Director, Information Security
Company
Weatherford
Location
Houston, United States
Employment type
Full-time
Posted
2 hours ago
Listed via
Weatherford
Position Summary
The Director of Information Security is responsible for leading Weatherford's global cybersecurity strategy, governance, operations, identity management, and risk management program across Network, IT, OT/Digital, AI, and Data environments.
This leader will establish and execute a modern security program that protects Weatherford's people, identities, privileged access, systems, operational technology, digital platforms, AI capabilities, and enterprise data while enabling business growth and digital transformation.
The role partners closely with Infrastructure, Network Operations, Cloud, Enterprise Applications, Digital/OT, Data & AI, Legal, Compliance, Internal Audit, HR, and business leadership to ensure cybersecurity and identity controls are embedded across all technology and business initiatives.
Key Responsibilities
Safety, Security & Compliance
Define and execute the enterprise cybersecurity strategy and roadmap.
Establish security governance, policies, standards, and control frameworks.
Lead cybersecurity risk assessments and prioritize mitigation activities.
Drive Zero Trust security principles across the enterprise.
Own the enterprise Identity and Access Management (IAM) strategy, including identity lifecycle, authentication, authorization, least privilege, and access governance.
Provide oversight for privileged access management, role-based access, access reviews, segregation of duties, and joiner-mover-leaver controls.
Establish cybersecurity standards for operational technology, field operations, industrial connectivity, digital platforms, and remote operations.
Develop security standards and governance for AI and GenAI technologies.
Evaluate AI-related risks, data exposure concerns, and third-party AI services.
Own enterprise data protection strategy.
Implement data classification, encryption, identity-based access governance, and Data Loss Prevention (DLP) programs.
Protect sensitive customer, employee, operational, and financial information.
Quality
Ensure security controls are embedded across servers, endpoints, cloud platforms, and enterprise infrastructure.
Ensure continuous monitoring and proactive threat mitigation.
Ensure secure integration between IT and OT environments.
Operations
Lead the security strategy for enterprise networks, cloud connectivity, remote access, firewalls, segmentation, and secure communications.
Oversee Security Operations, Threat Detection, Vulnerability Management, and Incident Response capabilities.
Lead cyber incident preparation, response, recovery, and executive communications.
Communication
Provide executive reporting on cyber risk, security posture, compliance, identity risk, and remediation progress.
Financial
Protect sensitive customer, employee, operational, and financial information.
People & Development
Partner with HR, IT, application owners, and business leaders to strengthen identity controls across employees, contractors, vendors, service accounts, and machine identities.
Partner with business and operational leaders to protect critical operational environments.
Partner with business and technology leaders to enable secure AI adoption and innovation.
Partner with Data & Analytics teams to secure enterprise data platforms.
Vision & Leadership
Build and lead a high-performing cybersecurity organization.
Develop succession plans and technical capability across security disciplines.
Foster a culture of accountability, collaboration, and continuous improvement.
Manage strategic vendors, service providers, budgets, and security investments.
Experience & Education
Required
12+ years of progressive cybersecurity and technology leadership experience.
Proven experience leading enterprise cybersecurity programs in large global organizations.
Experience across Network Security, Infrastructure Security, Cloud Security, Identity & Access Management, Data Security, Security Operations, and Risk Management.
Experience implementing or overseeing IAM capabilities such as SSO/MFA, privileged access management, identity lifecycle, access reviews, and least privilege controls.
Experience securing OT/Digital environments and industrial systems preferred.
Experience implementing Data Protection and DLP programs.
Familiarity with AI/GenAI security and governance principles.
Strong experience presenting cyber risks and security strategies to executive leadership.
Preferred
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related discipline.
Master's degree preferred.
CISSP, CISM, CRISC, CISA, GIAC, CCSP, or equivalent certifications.
Experience in energy, oilfield services, manufacturing, or industrial environments.
Knowledge, Skills & Abilities
Required
Reduction in enterprise cyber risk exposure.
Improved security maturity across Network, IT, Identity, OT/Digital, AI, and Data domains.
Timely remediation of vulnerabilities and security findings.
Reduced security incidents and business impact.
Regulatory, au
Explore more
Oil & Gas Alert tracks 21+ employer career pages and delivers daily digests of
new vacancies. Set your own keywords →