Senior Information Security Risk Manager

Statkraft

Oslo

On-site

NOK 900,000 - 1,300,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Unlimited learning opportunities
Global network of experts
Flexible working solutions
Competitive terms of employment

Job summary

Statkraft is seeking a Senior Information Security Risk Manager to strengthen the Information Security Management team. You will drive security risk management, governance, and continuous improvement across Statkraft's global operations from Oslo.

You will identify, analyse, treat and monitor information security risks, advise stakeholders, and support development of security governance. Strong communication in English is essential.

Qualifications

  • Master's degree or equivalent in information security, cyber security, risk management or related field.
  • 5–8 years of experience in information security, IT risk management, governance or compliance.
  • Experience conducting security risk assessments and facilitating risk treatment.
  • Strong understanding of governance frameworks and standards such as ISO/IEC 27001, ISO/IEC 27005, NIST CSF.
  • Experience with senior stakeholders and management; strong English communication.

Responsibilities

  • Lead and facilitate information security risk assessments across global processes, systems and services.
  • Advise leaders on information security risks and mitigation; support risk-based decisions.
  • Maintain risk registers and monitor treatment progress and effectiveness.
  • Develop governance practices, report risk landscape to stakeholders, and drive improvements.

Skills

Risk management
Information security
Stakeholder management
Security governance
Risk assessments
Communication

Education

Master's degree in Information Security or related

Tools

ISO 27001
ISO 27005
NIST CSF

Job description

Senior Information Security Risk Manager
  • Full-time
  • Business Units: TC - Digital Resilience

At Statkraft, we are committed to securing the systems, information, and digital capabilities that enable the transition to a renewable future. As Europe's largest generator of renewable energy, we operate in more than 20 countries and depend on secure, resilient, and well-governed information and technology services.

We are looking for a Senior Information SecurityRiskManager to strengthen our Information Security Management team and help drive security risk management, governance, and continuous improvement across Statkraft's global operations.

As Senior Information SecurityRiskManager, you willassist in identifying, analysing, treating and monitoring information security risks in Statkraft.You willact as a trusted advisor to business and technology stakeholders, helping them understand and manage information security and technology risks.

You will support the development and implementation of security governance practices, conduct risk assessments, facilitate risk treatment activities, and contribute to a strong security culture throughout the company.

The role combines strategic advisory work, stakeholder management, and hands on risk management activities. You will work closely with business units, digital teams, cyber security specialists, risk owners, and different levels of management.

The position reports to “Head of Risk Management”within the Information Security Management department.

Areas of responsibilities and accountabilities:
InformationSecurity Risk Management
  • Lead and facilitate information security risk assessments across business processes, systems, and servicesin Statkraft globally.
  • Advise business leaders, product owners, and process owners on information security risks and mitigation strategies, and support management in making informed risk-based decisions.
  • Maintain risk registers and monitor risk treatment progress and effectiveness of implemented security measures.
  • Report on the continuously changing and evolving risk landscape to key stakeholders.
  • Contribute to continuous improvement of information security methodologies, tools, and processes.
Security Culture and Awareness
  • Develop and deliver security awareness and training initiatives.
  • Promote risk ownership throughout the organisation.
  • Support the continued development of Statkraft's information security culture.
Stakeholder Management
  • Build strong relationships with business stakeholders across multiple countries and functions.
  • Translate technical and security-related topics into business-relevant language.
  • Facilitate discussions between business, technology, and security teams to achieve practical risk-based outcomes.
Required
  • Master's degree or equivalent experience in Information Security, Cyber Security, Risk Management, Information Systems, or a related discipline.
  • Minimum5-8 years of experience within information security, cyber security, IT risk management, governance, or compliance.
  • Strong experience conducting security risk assessments and facilitating risk treatment.
  • Excellent understanding of security governance frameworks and standards such as: ISO/IEC27001, ISO/IEC 27005, NIST Cybersecurity Framework, Risk management methodologies and control frameworks.
  • Experience working with senior business stakeholders and management teams.
  • Strong communication and presentation skills in English.
Preferred
  • Experience from critical infrastructure, energy, utilities, or industrial environments.
  • Professional certifications such as:CISSP, CISM, CRISC, ISO 27001 Lead Implementer or Lead Auditor.
  • Experience supporting audits, regulatory compliance, and internal control frameworks.
Personal Qualities
We are looking for someone who:
  • Thinks strategically while remaining pragmatic.
  • Builds trust and influences without formal authority.
  • Is comfortable challenging assumptions and driving improvement.
  • Has strong analytical and problem-solving skills.
  • Communicates effectively with both technical and non-technical audiences.
  • Thrives in a collaborative and international environment.
Whatweoffer
  • Unlimited learning opportunities at various levels of the organization
  • The chance to grow your career alongside a truly global network of experts, leaders, specialists, and graduates from different countries and backgrounds
  • The opportunity to work somewhere with pride, and be able to honestly say “My work is contributing to saving the planet”
  • A work culture that puts emphasis on the individual, offering flexible working solutions, and work-life balance principles
  • Statkraft offers competitive terms of employment and benefit schemes, andwe’rea trusted employer that puts the safety of our people first. We believe that a safe and healthy working environment is a matter of choice, not chance

