Talent.com
This job offer is not available in your country.
Senior Cyber Analyst (IT & OT)

Senior Cyber Analyst (IT & OT)

Omega ASStavanger, Rogaland, Norge
23 days ago
Job description

Overview

Omega 365 Consulting is a leading supplier of highly skilled project personnel in the oil and gas, renewable energy, and infrastructure sectors. We offer a wide range of consultant assignments, featuring many of the most exciting projects in Norway and internationally.

Assignment Description

  • To enhance the cyber team in the Clients project, we are seeking a highly skilled and motivated Senior Cyber Risk & GRC Analyst to join our IT project team. This hybrid role is pivotal in strengthening our organization's cyber resilience by assessing and mitigating risks, ensuring compliance with regulatory requirements, and supporting our overall cybersecurity strategy.
  • The Project will be receiving a large quantity of package deliveries with high degree of dependency on digital components, and potential cyber threats must be eliminated as part of our commissioning and handover to support processes.
  • The successful candidate will play a key leadership role in the implementation and continuous improvement of our risk and compliance frameworks, policies, and processes. The position will be part of a major project where digital deliveries covering the field of IT is a key part of the delivery. (Position details)
  • Full time position as consultant in a project organization
  • Requesting startup September 2025, or when the right candidate is available. Phased startup with less than full time as a part of engagement is acceptable.
  • Estimated end date H2-2027
  • Primary work location Stavanger or Oslo / Fornebu with rotation to Stavanger on scheduled basis.
  • Be part of the Project team and assist in testing and validating technical solutions that could potentially be a cyber threat.
  • Identify and work with the project teams to assess risks and guide teams and suppliers to implement more robust solutions if necessary.
  • Work with project and operations teams providing identification, assessment, and management of cybersecurity risks across systems, applications, and business processes.
  • Perform needed threat modeling and vulnerability risk assessments to support secure system design and implementation.
  • Through the established base and project organization, be part of monitoring work force working to identify internal and external threat landscapes and provide actionable intelligence to stakeholders.
  • In the context of cyber develop and maintain risk registers and present findings to senior leadership and other relevant stakeholders.
  • Collaborate with IT and business units to define risk treatment plans and track mitigation efforts.
  • Governance, Risk & Compliance (GRC)
  • Maintain and enhance the Information Security Management System (ISMS) and ensure alignment with ISO 27001, NIST CSF, and other relevant frameworks.
  • Conduct regular compliance reviews, gap analyses, and audits to ensure adherence to internal policies and external regulations (e.g., GDPR, PCI DSS, HIPAA).
  • Support the development and maintenance of security policies, standards, procedures, and guidelines.
  • Prepare and present reports for internal and external audits, certifications, and regulatory reviews.
  • Lead risk and control assessments, including third-party risk reviews and vendor due diligence.
  • Act as a subject matter expert on cyber risk and GRC best practices.
  • Work alongside project, operations and supplier teams with the “one team” mindset, enabling collaboration and positive progress to ensure we reach the common goal of an infrastructure and systems portfolio with the least number of cyber threats.
  • Work cross-functionally with OT, IT, audit, suppliers, system vendors, hardware vendors and business units to embed security into organizational culture and processes.
  • Being a team player is key for our progress, but if you discover cyber threats in a design you must have the guts to stand up for your findings and opinions and be resolute speaking up in a crowd
  • Primary tasks
  • Risk Assessments :
  • Conduct risk assessments to identify vulnerabilities and threats to the organization's information systems, temporary project offices, data transport methods, and more
  • This work will be performed primarily during commissioning and handover to operations phase of the project. This means there will be a steady stream of systems evaluations and follow-ups with project teams and vendors on technical details.
  • Hands-on penetration testing where needed. This will be determined based on risk processes and project priorities
  • Develop and implement strategies to mitigate identified risks and reduce the organization's exposure to cyber threats.
  • Follow up on specific implementations of improvements to systems design and configurations.
  • Compliance Management :
  • Ensure compliance with relevant regulations, standards, and best practices (e.g., GDPR, ISO 27001, NIST).
  • On a detailed level this also dictates that the project specific requirements might require work arounds that trigger related systems to adjust to comply with cyber requirements, leading to the fact that completed analysis of systems might have to be reevaluated.
  • Policy Development :
  • Implement and maintain cybersecurity and GRC policies, procedures, and frameworks.
  • Incident Response :
  • Coordinate incident response efforts, including investigation, containment, eradication, and recovery.
  • Threat Monitoring :
  • Work with operational teams in IT and OT to ensure we monitor and analyze emerging cyber threats and vulnerabilities, providing timely updates and recommendations.
  • Physical site inspection :
  • When required travel to project site to do physical inspection with relevant teams like IT, OT and Security. Follow up on any previous findings, and evaluate if new threats needs to be raised as risks and mitigated.
  • Documentation Management :
  • Maintain accurate and up-to-date documentation of project related GRC processes, procedures, and incident response plans.
  • Stakeholder Communication :
  • Communicate effectively with stakeholders at all levels, providing clear and actionable insights on cybersecurity and compliance matters.
  • Vulnerability Management :
  • Conduct regular vulnerability assessments and penetration testing to identify and address security weaknesses.
  • Continuous Improvement :
  • Continuously evaluate and improve the organization's cybersecurity and GRC practices to enhance overall security posture.

