Who We Are
Creative Artists Agency (CAA) is the leading entertainment and sports agency, with global expertise in filmed and live entertainment, digital media, publishing, sponsorship sales and endorsements, media finance, consumer investing, fashion, trademark licensing, and philanthropy. Distinguished by its culture of collaboration and exceptional client service, CAA’s diverse workforce identifies, innovates, and amplifies opportunities for the people and organizations that shape culture and inspire the world. The trailblazer of the agency business, CAA was the first to build a sports business, create an investment bank, launch a venture fund, found technology start-up companies, establish a philanthropic arm, build a business in China, and form a brand marketing services division, among other innovations. Named Most Valuable Sports Agency by Forbes for eight consecutive years, CAA represents more than 2,000 of the world’s top athletes in football, baseball, basketball, hockey, soccer, in addition to coaches, on-air broadcasters, and sports personalities and works in the areas of broadcast rights, corporate marketing initiatives, social impact, and sports properties for sales and sponsorship opportunities. Founded in 1975, CAA is headquartered in Los Angeles, and has offices in New York, Nashville, Memphis, Chicago, Miami, London, Munich, Geneva, Stockholm, Shanghai, and Beijing, among other locations globally.
Summary
Reporting to the CAA Deputy CISO this is a hands-on security leadership position working within the Information Risk Management (IRM) group and delivering solutions to the company at large. The core focus of this position is to develop and deliver the strategies, plans and execution support for the Information Security Training and Awareness Program. This role will develop and deliver awareness and training materials through various means including in-person, online learning, newsletters, and email. This person will work closely with functional Tech and business leads to align awareness deliverables to the highest risk activities and behaviors. The successful candidate will ensure the information security awareness program communicates security policies and requirements in a manner that is clear, action oriented and measurable.
We are looking for candidates who are self-driven and possess a mastery of security awareness and have a passion for data protection, personal information security and communications. Broad cybersecurity experience, and ability to correlate and convert technical signals into security awareness opportunities is desired. In a highly end-user centric environment, candidate must identify relevant awareness communications and distribute them promptly.
The candidate will play a key role in our teams’ efforts to build and support a defensible environment where we are able to detect, contain and respond quickly to data security threats and compromise in ways that serve to enable the business needs of a highly collaborative organization. The environment is fast-paced and commonly on the leading edge of technology, including early adoption of various cloud services along with the challenges of integrating those services into our security practices.
Responsibilities
Lead an information security awareness program that effectively engages employees resulting in measurable improvements in behavior
Partner with key teams such as Service Desk, HR Learning, Privacy and Compliance, to develop training to support the security awareness and data protection efforts
Proactive identification of current security events, determine applicability to CAA, and develop appropriate communications
In collaboration with other IRM team members, create and distribute training or awareness communication for IRM programs
Effective communication of CAA Policies and Standards to the Tech team and broader Agency and cross functional stakeholders
Develop and implement real-time awareness capabilities triggered at the point of risky behaviors identified in incident response or other technology workflows
In coordination with CAA Tech functional owners and the user community, provide solutions to reduce risk of sensitive information workflows and developing risk mitigations and training plans
Plan and administer information security and privacy training through online learning management systems and in person methods.
Prepare and deliver targeted awareness campaigns (cybersecurity month, phishing simulations, security newsletter)
Develop and maintain metrics measuring the results of individual campaigns and overall program effectiveness
Play an active role in CAA’s security incident response efforts, working to identify and mitigate information security threats
Required Capabilities
Minimum 8 years of Information Security experience with a Bachelor’s Degree
Minimum 3 years experience in a Security Awareness function
Experience in a leadership or managerial position is required
Marketing or Communications experience a plus
Ability to communicate complex messages in a clear and concise manner with stakeholders at all levels
Excellent organizational skills and ability to communicate with internal/external entities and executives
Effective leadership skills with demonstrated ability to coordinate people and teams to project/activity completion
Ability to work in team environment sharing responsibilities
Ability to work in a flexible environment where requirements and procedures continuously evolve
Experience with contractual and regulatory standards such as PCI, GDPR
Certification in information security (CISSP, CISM, GIAC, or equivalent) preferred
A capable professional writer, able to research and prepare high quality, clearly written awareness, and training materials
Proactive and self-motivated, taking the lead on security awareness and training activities
Location
This role will be based in our Los Angeles, CA office, Monday – Friday; hybrid.
Compensation
The annual base salary for this position is in the range of $139,000 - $160,000. This position also is eligible for benefits and discretionary bonus. Ultimately, the salary may vary based upon, but not limited to, relevant experience, time in role, business sector, and geographic location, among other criteria. Please talk with a CAA Recruiter to learn more.
Creative Artists Agency, LLC (the “Company”) is committed to a policy of Equal Employment Opportunity and will not discriminate on the basis of race (inclusive of traits historically associated with race, including hair texture and protective hairstyles), color, religion, creed, gender or sex (including pregnancy, childbirth, breastfeeding or related medical conditions), national origin, ancestry, age, physical disability, mental disability, medical condition, genetic information, family and medical care leave status, military or veteran status, marital status, family status, sexual orientation, gender identity, gender expression, political affiliation, an employee’s or their dependent’s reproductive health decision making (e.g., the decision to use or access a particular drug, device or medical service), or any other characteristic protected by applicable law. The Company also complies with the Americans with Disabilities Act and applicable state and local laws with regard to providing reasonable accommodation for qualified individuals with disabilities. CAA does not accept unsolicited resumes from third-party recruiters unless they were contractually engaged by CAA to provide candidates for a specified opening. Any such employment agency, person or entity that submits an unsolicited resume does so with the acknowledgement and agreement that CAA will have the right to hire that applicant at its discretion without any fee owed to the submitting employment agency, person or entity.