Model job description

Cyber-Aware Business Professional Model Job Description

This evidence-derived model adds a practical cybersecurity-responsibility layer to an existing non-technical role while keeping technical, legal, privacy and security decisions with authorized specialists.

Build practical workplace cybersecurity capabilities
Resource
Model job description
Evidence
United States
Reviewed
September 15, 2026
Format
Reusable professional guide

An evidence-derived model job description for non-technical professionals who protect accounts, information, supplier access and incident handoffs in everyday work.

Evidence scope: A frozen structured purposive sample of 100 current U.S.-scoped vacancies from 92 employers plus a separate 23-source current-trend review; the vacancy sample is not nationally representative.

How to use this model

This model describes a cybersecurity-responsibility layer that can be added to an existing non-technical job description. It is not a claim that “Cyber-Aware Business Professional” is one occupation or that every employee owns every activity. Adapt the responsibilities to the actual role, information, systems, decision rights, sector, and organizational procedures. Technical investigation, legal interpretation, privacy determinations, security administration, and external incident communication remain with authorized specialists.

Capability purpose

The professional protects workplace accounts, communications, business information, and third-party access during ordinary work. They pause and independently verify unusual or high-consequence requests, use approved systems and sharing methods, preserve accurate records, report suspicious activity promptly, and cooperate with the people responsible for security, privacy, IT, finance, procurement, HR, legal, and management decisions.

Typical reporting line and interfaces

The capability applies within the person's existing reporting line. Common interfaces include the line manager, service desk, information-security team, privacy or data-protection owner, finance, procurement, legal or compliance, HR, records management, client-service owners, and approved supplier contacts. The person follows the organization's named route rather than choosing an external contact or investigative action independently.

Core responsibilities for employees

Suspicious requests and phishing

  • Examine the sender, channel, context, timing, requested action, and consequence before acting.
  • Treat urgency, secrecy, unusual payment or access requests, lookalike addresses, unexpected links or attachments, and authentication prompts as reasons to pause and verify, not as automatic proof.
  • Verify identity or intent through a trusted path already known to the organization, not through a number, link, or contact supplied in the questionable request.
  • Report promptly through the approved internal route and preserve relevant facts without forwarding suspicious material widely.

Passwords, authentication, and accounts

  • Use unique passwords and an approved password manager where available.
  • Protect authentication, recovery, and session information; never share a password or one-time code.
  • Use assigned multi-factor authentication or passkeys and reject unexpected approval prompts.
  • Contact the authorized support route when account behavior, recovery, access, or sign-in activity is unexpected.

Data handling

  • Recognize information that may be sensitive because of its content, combination, business purpose, or local classification.
  • Confirm recipient, purpose, minimum necessary content, channel, access setting, and expiry before sharing.
  • Use approved repositories and apply assigned retention, transfer, archive, and disposal procedures.
  • Avoid entering confidential, personal, or live incident information into unapproved collaboration or AI tools.
  • Act within procedure after a misdirected message, lost device, broad sharing link, or other possible exposure, then report promptly.

Vendors and third parties

  • Use approved supplier identities and contacts for verification.
  • Limit access and disclosure to the documented business purpose and authorized scope.
  • Provide requested due-diligence facts accurately and route contractual, security, privacy, financial, and legal questions to the appropriate owner.
  • Surface expired, excessive, ownerless, or unnecessary third-party access for review.

Incident reporting and cyber hygiene

  • Record what was observed, when it occurred, what business work is affected, what safe action was taken, and what support is needed.
  • Separate fact from inference and avoid declaring a cause or impact that has not been assessed.
  • Keep work devices updated through approved mechanisms, use approved software and storage, lock unattended devices, and protect visible or audible information.
  • Complete assigned training and recurring reviews, and apply lessons to real workflows.

