Security Governance and Risk Manager

Kuwait Petroleum

Completely RemoteFull TimeInformation Technology
Posted Today

Job description

Responsibilities

  • Translate group security frameworks into practical policies, controls, and procedures
  • Build and strengthen a Security-by-Design culture across projects, platforms, and teams
  • Guide affiliates with clear tools, training, and hands-on support
  • Set up and drive a structured risk management cycle across the group
  • Support teams in identifying risks, defining actions, and tracking progress
  • Monitor execution, detect gaps, and report insights to senior leadership
  • Drive corrective actions and continuous improvement across affiliates
  • Support audit readiness and ensure documentation remains complete and accurate
  • Align with IT, PMO, and business teams to ensure governance supports business needs
  • Act as a trusted advisor for leadership on risk, compliance, and security priorities

Requirements

  • Master’s degree in Information Security, IT, or a related field
  • 8–12 years of experience in information security with a focus on GRC
  • Expertise in frameworks such as ISO 27001, NIST, NIS2, CIS, SOC 2, or IEC 62443
  • Experience with cloud security (Azure) and modern security ecosystems (SIEM, SOC, CIAM, PAM, or ServiceNow)
  • Hands-on experience implementing Security-by-Design in projects and procurement
  • Strong ability to communicate, influence stakeholders, and build trust

Preferred Qualifications

  • CISSP certification
  • CISM certification
  • ISO 27001 Lead Implementer or Auditor certification

Benefits

  • Key role with high visibility across an international organization
  • Opportunity to shape group-wide security standards and strategy
  • Access to a network of experts for continuous learning and growth
  • Flexible working arrangements and respect for work-life balance
  • Competitive salary package with extra-legal benefits

About the Company

Kuwait Petroleum continues to expand its business based on the qualities and commitment of extraordinary people. We look for talented individuals who deliver impact and help us excel through innovative solutions. We offer a creative atmosphere and a stimulating environment with significant opportunities for professional and personal growth.

Skills & tools

ISONISTAzureCISSPCISMCompliance

What the team is looking for

Use this list as a quick fit check before you apply.

  1. 01Master’s degree in Information Security, IT, or related field
  2. 028–12 years experience in information security
  3. 03Expertise in GRC (ISO 27001, NIST, NIS2, CIS, SOC 2, IEC 62443)
  4. 04Experience with cloud security (Azure)
  5. 05Knowledge of SIEM, SOC, CIAM, PAM, or ServiceNow
  6. 06Security-by-Design experience
  7. 07CISSP, CISM, or ISO 27001 certifications preferred