Senior Information Security Risk Manager

  • Full-time
  • Business Units: TC - Digital Resilience

Company Description

At Statkraft, we are committed to securing the systems, information, and digital capabilities that enable the transition to a renewable future. As Europe's largest generator of renewable energy, we operate in more than 20 countries and depend on secure, resilient, and well-governed information and technology services.

Job Description

We are looking for a Senior Information Security Risk Manager to strengthen our Information Security Management team and help drive security risk management, governance, and continuous improvement across Statkraft's global operations. 

As Senior Information Security Risk Manager, you will assist in identifying, analysing, treating and monitoring information security risks in Statkraft. You will act as a trusted advisor to business and technology stakeholders, helping them understand and manage information security and technology risks.  

You will support the development and implementation of security governance practices, conduct risk assessments, facilitate risk treatment activities, and contribute to a strong security culture throughout the company. 

The role combines strategic advisory work, stakeholder management, and hands-on risk management activities. You will work closely with business units, digital teams, cyber security specialists, risk owners, and different levels of management. 

The position reports to “Head of Risk Management” within the Information Security Management department. 

Areas of responsibilities and accountabilities: 

Information Security Risk Management 

  • Lead and facilitate information security risk assessments across business processes, systems, and services in Statkraft globally. 
  • Advise business leaders, product owners, and process owners on information security risks and mitigation strategies, and support management in making informed risk-based decisions. 
  • Maintain risk registers and monitor risk treatment progress and effectiveness of implemented security measures. 
  • Report on the continuously changing and evolving risk landscape to key stakeholders. 
  • Contribute to continuous improvement of information security methodologies, tools, and processes. 

Security Culture and Awareness 

  • Develop and deliver security awareness and training initiatives. 
  • Promote risk ownership throughout the organisation. 
  • Support the continued development of Statkraft's information security culture. 

Stakeholder Management 

  • Build strong relationships with business stakeholders across multiple countries and functions. 
  • Translate technical and security-related topics into business-relevant language. 
  • Facilitate discussions between business, technology, and security teams to achieve practical risk-based outcomes. 

Qualifications

Required 

  • Master's degree or equivalent experience in Information Security, Cyber Security, Risk Management, Information Systems, or a related discipline. 
  • Minimum 5-8 years of experience within information security, cyber security, IT risk management, governance, or compliance. 
  • Strong experience conducting security risk assessments and facilitating risk treatment. 
  • Excellent understanding of security governance frameworks and standards such as: ISO/IEC 27001, ISO/IEC 27005, NIST Cybersecurity Framework, Risk management methodologies and control frameworks. 
  • Experience working with senior business stakeholders and management teams. 
  • Strong communication and presentation skills in English. 

Preferred 

  • Experience from critical infrastructure, energy, utilities, or industrial environments. 
  • Professional certifications such as: CISSP, CISM, CRISC, ISO 27001 Lead Implementer or Lead Auditor.
  • Experience supporting audits, regulatory compliance, and internal control frameworks. 

Personal Qualities 

We are looking for someone who: 

  • Thinks strategically while remaining pragmatic. 
  • Builds trust and influences without formal authority. 
  • Is comfortable challenging assumptions and driving improvement. 
  • Has strong analytical and problem-solving skills. 
  • Communicates effectively with both technical and non-technical audiences. 
  • Thrives in a collaborative and international environment. 

Additional Information

What we offer 

  • Unlimited learning opportunities at various levels of the organization 
  • The chance to grow your career alongside a truly global network of experts, leaders, specialists, and graduates from different countries and backgrounds 
  • The opportunity to work somewhere with pride, and be able to honestly say “My work is contributing to saving the planet” 
  • A work culture that puts emphasis on the individual, offering flexible working solutions, and work-life balance principles 
  • Statkraft offers competitive terms of employment and benefit schemes, and we’re a trusted employer that puts the safety of our people first. We believe that a safe and healthy working environment is a matter of choice, not chance 

Statkraft manages critical infrastructure and services in several countries. The applicant must be eligible for security clearance and authorization. 

Statkraft's vision is to renew the way the world is powered. To navigate the complex journey ahead, we need every voice at the table. We therefore work actively to be a diverse and inclusive workplace and welcome all applicants regardless of background, gender, age, sexual orientation, religious belief, ethnicity, nationality or disability. 

Application deadline: 16.09.26

Location: Oslo

For further information please contact Øystein Dalheim, email: [email protected].

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Privacy Notice