Additional responsibilities for supervisors and leaders

  • Make reporting easy and psychologically safe; reward early escalation and avoid blaming the reporter for raising a concern.
  • Translate organizational expectations into concrete routines for the team's actual communication, data, account, vendor, and remote-work tasks.
  • Confirm that staff know the authorized verification, service-desk, finance, privacy, and management routes.
  • Maintain temporary business safeguards while specialist review proceeds, without presenting them as technical conclusions.
  • Review access, vendor ownership, recurring exceptions, and corrective actions at the locally approved cadence.
  • Coordinate concise status updates and ensure that external communication is owned and authorized.
  • Test team readiness through bounded fictional exercises and use results to remove friction, clarify ownership, and improve procedures.

Expected work products

Useful outputs may include a suspicious-message triage record, independent verification note, account-support ticket, safe-sharing decision, data-lifecycle checklist, vendor-intake record, access-review note, incident handoff, team cyber-hygiene routine, or exercise improvement plan. The exact product depends on the person's role. A sound product identifies context, source facts, action within authority, owner, uncertainty, exception, and next step without copying unnecessary sensitive information.

Required capabilities

  • Clear written and verbal communication under time pressure.
  • Careful attention to identity, authorization, recipient, access, and unusual context.
  • Ability to follow procedure while recognizing when an exception needs escalation.
  • Accurate record keeping and minimum-necessary information sharing.
  • Sound judgment about what may be done locally and what belongs to a specialist.
  • Willingness to ask a precise question, preserve uncertainty, and report early.
  • Practical use of approved communication, collaboration, ticketing, document, identity, training, and business systems relevant to the existing role.

Evidence of capability

Suitable evidence includes a sanitized example of a verification or incident handoff; a safe-sharing or vendor-access review; completion of a recognized workplace-security learning program; participation in a fictional exercise; an improvement that reduced recurring access, sharing, or reporting friction; and measured completion or quality results. Evidence must be truthful, authorized for disclosure, and stripped of confidential details.

Experience and levels

This responsibility layer does not require a separate cybersecurity job title. At an entry level, the person follows approved checks, protects assigned accounts and data, and reports observable facts. At an experienced individual-contributor level, the person improves repeatable workflows and supports colleagues. At a supervisor or leader level, the person sets team routines, assigns business owners, reviews exceptions, and coordinates specialist handoffs. Local employers should define the experience, tools and systems appropriate to the underlying business role.

Success measures

Organizations should choose measures that fit the work. Examples include reporting timeliness, completeness of initial handoffs, proportion of high-consequence requests independently verified, resolution of ownerless access, completion of assigned reviews, reduction in repeated sharing errors, exercise performance, and closure of agreed corrective actions. Click counts or training completion alone do not prove safer behavior, and incident counts need careful interpretation because more reporting can reflect better awareness.

Decision rights and escalation

The professional may pause a questionable action, decline an unexpected authentication request, verify through an approved independent route, restrict sharing or secure a device when an explicit procedure authorizes that step, preserve relevant facts, and open an internal report. They do not conduct unauthorized technical investigation, change security controls, access data beyond their role, contact an alleged attacker, approve their own vendor or payment exception, declare a legal or privacy event, or notify clients, regulators, insurers, law enforcement, or the public without authorized ownership.

Explicit limits

This model is vendor-neutral and does not replace an employer's job evaluation, security policy, incident plan, legal advice, collective agreement, or sector rules. It does not promise prevention, certification for a technical security role, employment, promotion, or earnings. Use it as an adaptable responsibility layer for the real job.

Local adaptation checklist and reusable model

Local adaptation checklist and reusable model

  • Replace generic role names with the organization's real owners and approved reporting routes.
  • Match responsibilities to the person's actual systems, information, supplier access and decision rights.
  • State which actions the person may take, may recommend, and must escalate.
  • Add the correct daily, weekly, monthly and event-driven cadence for the underlying business role.
  • Confirm required experience, tools, systems, success measures and evidence with the employer before use.

Use this model as a structured starting point, not as a live vacancy or universal employer policy.

Quick reference

Use the resource in five moves

  1. Read the role purpose and expected outputs.
  2. Compare the model with the local role and authority boundaries.
  3. Select only statements supported by real evidence.
  4. Adapt the reusable fields without inventing experience or approvals.
  5. Review the result with the accountable person before operational use.