Careers
August 8, 2026
Your CV Is Speaking the Wrong Language

# Jobs
# Opportunities
# Careers
Why security awareness has a career ceiling, and what the market actually calls the work you're already doing

Ant Davis

Your CV Is Speaking the Wrong Language
Part 1 of a two-part discussion on security awareness, enablement, and where the discipline goes next.
Security awareness has a ceiling, and it comes faster than most people expect.
Get a few years in and you're already close to it. When you get past a certain point, the salaries stop moving. The next step up is usually head of, or director, and those roles only really exist in the largest organisations, the ones with budget for a whole security culture team rather than a single person doing everything. Even then, half the time that seat is barely the job anymore. It's a step away from the work itself, into something more strategic, more about managing other people's work than doing your own.
Below that ceiling, the job market is thin. Ask around and most practitioners will tell you the same thing, there's rarely more than a handful of relevant roles open at any one time, and they all seem to land at once. Whether you find something often comes down to luck, being the person who happened to be looking the week the right role appeared, rather than any real reflection of how good you are at the job.
So if the ceiling within security awareness is this low, and this narrow, where else could that skill set actually go.
Enablement as a path, not just a label
This is where enablement gets interesting, and not just as a rewording exercise. Sales enablement and customer enablement are established, growing functions with their own career ladders, their own salary bands, and a lot more roles open at any given time than security awareness has.
Part of why the fit is so strong is that enablement isn't just one thing borrowed from one team. It covers ground that overlaps with internal comms, with change management, with learning and development, but it isn't limited to any single one of them. The newsletters and campaigns that keep a message alive across a workforce are internal comms skills, but stakeholder work, coaching, and measuring behaviour change go beyond what a comms function typically owns. Enablement is the wider category that actually holds all of it together.
Strip away the topic and the core skill set is close to identical, the same stakeholder management, coaching, storytelling and programme design, the same focus on measuring behaviour change rather than just completion. If the lines between security awareness and enablement blurred properly, a lot of practitioners who feel stuck at the top of a narrow ladder might find there's a much wider one standing right next to it.
I checked one of the job market tracking sites, the kind that logs every UK vacancy and tells you what's in demand and what it pays. Security awareness doesn't show up as its own category. It's not tracked on its own. It gets buried inside broader titles like security manager or information security management.
Enablement is different. It's tracked, priced, and has its own salary bands, its own regional breakdown, and its own list of co-occurring skills, the same ones already named above. The exact things security awareness practitioners do every day.
We're doing a recognised job. We're just calling it by a name the market doesn't recognise.
And this isn't just a language shift practitioners could make on their own CVs. It's already showing up at the top of the industry. Security leaders Nicholas McBride and Stuart Clark presented a whole model for it at HOU.SEC.CON , built around a "protect, enable, engage" framework, where security's job is defined as actively driving business outcomes rather than sitting there as a cost centre saying no. If CISOs are already building their functions around enablement, it's not a huge leap for the practitioners underneath them to start describing their own work the same way.
What are we actually good at, and what do we actually enjoy
If the lines blurred and a move like this became genuinely realistic, there's a more honest question to ask first. What is it that most of us actually enjoy about this work.
Is it the topic, the threat landscape, the technical side, staying close to what's actually putting the business at risk. Or is it the enablement side of it, the stakeholder relationships, the content and storytelling, watching someone's behaviour actually change because of something you built.
For a lot of practitioners I think it's the second one, and security just happens to be the subject matter it's been applied to. If that's true, the skill set was never really about phishing or passwords in the first place, it was about influence and behaviour change, and security was simply where that got learned. Don't assume too quickly that the topic itself is the part you'd miss.
The same work, different words
So I pulled apart a typical CV from this field, the kind most of us have written a version of, and rewrote it line by line. The work doesn't change. The language does.
Before:
Led the design and delivery of a security awareness strategy, building the training and communication programmes that helped employees work securely.
After:
Led the design and delivery of a security enablement strategy, building the training, communication, and engagement programmes that helped employees work securely without slowing down their day-to-day work.
Before:
Built an 85-strong champions network across the business.
After:
Built and led an 85-strong champions network, designing the onboarding, training, and ongoing support materials that kept it active across the organisation.
Before:
Ran phishing simulation campaigns across the business.
After:
Delivered risk-based behavioural coaching at the point of need, using simulation data to identify risky habits and correct them before they became real incidents.
Before:
Delivered annual security awareness training to all staff.
After:
Designed and delivered a continuous enablement programme embedded across the year, rather than a single annual compliance exercise.
Nothing here has been exaggerated, it's the same years and the same wins. But the second version reads as a recognised discipline with a defined skill set, not a niche security function.
A quick audit for your own CV
If you want to try this yourself, look for the giveaway words first, awareness, training, campaigns, and ask what the enablement equivalent is, strategy, programme, content, engagement.
Then look at who you were actually serving, whether that's employees, customers, or partners. Use their language, not security's. A champions network isn't just an awareness tactic, it's an onboarding and support programme. A newsletter isn't just a comms channel, it's a content and engagement strategy.
Last, check your bullets for outcomes, not just activity. Enablement language tends to lead with what changed for the audience, not just what you delivered.
Where this leaves us
Rewriting your own CV is one thing. Whether the discipline itself should adopt this language, in job titles and not just individual applications, is a bigger question, and I don't think it has a clean answer yet.
That's Part 2. Before I get into the case for and against actually renaming the function, I want to hear where practitioners in this community land on it. Would you take a title like Security Enablement Lead over Security Awareness Manager if it were offered to you tomorrow? Does the security part of the title matter to you, or is it the part you'd happily let go?
And underneath all of it is the question I keep coming back to. When you say you love this job, what are you actually describing. Is it the cyber, or is it the enablement. Drop your answer in the comments, I'll be pulling some of them into Part 2.
2
Comment (1)
Popular
Dive in
Related
Content
Free Cybersecurity Month toolkits, for when you can't build it all
By Maxime Cartier • Aug 20th, 2026 • Views 31
Content
Free Cybersecurity Month toolkits, for when you can't build it all
By Maxime Cartier • Aug 20th, 2026 • Views 31

