Select Page

Security awareness/security culture/human risk management specific job titles

CYBSAFE-SebDB Webinar-preblog-221011MS-36

12 March 2025

This isn’t super scientific but we’ve been keeping tabs on ABC/HRM-specific job titles over the years and here’s what we generally see:

Part 1 – Level/function prefix or suffix

The following prefixes or suffixes:

  • Lead (p & s)
  • Manager (s)
  • Head of (p)
  • Director (p & s)
  • Advisor (s)
  • Instructor (s)
  • Principal (p)
  • Program Manager (s)
  • Specialist (s)

 

Part 2 – Domain prefix

The following domain prefixes:

  • Cyber
  • Cybersecurity
  • Cyber Security
  • Information Security
  • InfoSec
  • Security

 

Part 3 – Function descriptor

  • Awareness Awareness and Culture
  • Awareness and Training
  • Awareness & Training
  • Awareness, Readiness and Engagement
  • Awareness, Training & Advocacy
  • Awareness Training and Human Risk Strategy
  • Behavioral Engineer
  • Behavioural Engineer
  • Behavioral Risk
  • Behavioural Risk Communication and Awareness
  • Culture
  • Culture Education and Awareness
  • Culture Training and Awareness
  • Cyberpsychology Engagement
  • Education
  • Education and Awareness
  • Education, Training and Awareness
  • Engagement Governance and Culture
  • Human Risk
  • Human Risk, Communications
  • Human Risk Management
  • Psychology & Engagement
  • Risk and Awareness
  • Risk and Behaviors
  • Risk and Behaviours
  • Risk Culture
  • Safety Awareness Training
  • Training and Awareness
  • Training & Awareness
  • Training and Cyber Awareness
  • Training and Education
  • Training, Awareness and Outreach
  • Training Education and Awareness

 

NB. This is only a list of ABC/HRM-specific titles i.e. for roles largely dedicated to awareness, behaviour, culture or managing human risk. It doesn’t account for the numerous people who have a much more generic title, and are maybe also responsible for other areas of cybersecurity/infosec.

Last updated 28 Feb 2025

Behave Hub newsletter CybSafe

Do one more thing right today. Subscribe to the Behave newsletter:

You may also like

Wake-up call: the human element in the UK retail cyberattacks

Wake-up call: the human element in the UK retail cyberattacks

The digital landscape has been buzzing with news of cyberattacks rocking the British retail sector. For many organisations, these headlines haven't just been news; they've been a stark, cold splash of reality, highlighting a threat that's not lurking in the shadows, but actively knocking at the...

Tool or infrastructure? Why it matters for HRM

Tool or infrastructure? Why it matters for HRM

Tool or infrastructure? Why it matters for HRM Let’s be clear: Not all HRM software is the same. It sounds obvious, right? Yet many people miss the difference between HRM tools, and HRM infrastructure.  And when it comes to compounding security gains and designing for outsized impact, the...

NIS2: Beefing up security for critical industries

NIS2: Beefing up security for critical industries

So, you've probably heard whispers (or maybe full-blown announcements!) about this thing called NIS2.  But what exactly is the NIS2 Directive, and why should you care?  Well, in a nutshell, it's a new set of rules from the EU designed to seriously beef up critical security infrastructure across...

An open letter to CISOs & Security Leaders

An open letter to CISOs & Security Leaders

The human side of cybersecurity is evolving. Fast.But there’s a good chance you might be stuck in the past. You probably have well-established views on security awareness, culture, and human risk.You genuinely believe they matter. But if we’re being honest - you mostly pay lip service to them. And...

Why security awareness still isn’t taken seriously (and how to fix it)

Why security awareness still isn’t taken seriously (and how to fix it)

Let’s start with a painful truth:Security awareness, culture, and human risk professionals are often undervalued. Despite the rising threat of human-enabled cyber attacks, many organizations still treat addressing the human aspect as a checkbox. A communications initiative. A nice-to-have....

Security metrics reboot: Less input, better output, real outcomes

Security metrics reboot: Less input, better output, real outcomes

Unfortunately, most security awareness professionals don’t really understand the difference between: ✅ Inputs✅ Outputs✅ Outcomes But they don’t want to admit it. And honestly? We get it. It’s like pretending to know the plot of Inception when deep down, you’re just as confused as everyone else. No...