Senior Information Security Risk Manager

Statkraft

Oslo

On-site

NOK 1,100,000 - 1,500,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Unlimited learning opportunities
Global network of experts
Flexible working arrangements
Competitive terms of employment

Job summary

Statkraft is seeking a Senior Information Security Risk Manager to strengthen the Information Security Management team and drive risk governance and improvement across its global operations. The role focuses on risk assessment, treatment, and stakeholder advisory across business units and digital teams.

You will develop risk management practices, maintain risk registers, and promote a strong security culture, reporting to the Head of Risk Management within ISM.

Qualifications

  • Master's degree or equivalent in information security or related field.
  • 5–8 years of experience in information security, risk management, governance, or compliance.
  • Experience conducting security risk assessments and facilitating risk treatment.
  • Strong knowledge of security governance frameworks and standards (ISO/IEC 27001, ISO/IEC 27005, NIST CSF).
  • Excellent communication and presentation skills in English.

Responsibilities

  • Lead and facilitate information security risk assessments across global processes, systems, and services.
  • Advise leaders on information security risks and mitigation strategies for informed risk-based decisions.
  • Maintain risk registers and monitor treatment progress and effectiveness of controls.
  • Report on evolving risk landscape to key stakeholders and drive continuous improvement of methodologies.
  • Develop and deliver security governance practices and risk awareness across the organization.

Skills

Stakeholder management
Communication
Analytical thinking
Strategic thinking
Risk management

Education

Master's degree in Information Security

Tools

ISO/IEC 27001
NIST Cybersecurity Framework
ISO/IEC 27005

Job description

At Statkraft, we are committed to securing the systems, information, and digital capabilities that enable the transition to a renewable future. As Europe's largest generator of renewable energy, we operate in more than 20 countries and depend on secure, resilient, and well-governed information and technology services.

We are looking for aSenior Information SecurityRiskManagerto strengthen our Information Security Management team and help drive security risk management, governance, and continuous improvement across Statkraft's global operations.

As Senior Information SecurityRiskManager, you willassist in identifying, analysing, treating and monitoring information security risks in Statkraft.You willact as a trusted advisor to business and technology stakeholders, helping them understand and manage information security and technology risks.

You will support the development and implementation of security governance practices, conduct risk assessments, facilitate risk treatment activities, and contribute to a strong security culture throughout the company.

The role combines strategic advisory work, stakeholder management, and hands-on risk management activities. You will work closely with business units, digital teams, cyber security specialists, risk owners, anddifferent levels ofmanagement.

The position reports to“Head of Risk Management”withintheInformation Security Management department.

Areas of responsibilities and accountabilities:
InformationSecurity Risk Management
  • Lead and facilitate information security risk assessments across business processes, systems, and servicesin Statkraft globally.
  • Advise business leaders, product owners, and process owners on information security risks and mitigation strategies, and support management in making informed risk-based decisions.
  • Maintain risk registers and monitor risk treatment progress and effectiveness of implemented security measures.
  • Report on the continuously changing and evolving risk landscape to key stakeholders.
  • Contribute to continuous improvement of information security methodologies, tools, and processes.
Security Culture and Awareness
  • Develop and deliver security awareness and training initiatives.
  • Promote risk ownership throughout the organisation.
  • Support the continued development of Statkraft's information security culture.
Stakeholder Management
  • Build strong relationships with business stakeholders across multiple countries and functions.
  • Translate technical and security-related topics into business-relevant language.
  • Facilitate discussions between business, technology, and security teams to achieve practical risk-based outcomes.
Required
  • Master's degree or equivalent experience in Information Security, Cyber Security, Risk Management, Information Systems, or a related discipline.
  • Minimum5-8 years of experience within information security, cyber security, IT risk management, governance, or compliance.
  • Strong experience conducting security risk assessments and facilitating risk treatment.
  • Excellent understanding of security governance frameworks and standards such as: ISO/IEC27001, ISO/IEC 27005, NIST Cybersecurity Framework, Risk management methodologies and control frameworks.
  • Experience working with senior business stakeholders and management teams.
  • Strong communication and presentation skills in English.
Preferred
  • Experience from critical infrastructure, energy, utilities, or industrial environments.
  • Professional certifications such as:CISSP, CISM, CRISC, ISO 27001 Lead Implementer or Lead Auditor.
  • Experience supporting audits, regulatory compliance, and internal control frameworks.
Personal Qualities

