Director, Information Security
About the role
The Director of Information Security is responsible for leading Weatherford's global cybersecurity strategy, governance, operations, identity management, and risk management program across Network, IT, OT/Digital, AI, and Data environments. This leader will establish and execute a modern security program that protects Weatherford's people, identities, privileged access, systems, operational technology, digital platforms, AI capabilities, and enterprise data while enabling business growth and digital transformation. The role partners closely with Infrastructure, Network Operations, Cloud, Enterprise Applications, Digital/OT, Data & AI, Legal, Compliance, Internal Audit, HR, and business leadership to ensure cybersecurity and identity controls are embedded across all technology and business initiatives.
Responsibilities
- Define and execute the enterprise cybersecurity strategy and roadmap.
- Establish security governance, policies, standards, and control frameworks.
- Lead cybersecurity risk assessments and prioritize mitigation activities.
- Drive Zero Trust security principles across the enterprise.
- Own the enterprise Identity and Access Management (IAM) strategy, including identity lifecycle, authentication, authorization, least privilege, and access governance.
- Provide oversight for privileged access management, role-based access, access reviews, segregation of duties, and joiner-mover-leaver controls.
- Establish cybersecurity standards for operational technology, field operations, industrial connectivity, digital platforms, and remote operations.
- Develop security standards and governance for AI and GenAI technologies.
- Evaluate AI-related risks, data exposure concerns, and third-party AI services.
- Own enterprise data protection strategy.
- Implement data classification, encryption, identity-based access governance, and Data Loss Prevention (DLP) programs.
- Protect sensitive customer, employee, operational, and financial information.
- Ensure security controls are embedded across servers, endpoints, cloud platforms, and enterprise infrastructure.
- Ensure continuous monitoring and proactive threat mitigation.
- Ensure secure integration between IT and OT environments.
- Provide executive reporting on cyber risk, security posture, compliance, identity risk, and remediation progress.
- Protect sensitive customer, employee, operational, and financial information.
- Partner with HR, IT, application owners, and business leaders to strengthen identity controls across employees, contractors, vendors, service accounts, and machine identities.
- Partner with business and operational leaders to protect critical operational environments.
- Partner with business and technology leaders to enable secure AI adoption and innovation.
- Partner with Data & Analytics teams to secure enterprise data platforms.
- Build and lead a high-performing cybersecurity organization.
- Develop succession plans and technical capability across security disciplines.
- Foster a culture of accountability, collaboration, and continuous improvement.
- Manage strategic vendors, service providers, budgets, and security investments.
Qualifications
- 12+ years of progressive cybersecurity and technology leadership experience.
- Proven experience leading enterprise cybersecurity programs in large global organizations.
- Experience across Network Security, Infrastructure Security, Cloud Security, Identity & Access Management, Data Security, Security Operations, and Risk Management.
- Experience implementing or overseeing IAM capabilities such as SSO/MFA, privileged access management, identity lifecycle, access reviews, and least privilege controls.
- Experience securing OT/Digital environments and industrial systems preferred.
- Experience implementing Data Protection and DLP programs.
- Familiarity with AI/GenAI security and governance principles.
- Strong experience presenting cyber risks and security strategies to executive leadership.
- Preferred Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related discipline. Master's degree preferred.
- CISSP, CISM, CRISC, CISA, GIAC, CCSP, or equivalent certifications.
- Experience in energy, oilfield services, manufacturing, or industrial environments.
Skills
- Reduction in enterprise cyber risk exposure.
- Improved security maturity across Network, IT, Identity, OT/Digital, AI, and Data domains.
- Timely remediation of vulnerabilities and security findings.
- Reduced security incidents and business impact.
- Regulatory, audit, and compliance readiness.
- Effective DLP and data protection outcomes.
- Improved identity governance outcomes, including timely access reviews, reduced excessive privileges, strong MFA adoption, and effective privileged access controls.
- Secure adoption of cloud, digital, and AI technologies.
- High-performing and engaged cybersecurity team.
Benefits
Weatherford is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law.