Qualifications

  • Bachelor’s degree in information technology, Cybersecurity, or a related field is requested but not necessary if relevant experience and / or certification is in place.
  • Minimum of 10+ years of combined experience in cyber risk management, IT & OT security, or GRC roles.
  • In-depth knowledge of cybersecurity frameworks (NIST, ISO 27001, CIS, etc.).
  • Strong understanding of regulatory compliance requirements and risk assessment methodologies.
  • Professional certifications such as CISSP, CISM, CRISC, CISA, or similar strongly preferred.
  • Excellent analytical, problem-solving, and communication skills.
  • Ability to manage multiple priorities in a fast-paced environment with minimal supervision.
  • The candidate must be able to demonstrate genuine interest in the field of cyber security, and show evidence of being a true “hands on white hacker” type of person.
  • Desirable Attributes
  • Many years with hands-on experience finding vulnerabilities in digital systems.
  • Deeper understanding of how hardware and software actually works
  • Experience with both IT and OT systems, and what typically separates these environments and also how systems and suppliers work within these environments.
  • Experience with GRC tools (e.g., Archer, ServiceNow GRC, RiskLens).
  • Familiarity with cloud environments (AWS, Azure, GCP) and related security challenges.
  • Passion for continuous improvement and proactive risk management.
  • Be self-motivated with a willingness to learn from others and work with minimum direction.
  • Actively seeks out know-how and best practice, related to own area of contribution.
  • Anticipate future situations and plans to meet them.
  • Bias for action - do things before being asked to or forced to by events.
  • Willingly takes the lead when challenges occur.
  • Actively promotes open and effective communication.
  • Strong planning and organizing ability.
  • Actively promotes a positive team environment, demonstrating shared commitment to the success of the team and the wider project organization.
  • Actively engages and respects contributions of others, in face to face or virtual meetings.
  • Seeks to develop self and coach others to help their development.
  • Build networks to enhance effectiveness and share knowledge.
  • Focuses effort and prioritizes work to deliver business value.
  • Good knowledge of the English and Norwegian languages (both written and verbal).
  • Personalized, hands-on support from our dedicated Omega 365 team members
  • Collaboration with one of Norway's most prestigious consultant firms
  • Guidance from experienced department managers, facilitating the development of your project expertise
  • Internal visa assistance and expert advice for EEA / expat consultants
  • Excellent opportunities to expand your professional network through project involvement and social gatherings
  • Exclusive benefits including access to holiday houses and cabins in locations such as Hovden, Hemsedal, Geilo, Hafjell, Oppdal, Voss, Vågsli, Sirdal, Gran Canaria, and Thailand
  • Diverse offerings of events including concerts and exciting excursions, both in Norway and abroad. We unveil attractive new trips exclusively for our employees every year.
  • #J-18808-Ljbffr

    Create a job alert for this search

    Senior Cyber Analyst • Stavanger, Rogaland, Norge

    Related jobs
    • Promoted
    IT Business Analyst / Team Lead

    IT Business Analyst / Team Lead

    Omega ASStavanger, Rogaland, Norge
    Omega 365 Consulting is a leading supplier of highly skilled project personnel in the oil and gas, renewable energy, and infrastructure sectors. We offer a wide range of consultant assignments, feat...Show moreLast updated: 3 days ago
    • Promoted
    IT Business Analyst

    IT Business Analyst

    Head Energy SolveStavanger, Rogaland, Norge
    The candidate in question will assume a pivotal position as Technical Team Lead, orchestrating technical workstreams that span multiple projects, teams, and external vendors.This cross-functional c...Show moreLast updated: 3 days ago
    • Promoted
    IT Business Analyst

    IT Business Analyst

    Sopra SteriaØrpetveit, Rogaland, Norge
    Vil du være IT Business Analyst i prosjekter som former fremtidens energibransje? Vi ser etter erfarne IT Business Analysts som ønsker å bidra til utvikling av teknologiske løsninger for en mer eff...Show moreLast updated: 16 days ago
    • Promoted
    Summer 2026 Norway - IT & Cybernetics

    Summer 2026 Norway - IT & Cybernetics

    EquinorStavanger, Rogaland, Norge
    What does the involve? If you’re a student interested in a career in Equinor, our summer programme enables you to gain highly relevant hands-on experience in your chosen discipline.Our goal is to i...Show moreLast updated: 10 days ago
    • Promoted
    NIFC Intel Military Analyst - SOF / Non-Linear

    NIFC Intel Military Analyst - SOF / Non-Linear

    SpektrumWorkFromHome, Rogaland, Norge
    The NATO Joint Warfare Centre (JWC) is a NATO establishment focused on improving the Alliance's operational capabilities through training and exercises. The JWC is located in Stavanger, Norway, and ...Show moreLast updated: 26 days ago
    • Promoted
    Digital Project Manager / Business Analyst

