Information Security Coordinator – Policy and Training
NXP Semiconductors · Austin, TX · Yesterday
HybridTrainingFull-time
About the Role
The IT Security Policy & Training Coordinator supports the day-to-day governance of enterprise security policies and standards and manages the planning, deployment, and measurement of security trainings for targeted audiences. This role keeps policy artifacts organized and current, streamlines reviews and approvals, and helps translate complex security requirements into clear, actionable, and engaging content (documents, visuals, and short-form video/microlearning). You’ll partner closely with GRC, Security Engineering, IT, Legal, HR, and Corporate Communications to ensure our policies are usable, findable, and adopted – and that trainings are timely, relevant, and measurable.
Responsibilities
- Policy Governance (≈50%)
- Orchestrate policy lifecycle: intake, drafting/editing, SME review, legal/compliance check, approval, publication, and versioning.
- Maintain the policy library (e.g., SharePoint/Confluence): metadata, effective/expiry dates, mappings to frameworks, archives, and cross-references.
- Coordinate working groups: schedule reviews, track comments, resolve feedback, and drive on-time approvals.
- Document control & traceability: maintain revision lifecycle of documents; ensure audit-ready documentation.
- Framework alignment: map policies/standards to NIST CSF/800-53, ISO/IEC 27001/27002, CIS Controls, SOC 2, HIPAA, PCI DSS as applicable.
- Quality & readability: apply organization-wide style standards, correct security language, and technical documentation best practices.
- Communications: draft release notes, FAQs, and briefings for new and updated policies; support targeted rollout plans.
- Training & Awareness (≈40%)
- Coordinate targeted trainings for specific groups (e.g., engineers, admins, finance, HR, contractors): delivered via LMS and microlearning channels.
- Content coordination and light production: assist with storyboards, job aids, one-pagers, infographics, short explainer videos, and slide decks.
- LMS operations: create courses/assignments, track completions, manage reminders, and generate reports for leaders and audits.
- Campaigns & nudges: support awareness activities (e.g., new policy launches, security training refreshers, phishing awareness, data handling).
- Measurement: monitor comprehension and adoption using quizzes, surveys, and behavioral metrics; recommend improvements.
- Operational Excellence (≈10%)
- Metrics & dashboards: maintain KPIs (policy cycle time, review throughput, training completion, quiz scores, sentiment).
- Requests & support: triage and fulfill requests for policy access, clarifications, and exemptions; escalate as needed.
- Continuous improvement: document and refine playbooks, templates, and workflows.
Requirements
- 1–3 years of experience in an IT policy management, GRC, information security, or compliance documentation environment (enterprise experience preferred).
- Technical writing proficiency with a portfolio or samples that demonstrate structured, plain-language writing (policies, standards, SOPs, or knowledge articles).
- Graphic and/or video design skills (foundational): ability to create clean visuals or short videos for training/awareness (e.g., infographics, micro-explainers, motion graphics).
- Experience coordinating document reviews and approvals across multiple stakeholders.
- Familiarity with security frameworks (NIST, ISO 27001/27002, CIS Controls, SOC 2; healthcare/financial regulators a plus).
- Hands-on with collaboration tools (SharePoint, Confluence, Microsoft 365/Teams) and LMS administration basics.
- Strong organization, attention to detail, and follow-through; able to manage multiple deadlines.
- Excellent written and verbal communication skills and stakeholder management.
Preferred Qualifications
- Experience with LMS platforms (e.g., Workday Learning, Cornerstone, Docebo) and formats (SCORM/xAPI).
- Tools: Adobe Creative Cloud (Illustrator, Premiere Pro, After Effects), Camtasia, Articulate 360/Rise, Canva/Vyond, Snagit.
- Familiarity with Jira/ServiceNow for workflow or intake, Power BI/Tableau for reporting.
- Exposure to secure coding, cloud security (AWS, Azure), or data protection concepts.
- Knowledge of accessibility standards (WCAG) and inclusive design for learning content.
- Experience supporting audits or compliance assessments (SOC 2, ISO 27001).
Skills
- Clarity-first communicator: translates technical/security concepts into plain language.
- Process discipline: ensures repeatable, auditable workflows and documentation rigor.
- Collaboration: builds trust with SMEs and business partners; navigates feedback constructively.
- Design mindset: uses visuals and short-form media to improve comprehension and adoption.
- Results & metrics driven: sets targets, reports outcomes, and iterates.
Success Metrics (first 6–12 months)
- ≥ 95% on-time policy review cycles and version control accuracy.
- ≥ 90% training completion on targeted assignments within SLA; average quiz score ≥ 85%.
- Cycle time reduction for policy revisions (baseline minus ≥ 20%).
- Engagement uplift: increase in training satisfaction/utility (e.g., +10 pts CSAT or survey results).
- Audit readiness: complete, traceable policy artifacts and training records for audits/exams.