Statkraft manages critical infrastructure and services in several countries. The applicant must be eligible for security clearance and authorization.

Statkraft's vision is to renew the way the world is powered. To navigate the complex journey ahead, we need every voice at the table. We therefore work actively to be a diverse and inclusive workplace and welcome all applicants regardless of background, gender, age, sexual orientation, religious belief, ethnicity,nationalityor disability.

Location: Oslo

For further information please contact Øystein Dalheim, email: [emailprotected] .

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

We are looking for a Senior Information Security Risk Manager to strengthen our Information Security Management team ...
We are looking for a Senior Information Security Risk Manager to strengthen our Information Security Management team ...

Statkraft • Oslo

On-site
NOK 900,000 - 1,200,000
Unlimited learning opportunities
Global network of experts
Global Information Security Risk Leader
Global Information Security Risk Leader

Statkraft • Oslo

On-site
NOK 900,000 - 1,300,000
Unlimited learning opportunities
Global network of experts
Flexible working solutions
+1
Senior Manager, Corporate Strategy
Senior Manager, Corporate Strategy

Statkraft • Oslo

On-site
NOK 1,500,000 - 2,100,000
International environment
Professional development
Flexible working arrangements
+2
Global Information Security Risk Leader - Flexible & Growth
Global Information Security Risk Leader - Flexible & Growth

Statkraft • Oslo

On-site
NOK 900,000 - 1,200,000
Unlimited learning opportunities
Global network of experts
Analyst/Senior Analyst - Clean Energy Technologies
Analyst/Senior Analyst - Clean Energy Technologies

Statkraft • Oslo

Hybrid
NOK 900,000 - 1,300,000
Great Place to Work
Global network of experts
Flexible working
Senior Software Developer
Senior Software Developer

Statkraft • Oslo

On-site
NOK 700,000 - 900,000
Power Platform Manager
Power Platform Manager

Statkraft • Oslo

On-site
NOK 900,000 - 1,200,000
Senior Advisor - Market Regulatory Affairs
Senior Advisor - Market Regulatory Affairs

Statkraft group. • Oslo

On-site
NOK 900,000 - 1,200,000
Professional development
International environment
Competitive compensation
+2
Cyber Security & Governance Manager
Cyber Security & Governance Manager

Var energi • Stavanger

Hybrid
NOK 900,000 - 1,200,000
Pension
Insurance schemes
Loan arrangements
+3
Cyber Security & Governance Manager
Cyber Security & Governance Manager

Vår Energi AS • Stavanger

On-site
NOK 1,000,000 - 1,400,000
Pension
Insurance schemes
Loan arrangements
+3