1

Phishing Simulation Jobs (NOW HIRING)

... phishing simulation campaigns, including follow-up education for higher-risk user groups. • Coordinate security-related work across IT, compliance, and internal security partners while keeping ...

You will also contribute to security awareness training and phishing simulation programs and cross-train with and support other members of the security team. This role is a great fit for someone ...

Maintain and Administer the Security Awareness and Phishing Simulation platform. Support and assist in the development of Forensic tasks and needs. Provide Application penetration testing when ...

Be Seen First

IT Security Analyst

Bryans Road, MD · On-site

$60K - $75K/yr

Provide assistance with employee security awareness training and phishing simulation exercises. Qualifications: * Minimum 1+ years experience in Security Operations role * Must have a valid driver ...

Apply for Position

Reston, VA · On-site

$40K - $50K/yr

Set up phishing simulations to assess and improve the organization's resilience to phishing attacks. * Educate employees about phishing risks to enhance their ability to recognize and report phishing ...

Administer phishing simulation campaigns, security awareness training, user follow-up, and reporting; partner with IT and business leaders to improve user resilience against social engineering ...

... phishing simulation campaigns. • Support the development, testing, and ongoing improvement of Disaster Recovery plans to ensure the organization can effectively respond to and recover from ...

Incorporate existing phishing simulation tool, KnowBe4, to execute monthly campaigns and integrate the campaign results into the overall training and awareness program. * Develop annual, role-based ...

next page

Showing results 1-20

Phishing Simulation information

See salary details

$39K

$101.3K

$144K

How much do phishing simulation jobs pay per year?

As of Jun 26, 2026, the average yearly pay for phishing simulation in the United States is $101,255.00, according to ZipRecruiter salary data. Most workers in this role earn between $78,500.00 and $129,500.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals running phishing simulation programs, and how can they be addressed?

Professionals managing phishing simulation programs often encounter challenges such as employee resistance, maintaining engagement, and ensuring simulations stay relevant to evolving threats. To address these, it's important to communicate the purpose of simulations clearly, provide timely feedback and education, and regularly update campaigns to reflect current phishing tactics. Collaborating closely with IT, HR, and leadership teams helps foster a culture of security awareness and ensures the program's effectiveness.

What is a phishing simulation?

A phishing simulation is a cybersecurity exercise where organizations send fake phishing emails to employees to test their ability to recognize and report malicious messages. The goal is to raise awareness about phishing tactics and improve employees' responses to real threats. These simulations help identify vulnerabilities within the organization and guide future training efforts to reduce the risk of successful phishing attacks.

What is the difference between Phishing Simulation vs Security Analyst?

AspectPhishing SimulationSecurity Analyst
CredentialsCertifications like CEH, CompTIA Security+Certifications like CISSP, CISA, CEH
Work EnvironmentTypically in cybersecurity teams, focusing on training and awarenessIn IT/security departments, analyzing threats and implementing security measures
Employer & IndustryUsed by organizations to test employee awareness in cybersecurityEmployed by organizations to protect IT infrastructure and respond to security incidents

While both roles are part of cybersecurity, Phishing Simulation focuses on testing and training employees against phishing attacks, whereas Security Analysts monitor, analyze, and respond to security threats within an organization.

What are the key skills and qualifications needed to thrive as a Phishing Simulation Specialist, and why are they important?

To thrive as a Phishing Simulation Specialist, you need a solid understanding of cybersecurity principles, social engineering tactics, and experience with security awareness training programs, usually backed by a degree in information security or related certifications like CEH or CISSP. Familiarity with phishing simulation platforms (e.g., KnowBe4, Cofense), email security systems, and data analytics tools is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for designing realistic scenarios and educating users. These skills and qualifications are essential for helping organizations identify vulnerabilities, reduce human risk, and strengthen their overall security posture.
More about Phishing Simulation jobs
What cities are hiring for Phishing Simulation jobs? Cities with the most Phishing Simulation job openings:
What states have the most Phishing Simulation jobs? States with the most job openings for Phishing Simulation jobs include:
Infographic showing various Phishing Simulation job openings in the United States as of June 2026, with employment types broken down into 5% Internship, 87% Full Time, 5% Part Time, and 3% Contract. Highlights an 82% In-person, 3% Hybrid, and 15% Remote job distribution, with an average salary of $101,255 per year, or $48.7 per hour.
Cybersecurity GRC Manager, FCH - IT - SECURITY (6604480001)

