a month. Preferred market DMV (DC, Maryland, Virginia).
Key Responsibilities
Enterprise Security Awareness & Training Program Leadership
  • With guidance from the GRC Director, lead the UVA Health cybersecurity awareness and training program, including annual planning, execution, and continuous improvement.
  • Develop and deliver role-appropriate training for workforce members, including onboarding, annual refresher training, and targeted campaigns based on risk trends.
  • Design, run, and continuously refine phishing simulation campaigns; analyze results, identify systemic risk patterns, and recommend corrective actions.
  • Maintain program metrics and dashboards to demonstrate effectiveness, maturity, and risk reduction over time.
  • Ensure documentation and evidence of training completion and program effectiveness are maintained to support audits and regulatory reviews.
Phishing & Social Engineering Risk Management
  • Monitor and assess emerging phishing and social engineering techniques affecting healthcare organizations.
  • Develop awareness content addressing real-world attack scenarios (e.g., phishing, spear-phishing, business email compromise, vishing, smishing).
  • Partner with IT Security Operations and Incident Response teams to incorporate lessons learned from security incidents into training and awareness activities.
Compliance Assessments & Governance Support
  • Serve as a senior contributor to cybersecurity and regulatory compliance assessments by coordinating evidence collection, validating control effectiveness, and supporting remediation tracking.
  • Participate in periodic security risk assessments and governance activities aligned with UVA Health's cybersecurity risk management practices.
  • Collaborate with Internal Audit, Compliance, and Privacy stakeholders to support internal and external audits and readiness activities.
Policy Development & Lifecycle Management
  • Lead or co-lead development, review, maintenance, and communication of IT security policies, standards, and procedures.
  • Ensure policies reflect UVA Health governance expectations and are aligned with healthcare regulatory requirements and recognized cybersecurity frameworks.
  • Coordinate policy lifecycle activities, including scheduled reviews, updates, approvals, and workforce communication.
Data Governance & Privacy Controls
  • Apply and support cybersecurity controls related to data governance, data classification, and privacy protection for sensitive health and business information.
  • Work closely with Privacy and Compliance teams to support appropriate handling of PHI and other regulated data across systems and workflows.
  • Assist in identifying risks related to data access, use, and disclosure, and support mitigation strategies consistent with UVA Health standards.
Leadership & Collaboration
  • Act as a subject matter expert and trusted advisor for security awareness, human-centric risk, and governance topics across the health system.
  • Influence without authority by partnering with clinical, operational, academic, and administrative stakeholders.
  • Mentor junior staff or contribute expert guidance within cross-functional initiatives as assigned.

MINIMUM REQUIREMENTS
Education: Bachelor's degree
Experience: 5-7 years relevant experience. Relevant experience may be considered in lieu of a degree.
Licensure: CISSP or HCISPP required or actively working on and can demonstrate a plan to achieve
Preferred Qualifications
  • Experience leading healthcare cybersecurity programs or academic health systems.
  • Experience with phishing simulation platforms and awareness maturity metrics.
  • Familiarity with NIST CSF, HIPAA security principles, and healthcare compliance expectations.
  • Certifications such as CISSP, HCISP, CISM, CISA, Security + is preferred.

PHYSICAL DEMANDS
This is primarily a sedentary job involving extensive use of desktop computers. The job does occasionally require traveling some distance to attend meetings, and programs.
The pay range for this role is $91,312.00 - $168,748.00 annually. Individual compensation will be determined by the selected candidate's qualifications, previous work experience, and/or education.
Benefits
  • Comprehensive Benefits Package: Medical, Dental, and Vision Insurance
  • Paid Time Off, Long-term and Short-term Disability, Retirement Savings
  • Health Saving Plans, and Flexible Spending Accounts
  • Certification and education support
  • Generous Paid Time Off

UVA Health is a world-class Magnet Recognized academic medical center and health system with a level 1 trauma center. 2023-2024 U.S. News & World Report "Best Hospitals" guide rates UVA Health University Medical Center as "High Performing" in 5 adult specialties and 14 conditions/procedures. We are one of 70 National Cancer Institute designated cancer centers. UVA Health Children's is named by 2023-2024 U.S. News & World Report as the best children's hospital in Virginia with 9 specialties ranked among the best in the nation. Our footprint also encompasses 3 community hospitals and an integrated network of primary and specialty care clinics throughout Charlottesville, Culpeper, Northern Virginia, and beyond.
The University of Virginia is an equal opportunity employer. All interested persons are encouraged to apply, including veterans and individuals with disabilities. Learn more about UVA's commitment to non-discrimination and equal opportunity employment .

What University Of Virginia employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


University of Virginia logo

About University of Virginia

Sourced by ZipRecruiter

The University of Virginia is distinctive among institutions of higher education. Founded by Thomas Jefferson in 1819, the University sustains the ideal of developing, through education, leaders who are well-prepared to shape the future of the nation.

Industry

Colleges, universities, and professional schools

Company size

10,000+ Employees

Headquarters location

Charlottesville, VA, US

Year founded

1819