CyberSecurity Analyst/GRC Consultant
Candidates without valid work permit in Norway and NORSOK experience from Operator will not be evaluated
Location: Oslo / Stavanger (flexible)
Start date: 9 February 2026
End date: 29 January 2027
Job Description
We are seeking a skilled and motivated Cybersecurity GRC (Governance, Risk & Compliance) Consultant to strengthen and operate cybersecurity capabilities across IT, OT, and digital initiatives.
In this role, you will help ensure that cyber risks are understood, managed, and communicated in a structured and actionable way. You will bridge strategy and execution, influence decision-making, and embed cybersecurity into everyday processes across the organization.
Key Responsibilities
Cybersecurity Governance
Maintain and develop cybersecurity governance frameworks, policies, and standards
Align cybersecurity practices with internal risk frameworks and enterprise governance models
Translate strategy and regulatory requirements into actionable, implementable controls
Risk Management
Facilitate and perform cybersecurity risk assessments across IT, OT, and digital initiatives
Support risk-based decision-making for projects, suppliers, and operations
Track risk treatment plans, risk acceptance, and management actions
Compliance & Assurance
Support compliance with relevant laws, regulations, and industry standards (e.g., NIS2, ISO/IEC 27001, IEC 62443)
Plan and execute internal cybersecurity assessments
Contribute to management reporting and leadership decision support
Advisory & Collaboration
Act as a trusted cybersecurity advisor for projects, product teams, and business units
Collaborate with IT, OT, architecture, procurement, and vendors
Support secure-by-design and risk-based ways of working
Awareness & Capability Building
Develop cybersecurity guidance, training, and awareness initiatives
Help build a strong risk culture across the organization
Qualifications & Experience
Required
Relevant education in cybersecurity, IT, engineering, or related field
Practical experience in cybersecurity governance, risk management, and compliance
Solid understanding of cybersecurity principles across IT, and preferably OT
Experience with standards such as ISO 27001, NIST, CIS, or IEC 62443
Knowledge of AI, automation, and emerging technologies’ effect on cybersecurity risk
Preferred
Experience in energy, industrial, or other complex operational environments
Familiarity with regulatory requirements such as NIS2 or critical infrastructure legislation
Experience with third-party risk management or supplier assurance
Cybersecurity certifications such as CISM, CISSP, CRISC, ISO 27001 LA/LI
Personal Qualities
Structured, pragmatic, and risk-based in approach
Comfortable working independently while collaborating across disciplines
Able to challenge constructively and influence without formal authority
Motivated by improving real-world security, not just documentation
Why Join
- Department
- IT
- Role
- Cyber Security Engineer
- Locations
- Forus, Stavanger, Oslo
- Work schedule
- Normal week 5/2
About Energy
Energy specializes in providing consultants to the Land based Industry, Oil & Gas, Renewable Energy and Marine sector, primarily operating in the the Scandinavian Market.
We collaborate closely with our clients to identify individuals who can drive meaningful growth and prosperity for their business and the region as a whole. Our approach is rooted in partnership, where we tailor our services to meet each client’s unique needs.