
Information Security Coordinator β Policy and Training
- Confluence
- CIS Controls
- SOC2
- HIPAA
- PCI DSS
- triage
- Technical Writing
- NIST
- ISO 27001
- Adobe Creative Cloud
- Illustrator
- Camtasia
- Jira
- ServiceNow
- Power BI
- Tableau
- AWS
- Azure
- WCAG
Role Summary
TheIT Security Policy & Training Coordinator supports the day-to-day governance of enterprise security policies and standards and manages the planning, deployment, and measurement of security trainings for targeted audiences. This role keeps policy artifacts organized and current, streamlines reviews and approvals, and helps translate complex security requirements into clear, actionable, and engaging content (documents, visuals, and short-form video/microlearning). Youβll partner closely with GRC, Security Engineering, IT, Legal, HR, and Corporate Communications to ensure our policies are usable, findable, and adopted β and that trainings are timely, relevant, and measurable.
What Youβll Do
Policy Governance (β50%)
- Orchestrate policy lifecycle: intake, drafting/editing, SME review, legal/compliance check, approval, publication, and versioning.
- Maintain the policy library (e.g., SharePoint/Confluence): metadata, effective/expiry dates, mappings to frameworks, archives, and cross-references.
- Coordinate working groups: schedule reviews, track comments, resolve feedback, and drive on-time approvals.
- Document control & traceability: maintain revision lifecycle of documents; ensure audit-ready documentation.
- Framework alignment: map policies/standards to NIST CSF/800-53, ISO/IEC 27001/27002, CIS Controls, SOC 2, HIPAA, PCI DSS as applicable.
- Quality & readability: apply organization-wide style standards, correct security language, and technical documentation best practices.
- Communications: draft release notes, FAQs, and briefings for new and updated policies; support targeted rollout plans.
Training & Awareness (β40%)
- Coordinate targeted trainings for specific groups (e.g., engineers, admins, finance, HR, contractors): delivered via LMS and microlearning channels.
- Content coordination and light production: assist with storyboards, job aids, one-pagers, infographics, short explainer videos, and slide decks.
- LMS operations: create courses/assignments, track completions, manage reminders, and generate reports for leaders and audits.
- Campaigns & nudges: support awareness activities (e.g., new policy launches, security training refreshers, phishing awareness, data handling).
- Measurement: monitor comprehension and adoption using quizzes, surveys, and behavioral metrics; recommend improvements.
Operational Excellence (β10%)
- Metrics & dashboards: maintain KPIs (policy cycle time, review throughput, training completion, quiz scores, sentiment).
- Requests & support: triage and fulfill requests for policy access, clarifications, and exemptions; escalate as needed.
- Continuous improvement: document and refine playbooks, templates, and workflows.
Minimum Qualifications
- 1β3 years of experience in anIT policy management, GRC, information security, or compliance documentation environment (enterprise experience preferred).
- Technical writing proficiency with a portfolio or samples that demonstrate structured, plain-language writing (policies, standards, SOPs, or knowledge articles).
- Graphic and/or video design skills (foundational): ability to create clean visuals or short videos for training/awareness (e.g., infographics, micro-explainers, motion graphics).
- Experience coordinatingdocument reviews and approvals across multiple stakeholders.
- Familiarity withsecurity frameworks (NIST, ISO 27001/27002, CIS Controls, SOC 2; healthcare/financial regulators a plus).
- Hands-on withcollaboration tools (SharePoint, Confluence, Microsoft 365/Teams) andLMS administration basics.
- Strongorganization, attention to detail, and follow-through; able to manage multiple deadlines.
- Excellentwritten and verbal communication skills and stakeholder management.
Preferred Qualifications
- Experience withLMS platforms (e.g., Workday Learning, Cornerstone, Docebo) and formats (SCORM/xAPI).
- Tools:Adobe Creative Cloud (Illustrator, Premiere Pro, After Effects),Camtasia,Articulate 360/Rise,Cavnva/Vyond,Snagit.
- Familiarity withJira/ServiceNow for workflow or intake,Power BI/Tableau for reporting.
- Exposure tosecure coding,cloud security (AWS, Azure), ordata protection concepts.
- Knowledge ofaccessibility standards (WCAG) and inclusive design for learning content.
- Experience supportingaudits or compliance assessments (SOC 2, ISO 27001).
Core Competencies
- Clarity-first communicator: translates technical/security concepts into plain language.
- Process discipline: ensures repeatable, auditable workflows and documentation rigor.
- Collaboration: builds trust with SMEs and business partners; navigates feedback constructively.
- Design mindset: uses visuals and short-form media to improve comprehension and adoption.
- Results & metrics driven: sets targets, reports outcomes, and iterates.
Success Metrics (first 6β12 months)
- β₯95% on-timepolicy review cycles and version control accuracy.
- β₯90%training completion on targeted assignments within SLA; average quiz score β₯85%.
- Cycle time reduction for policy revisions (baseline minus β₯20%).
- Engagement uplift: increase in training satisfaction/utility (e.g., +10 pts CSAT or survey results).
- Audit readiness: complete, traceable policy artifacts and training records for audits/exams.
More information about NXP in the United States...
NXP is an EqualOpportunity/Affirmative Action Employer regardless of age, color, national origin, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, marital status, status as a disabled veteran and/or veteran of the Vietnam Era or any other characteristic protected by federal, state or local law. In addition, NXP will provide reasonable accommodations for otherwise qualified disabled individuals.
#LI-97b2Information Security Coordinator β Policy and Training Β· NXP USA Inc.