Information Security Specialist
Company Description
Statkraft has been making clean energy possible for over a century. That’s what we offer. 125 years of unrivalled expertise in supplying the world with what it needs most. We envision a world that runs entirely on renewable energy. Because in the fight against climate change, we don’t see renewable energy as part of the solution – we believe it must be the solution. With us, you’ll shape a career that is truly forward-facing with many amazing opportunities and offerings to match.
Job Description
The Information Security Specialist is responsible for ensuring compliance with Cybersecurity and Information Security standards and guidelines across the company, aligned with our corporate IT operating model. This role requires maintaining a strategic view of the business and local needs to ensure the effective application of our guidelines, as well as ensuring compliance with the implemented ISMS and promoting Information Security awareness throughout the organization.
Qualifications
- Five (5) years of experience in information technology, with a strong technical foundation in infrastructure, networking and/or systems, including network and systems architecture, TCP/IP, network segmentation, access control and security architecture, preferably in complex or global organizations.
- Three (3) years of proven experience in cybersecurity and/or information security roles, preferably focused on Governance, Risk and Compliance (GRC) and/or security architecture.
- Mandatory certification in ISO/IEC 27001, ISO/IEC 27005, CISM or CISSP.
- Proven experience in ISMS implementation and maintenance, including security policies, controls, risk assessments, compliance management, internal and external audit support, corrective action tracking, and continuous improvement initiatives.
- Proven experience conducting information security and cybersecurity risk assessments, including identification of threats, vulnerabilities and impacts, definition of risk treatment measures, and recommendation of technical, organizational and administrative security controls and contractual requirements.
- Knowledge of recognized cybersecurity frameworks and standards, particularly NIST and ISA/IEC 62443. Knowledge or experience in OT/ICS (desirable but not mandatory)
- University degree in Engineering, Computer Science, Information Technology, Telecommunications or related fields.
- Fluent in Spanish and English, both written and spoken.
Additional Information
- Unlimited learning opportunities at various levels of the organisation
- The chance to grow your career alongside a truly global network of experts, leaders, specialists and graduates from different countries and backgrounds.
- The opportunity to work somewhere with pride, and to be able to honestly say “My work is contributing to saving the planet”.
- A work culture that puts emphasis on the individual, offering flexible working solutions, and work life balance principles.