Governance, risk and compliance

SmartSuite for the Security Awareness Lead

The Security Awareness Lead runs the programme that builds secure behaviour: training curricula, phishing simulations, role-based content, policy acknowledgements and the metrics that show whether behaviour is changing. They evidence awareness controls for auditors and regulators.

What you own

  • Design and deliver the security awareness and training programme
  • Run phishing simulations and targeted campaigns
  • Track training completion and policy acknowledgements
  • Measure behaviour change and report awareness metrics
  • Tailor content to high-risk roles and regulatory requirements
  • Evidence awareness controls for audits and certifications

Where the role sits

Each name opens that role's page.

Reports to

Information Security Officer

Information Security Officer

See the role
Chief Information Security Officer

Chief Information Security Officer

See the role

Direct reports

Works closely with

HR Operations Manager

HR Operations Manager

See the role
Policy and Governance Manager

Policy and Governance Manager

See the role
IT Compliance Manager

IT Compliance Manager

See the role
Communications Director

Communications Director

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

Touches

contributes or approves

compliance, policy, issues-actions, reporting

Depends on

consumes its output

risk

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

No items found.

Suites that serve this role

How SmartSuite supports this role

Compliance management. Tracks training completion and policy acknowledgements as evidence for awareness controls.

Policy management. Runs attestation campaigns for security policies with reminders and completion dashboards.

Issues and actions. Logs simulation failures and follow-up actions by team.

Reporting. Reports awareness metrics and behaviour trends to security leadership and auditors.

Industry reference

NIST SP 800-50 Rev. 1 (2024) is the programme guide; ISO/IEC 27001:2022 Annex A 6.3 requires awareness, education and training; the SANS maturity model benchmarks the programme. Awareness is a tested control in SOC 2, PCI DSS (Requirement 12.6) and ISO 27001 audits.

Regulators require it outright: the HIPAA Security Rule's security awareness and training standard, the GLBA Safeguards Rule's staff training requirement, NYDFS 23 NYCRR 500.14, FFIEC guidance for banks, annual security awareness training for US federal staff under FISMA, and NIS2's requirement that management bodies receive cybersecurity training.

In their words

Related roles

Information Security Officer

Information Security Officer

See the role
Chief Information Security Officer

Chief Information Security Officer

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.