Related Posts
So I've had 2 hiring managers and several recruiters from Amazon reach out to me about applying for some open positions with the company (android). I completed the coding assessment and now they want me to go through a round of 5 hour interviews next week. Is there a good chance I'll be hired if engineering managers are reaching out to me? I'm really not sure how badly I want to work for them and I don't want to be laid off months after being hired on. Anyone know what Amazon hiring is like?
Additional Posts in Cyber Security Bowl
New to Fishbowl?
unlock all discussions on Fishbowl.




The problem is that mandatory security awareness training is something that’s required from a legal / risk / compliance perspective. So there’s no getting rid of the exercise itself.
But there’s nothing really mandating HOW you conduct the training itself. There are options ranging to gamification of the results themselves (showing recognition centrally on those who pass those activities on the first attempt, for instance), as well as more punitive measures (click on a phishing exercise link three times, you’re fired).
The most effective method is likely in the middle, with executive leadership setting the right “tone at the top” - if leadership only looks at security awareness training as a compliance activity (most do), it will never be elevated above other “check the box” compliance activities (e.g., HIPAA responsibilities in healthcare, AML/KYC for banking, etc.)
I don’t know about that. I used to run the simulations as part of my side duties. Awareness training for a few orgs help over time. How effective give your training is usually tied to relevance via customization, engagement, and quality. How to measure effectiveness you correlate the click and open metrics over time too. The human really is the weakest link