Cybersecurity GRC Manager, FCH - IT - SECURITY (6604480001)

FROEDTERT HEALTH

Menomonee Falls, WI • On-site

$111K - $150K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted yesterday


Job description

Discover. Achieve. Succeed. #BeHere
Location: US:WI:MENOMONEE FALLS at our WOODLAND PRIME 400 facility.
This job is REMOTE.
FTE: 1.000000
Standard Hours: 40.00
Shift: Flexible 1st shift between 7 am and 5 pm
Shift Details: Holidays: Weekends:
Job Summary:
Healthcare security isn't a compliance checkbox problem - it's a patient safety problem. At Froedtert ThedaCare, the Cybersecurity GRC Manager owns the program that connects our governance posture to real-world risk outcomes for patients, clinicians, and the communities we serve across Wisconsin.
This is a high-visibility, high-autonomy leadership role inside a Cybersecurity & Infrastructure team that operates with strategic intent and operational rigor. You will build and run a team of 5+ GRC professionals, serve as the internal subject matter authority on compliance and risk, and translate complex regulatory requirements into actionable programs that the broader organization can execute against.
If you've built GRC programs from scratch (or rebuilt ones that needed it), know your way around a HIPAA gap analysis and a third-party risk assessment in equal measure, are people-focused, and lead with clarity rather than bureaucracy - this is the role for you
People Leadership
• Lead, mentor, and grow a team of 5+ GRC analysts and specialists across compliance, risk, policy, and awareness domains
• Establish clear role expectations, development pathways, and performance standards for each team member
• Foster a team culture that balances rigor with pragmatism - we care about outcomes, not just documentation
HIPAA & Healthcare Compliance
• Serve as the organization's functional lead for HIPAA Privacy and Security Rule compliance, including ongoing gap assessment and remediation tracking
• Coordinate with Legal, Privacy, and Clinical Operations to ensure compliance obligations are understood and operationalized across the enterprise
• Oversee preparation for and response to regulatory inquiries, OCR investigations, and audit activity
Risk Management & Third-Party Risk
• Own the enterprise cybersecurity risk register, ensuring risks are identified, assessed, prioritized, and tracked to resolution
• Lead the third-party risk management program, including vendor onboarding assessments, ongoing monitoring, and risk-tiering across the supply chain
• Develop risk reporting for executive and board audiences, translating technical risk into business impact language
Policy & Controls Frameworks
• Own the cybersecurity policy lifecycle: authorship, review cadence, version control, approval workflows, and exception management
• Maintain alignment to NIST CSF, managing control mapping, evidence collection, and control effectiveness measurement
• Drive continuous improvement of the controls environment based on assessment findings, threat intelligence inputs, and regulatory changes
Audit & Assessment Management
• Serve as the primary point of contact and program lead for internal and external cybersecurity audits and assessments
• Coordinate evidence collection, manage stakeholder readiness, and oversee finding remediation tracking through to closure
• Develop and maintain audit-ready documentation across all GRC domains
Security Awareness & Phishing Simulation
• Own the enterprise security awareness program, including curriculum development, delivery scheduling, and effectiveness measurement
• Manage the phishing simulation program end-to-end: scenario design, cadence, metrics, and targeted follow-up training for at-risk populations
• Tailor awareness content for diverse audiences - from clinical staff to executive leadership - with a voice that educates rather than shames
EXPERIENCE DESCRIPTION:
• A minimum of six year experience in a related field.
• Prefer 3+ years leading or managing a team in a GRC, compliance, or risk management capacity
• Prefer experience in a healthcare or other highly regulated industry, with direct exposure to HIPAA compliance obligations
• Demonstrated experience managing a third-party risk program, including vendor assessments and risk tiering
• Prefer prior experience building or significantly maturing a GRC program, not just maintaining one
• Prefer experience managing external audits or assessments (SOC 2, HITRUST, OCR, internal audit, etc.)
EDUCATION DESCRIPTION:
A Bachelors degree is required.
Bachelors in Computer Science or similar degree is preferred.
SPECIAL SKILLS DESCRIPTION:
• In-depth knowledge of cybersecurity frameworks including but not limited to NIST CF, HITRUST CSF, ISO 27001.
• Experience in managing or leading security organizations responsible for GRC, Cybersecurity, Medical Device Security, Security Operations Centers.
• Understanding of general security concepts including but not limited to cryptography, DLP, Security Operations Center, Security Managed Services, SEM, FW, Audit.
• Demonstrated record of managing third party security services, preferably with the cloud providers.
• Experience in Healthcare industry is preferred.
• Ability to communicate and represent IT Security organization with all business partners and third party vendors.
• Strong oral, presentation, writing skills. and demonstrated record to deliver results.
• Ability to build relationships with business stakeholders of the IT Security program
• Familiarity with HIPAA Privacy and Security Rules and their operational implications for a large health system
• Ability to develop and present executive-level risk reporting that communicates risk in business impact terms
• Comfort operating in a matrixed environment with multiple stakeholder groups including Legal, HR, IT, Clinical Operations, and executive leadership
Certifications
• Prefer CISSP, CISM, CRISC, HCISPP, or equivalent certification
• Prefer Certified in Healthcare Privacy and Security (CHPS) or equivalent
Compensation, Benefits & Perks at Froedtert Health
Pay is expected to be between: (expressed as hourly) $49.15 - $84.07. Final compensation is based on experience and will be discussed with you by the recruiter during the interview process.
Froedtert Health Offers a variety of perks & benefits to staff, depending on your role you may be eligible for the following:
  • Paid time off
  • Growth opportunity- Career Pathways & Career Tuition Assistance, CEU opportunities
  • Academic Partnership with the Medical College of Wisconsin
  • Referral bonuses
  • Retirement plan - 403b
  • Medical, Dental, Vision, Life Insurance, Short & Long Term Disability, Free Workplace Clinics
  • Employee Assistance Programs, Adoption Assistance, Healthy Contributions, Care@Work, Moving Assistance, Discounts on gym memberships, travel and other work life benefits available

