Select Page

Security awareness/security culture/human risk management specific job titles

CYBSAFE-SebDB Webinar-preblog-221011MS-36

12 March 2025

This isn’t super scientific but we’ve been keeping tabs on ABC/HRM-specific job titles over the years and here’s what we generally see:

Part 1 – Level/function prefix or suffix

The following prefixes or suffixes:

  • Lead (p & s)
  • Manager (s)
  • Head of (p)
  • Director (p & s)
  • Advisor (s)
  • Instructor (s)
  • Principal (p)
  • Program Manager (s)
  • Specialist (s)

 

Part 2 – Domain prefix

The following domain prefixes:

  • Cyber
  • Cybersecurity
  • Cyber Security
  • Information Security
  • InfoSec
  • Security

 

Part 3 – Function descriptor

  • Awareness Awareness and Culture
  • Awareness and Training
  • Awareness & Training
  • Awareness, Readiness and Engagement
  • Awareness, Training & Advocacy
  • Awareness Training and Human Risk Strategy
  • Behavioral Engineer
  • Behavioural Engineer
  • Behavioral Risk
  • Behavioural Risk Communication and Awareness
  • Culture
  • Culture Education and Awareness
  • Culture Training and Awareness
  • Cyberpsychology Engagement
  • Education
  • Education and Awareness
  • Education, Training and Awareness
  • Engagement Governance and Culture
  • Human Risk
  • Human Risk, Communications
  • Human Risk Management
  • Psychology & Engagement
  • Risk and Awareness
  • Risk and Behaviors
  • Risk and Behaviours
  • Risk Culture
  • Safety Awareness Training
  • Training and Awareness
  • Training & Awareness
  • Training and Cyber Awareness
  • Training and Education
  • Training, Awareness and Outreach
  • Training Education and Awareness

 

NB. This is only a list of ABC/HRM-specific titles i.e. for roles largely dedicated to awareness, behaviour, culture or managing human risk. It doesn’t account for the numerous people who have a much more generic title, and are maybe also responsible for other areas of cybersecurity/infosec.

Last updated 28 Feb 2025

Behave Hub newsletter CybSafe

Do one more thing right today. Subscribe to the Behave newsletter:

You may also like

Security metrics reboot: Less input, better output, real outcomes

Security metrics reboot: Less input, better output, real outcomes

Unfortunately, most security awareness professionals don’t really understand the difference between: ✅ Inputs✅ Outputs✅ Outcomes But they don’t want to admit it. And honestly? We get it. It’s like pretending to know the plot of Inception when deep down, you’re just as confused as everyone else. No...

The dogma of security awareness: Exposing cybersecurity’s biggest blind spot

The dogma of security awareness: Exposing cybersecurity’s biggest blind spot

“Humans are the weakest link.”“Security Awareness training = better behaviour”"If we can nail engagement, we’ll nail risk reduction.""Security Awareness is *actually* about so much more than awareness.”“Security culture is the golden ticket to risk reduction.”“Good communication, messaging,...

Can BS make SA&T stick? Hot takes from the experts…

Can BS make SA&T stick? Hot takes from the experts…

Using insights from “Oh, Behave!” to strengthen security training and drive lasting behavioral change Security training. It’s as commonplace in an organization as writing “see attached” and forgetting to attach anything. It can help to tackle cybersecurity risks—but only when done well. Simply...

Maximizing security awareness engagement: How the pros do it

Maximizing security awareness engagement: How the pros do it

Ditch mandatory training, starting riiiight…now!Want to boost security awareness? Talk about something else entirelyGet serious about funThe top mic-drop insights from our Cybersecurity Awareness Month engagement webinar We know people whose organizations make a big deal of CAM are much more...