We are looking for someone who:

  • Thinks strategically while remaining pragmatic.
  • Builds trust and influences without formal authority.
  • Is comfortable challenging assumptions and driving improvement.
  • Has strong analytical and problem-solving skills.
  • Communicates effectively with both technical and non-technical audiences.
  • Thrives in a collaborative and international environment.
Whatweoffer
  • Unlimited learning opportunities at various levels of the organization
  • The chance to grow your career alongside a truly global network of experts, leaders, specialists, and graduates from different countries and backgrounds
  • The opportunity to work somewhere with pride, and be able to honestly say “My work is contributing to saving the planet”
  • A work culture that puts emphasis on the individual, offering flexible working solutions, and work-life balance principles
  • Statkraft offers competitive terms of employment and benefit schemes, andwe’rea trusted employer that puts the safety of our people first. We believe that a safe and healthy working environment is a matter of choice, not chance

Statkraft manages critical infrastructure and services in several countries. The applicant must be eligible for security clearance and authorization.

Statkraft's vision is to renew the way the world is powered. To navigate the complex journey ahead, we need every voice at the table. We therefore work actively to be a diverse and inclusive workplace and welcome all applicants regardless of background, gender, age, sexual orientation, religious belief, ethnicity,nationalityor disability.

Application deadline:

16.09.26

Location:

Oslo

For further information please contact Øystein Dalheim, email: oystein.dalheim@statkraft.com.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Vice President HSS
Senior Vice President HSS

Statkraft • Oslo

On-site
NOK 900,000 - 1,400,000
Senior Vice President HSS
Senior Vice President HSS

Statkraft AS • Oslo

On-site
NOK 2,500,000 - 4,000,000
Senior Manager, Corporate Strategy
Senior Manager, Corporate Strategy

Statkraft • Oslo

On-site
NOK 1,500,000 - 2,100,000
International environment
Professional development
Flexible working arrangements
+2
Senior HR Business Partner, Organisational Development & Change
Senior HR Business Partner, Organisational Development & Change

Statkraft • Oslo

On-site
NOK 900,000 - 1,200,000
Flexible working arrangements
Pension and insurance schemes
EV charging facilities
Senior HR Business Partner, Organisational Development & Change
Senior HR Business Partner, Organisational Development & Change

Statkraft AS • Oslo

Hybrid
NOK 900,000 - 1,300,000
Flexible working arrangements
Pension and insurance schemes
Access to sports clubs and fitness
+1
Senior Vice President Head of Performance Management
Senior Vice President Head of Performance Management

Statkraft • Oslo

On-site
NOK 2,000,000 - 3,200,000
Unlimited learning opportunities
Global network of experts
Pride in our work – impact on energy
+1
Senior HR Business Partner, Organisational Development & Change
Senior HR Business Partner, Organisational Development & Change

SmartRecruiters, Inc. • Oslo

On-site
NOK 1,000,000 - 1,400,000
Competitive pension
Insurance schemes
Flexibie working arrangements
+2
Power Platform Manager
Power Platform Manager

Statkraft • Oslo

On-site
NOK 900,000 - 1,200,000
Senior Advisor - Market Regulatory Affairs
Senior Advisor - Market Regulatory Affairs

Statkraft group. • Oslo

On-site
NOK 900,000 - 1,200,000
Professional development
International environment
Competitive compensation
+2
Senior Software Developer
Senior Software Developer

Statkraft • Oslo

On-site
NOK 700,000 - 900,000