Petroplan is recruiting for a Cybersecurity Engineer on behalf of a US-based LNG Operator.
The Cybersecurity Engineer is responsible for developing, implementing, and maintaining cybersecurity architecture and controls designed to protect enterprise information systems, operational technology (OT), and cloud environments. This position provides technical expertise and architectural guidance across a complex technology landscape that includes multi-cloud infrastructure, enterprise applications, and industrial control systems supporting critical operations.
The Cybersecurity Engineer will establish secure architecture patterns, conduct cybersecurity and threat assessments, and incorporate security best practices into technology platforms and initiatives. The role is instrumental in protecting corporate and operational assets while ensuring compliance with organizational security requirements, applicable regulations, and recognized cybersecurity frameworks.
This position works closely with IT, engineering, operations, application development, infrastructure teams, and external technology partners to incorporate cybersecurity throughout system design, implementation, integration, and ongoing operations.
Key Responsibilities
- Design, implement, and maintain cybersecurity architectures supporting enterprise IT and OT environments across on-premises, cloud, and hybrid infrastructure.
- Develop and maintain security reference architectures, standards, and secure design patterns that enable consistent and scalable implementation of security controls.
- Perform cybersecurity architecture and design reviews for applications, infrastructure, enterprise platforms, and technology solutions.
- Integrate cybersecurity requirements and controls throughout system architecture, development, implementation, and deployment processes.
- Contribute to the continued development and maturity of the organization's enterprise cybersecurity program.
- Lead or support threat modeling activities and work with technical teams to identify security risks and incorporate appropriate mitigation strategies.
- Conduct cybersecurity risk assessments and align security recommendations with broader enterprise risk management objectives.
- Identify vulnerabilities, security gaps, and potential areas of exposure and develop practical remediation strategies.
- Establish and maintain cybersecurity standards, policies, procedures, and technical requirements based on regulatory obligations and industry best practices.
- Ensure security assessments, architecture reviews, and control evaluations are consistently documented and executed.
- Design and implement security controls across major cloud platforms, including identity and access management, network segmentation, encryption, logging, monitoring, and compliance capabilities.
- Support secure software and infrastructure delivery practices through DevSecOps integration, automation, and continuous security testing.
- Identify opportunities to leverage security automation, infrastructure-as-code, and security-as-code practices.
- Apply recognized cybersecurity frameworks and control standards, including NIST, ISO 27000-series, FISMA, FedRAMP, and related industry standards.
- Support internal and external audits, regulatory reviews, compliance assessments, and cybersecurity control validation activities.
- Maintain comprehensive documentation related to security architecture decisions, risk assessments, security reviews, and compliance requirements.
- Collaborate with infrastructure, applications, engineering, IT, and OT teams to incorporate cybersecurity requirements into technology projects and operational environments.
- Coordinate with cloud service providers, technology vendors, and third-party partners to evaluate and maintain secure system integrations.
- Provide cybersecurity expertise and technical direction during technology implementations, system upgrades, migrations, and infrastructure changes.
Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical discipline; equivalent professional experience may be considered.
Required Experience & Technical Knowledge
- 10+ years of progressive experience in cybersecurity, information security engineering, security architecture, or a related discipline.
- Experience within energy, utilities, industrial, manufacturing, critical infrastructure, or similarly complex environments is highly desirable.
- 5+ years of experience conducting cybersecurity risk assessments and applying security frameworks such as the NIST 800 series, ISO 27000 series, or IT General Controls.
- Demonstrated experience designing and implementing cybersecurity controls within cloud environments, particularly Microsoft Azure and Amazon Web Services (AWS).
- Experience supporting multi-cloud, hybrid, and on-premises technology environments.
- Experience implementing or supporting security controls aligned with NIST 800-53, FISMA, FedRAMP Moderate/High, or comparable control frameworks.
- Strong understanding of Identity and Access Management (IAM), authentication, and authorization technologies, including SAML, OAuth, OIDC, and Multi-Factor Authentication (MFA).
- Experience with cryptographic technologies, encryption, key management, and secrets management solutions.
- Strong knowledge of network security, data protection, encryption, secure connectivity, segmentation, and access control technologies.
- Familiarity with DevSecOps methodologies, cybersecurity automation, and integrating security into CI/CD environments.
- Experience securing enterprise applications, cloud services, infrastructure platforms, and complex technology environments.
- Ability to communicate complex cybersecurity concepts and risks effectively to both technical and non-technical stakeholders.