The Froedtert & the Medical College of Wisconsin regional health network is a partnership between Froedtert Health and the Medical College of Wisconsin supporting a shared mission of patient care, innovation, medical research and education. Our health network operates eastern Wisconsin's only academic medical center and adult Level I Trauma center engaged in thousands of clinical trials and studies. The Froedtert & MCW health network, which includes ten hospitals, nearly 2,000 physicians and more than 45 health centers and clinics draw patients from throughout the Midwest and the nation.
We are proud to be an Equal Opportunity Employer who values and maintains an environment that attracts, recruits, engages and retains a diverse workforce. We welcome protected veterans to share their priority consideration status with us at 262-439-1961. We maintain a drug-free workplace and perform pre-employment substance abuse testing. During your application and interview process, if you have a need that requires an accommodation, please contact us at 262-439-1961. We will attempt to fulfill all reasonable accommodation requests.

Froedtert logo

About Froedtert

Sourced by ZipRecruiter

Froedtert is a world-class healthcare organization based in Milwaukee, WI, United States. The company operates within the healthcare and wellness industry, providing a broad spectrum of medical services to the residents of southeastern Wisconsin and beyond. Froedtert was founded in 1980 and is an academic health network, which ripples an integrated affiliation with the Medical College of Wisconsin. The company prides itself on its cutting-edge treatments, sophisticated technology, and groundbreaking research. Froedtert’s mission is to advance health in the communities they serve, with a profound commitment towards patient care, education, research and community outreach.

Industry

Health care and social assistance

Company size

1,001 - 5,000 Employees

Headquarters location

Milwaukee, WI, US

Year founded

1980