    Digital Project Manager / Business Analyst

    Omega ASStavanger, Rogaland, Norge
    Digital Project Manager / Business Analyst.Omega 365 Consulting is a leading supplier of highly skilled project personnel in the oil and gas, renewable energy, and infrastructure sectors.We offer a w...Show moreLast updated: 15 days ago
    • Promoted
    IT Business Analyst

    IT Business Analyst

    EquinorStavanger, Rogaland, Norge
    Location(s) : Stavanger, Bergen.Discipline : Information Technology.Education Preferred : Master's Degree or PhD.Experience Preferred : Not Indicated. We're 23,000 colleagues in more than 30 countries d...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Information Mgmt. Specialist

    Senior Information Mgmt. Specialist

    Head Energy SolveStavanger, Rogaland, Norge
    Define and perform activities to efficiently and systematically manage information from capture to disposal.This includes revision control, retention requirements and review / approval workflows whe...Show moreLast updated: 16 days ago
    • Promoted
    Senior Nettverksingeniør IT / OT

    Senior Nettverksingeniør IT / OT

    Sopra Steria USAStavanger, Rogaland, Norge
    Vil du bli en del av vårt nettverksteam som bygger fremtidens infrastruktur?.Vil du bli en del av Sopra Steria som er et av Nordens største produkt- og leverandøruavhengige kompetansemiljø innen ne...Show moreLast updated: 30+ days ago
    • Promoted
    Cyber Subject Matter Expert (SME)

    Cyber Subject Matter Expert (SME)

    SpektrumStavanger, Rogaland, Norge
    Spektrum have a wide range of exciting opportunities in several global locations.We are always looking to add great new talent to our team and look forward to hearing from you.Spektrum supports ape...Show moreLast updated: 25 days ago
    • Promoted
    Cyber Security Analyst

    Cyber Security Analyst

    NES FircroftWorkFromHome, Rogaland, Norge
    Contract period : 29 / 09 / 2025 - 31 / 12 / 2027.Location : Primary location is Stavanger, or Oslo / Fornebu with rotation to Stavanger on scheduled basis. Key responsibilities and tasks.Be part of the project...Show moreLast updated: 23 days ago
    • Promoted
    IT Support Specialist

    IT Support Specialist

    BCIC SwissStavanger, Rogaland, Norge
    BCIC Swiss GmBH | Best Connect International Company is looking for a full time on-site IT Support Specialist in Norway.Hardware and Software Knowledge, Troubleshooting. Provide first- or second-lev...Show moreLast updated: 23 days ago
    • Promoted
    Senior Information Mgmt. Specialist

    Senior Information Mgmt. Specialist

    Head EnergyStavanger, Rogaland, Norge
    Head Energy is an independent Scandinavian engineering & consulting house providing a wide range of products to onshore and offshore industries. We work with reputed clients in Energy, Civil Constru...Show moreLast updated: 17 days ago
    • Promoted
    Senior Cyber Analyst

    Senior Cyber Analyst

    Head Energy SolveStavanger, Rogaland, Norge
    Senior Cyber Analyst (Pnr : 22261).Test and validate technical solutions for potential cyber threats.Perform threat modeling, vulnerability assessments, and penetration testing.Maintain risk register...Show moreLast updated: 23 days ago
    • Promoted
    Senior Cyber Analyst

    Senior Cyber Analyst

    Head EnergyStavanger, Rogaland, Norge
    Head Energy is an independent Scandinavian engineering & consulting house providing a wide range of products to onshore and offshore industries. We work with reputed clients in Energy, Civil Constru...Show moreLast updated: 23 days ago
    Chief Operating Officer

    Chief Operating Officer

    RM Staffing B.V.Stavanger, 11, NO
    This role requires strong expertise across both.The ideal candidate combines solid coding skills with an eye for clean UI / UX, strong problem-solving ability, and a collaborative mindset.Build respo...Show moreLast updated: 3 days ago
    • Promoted
    Senior Information Mgmt. Specialist

    Senior Information Mgmt. Specialist

    IKM Consultants ASStavanger, Rogaland, Norge
    Develop and implement comprehensive information management strategies and policies.Oversee the entire lifecycle of corporate information, from creation and classification to archival and disposal.E...Show moreLast updated: 30+ days ago
    • Promoted
    Bli vår neste Cyber Security Spesialist (ICSE)... Akkodis IT • Stavanger

    Bli vår neste Cyber Security Spesialist (ICSE)... Akkodis IT • Stavanger

    Akkodis groupStavanger, Rogaland, Norge
    Har du lidenskap for cybersikkerhet og lyst til å jobbe i grensesnittet mellom IT og OT? Ønsker du å bidra til sikre og pålitelige industrielle systemer i noen av Norges mest komplekse og spennende...Show moreLast updated: 30+ days ago