- 1A INTERNATIONAL BUSINESS PARK West Region (Singapore) Singapore

Working Location
Job Description
Responsibilities
The Principal Engineer, OT Cybersecurity, will provide senior technical leadership for the design, integration, assurance, and delivery of OT cybersecurity solutions for major offshore oil and gas projects, with a primary focus on topside facilities for FPSO, FLNG, floating production units, and offshore assets.
The role will lead cybersecurity scope and strategy definition, system architecture, design-basis preparation, functional specifications, technical studies, cybersecurity risk assessments, HAZOP and CHAZOP participation, vendor engineering coordination, system integration, and project cybersecurity deliverables across feasibility, concept, pre-FEED, FEED, detailed engineering, EPCI, commissioning, and operations support phases.
The successful candidate will embed Secure by Design principles across Industrial Automation and Control Systems, process control environments, marine networks, telecom interfaces, subsea control systems, and IT/OT integration with offshore and onshore corporate networks.
As the subject matter expert for OT cybersecurity, the Principal Engineer will ensure solutions are safe, reliable, maintainable, compliant, and aligned with client, classification society, regulatory, company, and project requirements.
This role requires the ability to identify optimal technical solutions, resolve complex cybersecurity design and integration issues, and communicate recommendations clearly through technical reports, design reviews, client meetings, vendor discussions, and project decision-making forums. Frequent travel may be required to project offices, fabrication yards, vendor facilities, and offshore or commissioning locations in the United States, Europe, and Asia.
The ideal candidate will bring extensive offshore oil and gas experience, deep expertise in OT cybersecurity solutions, and a proven record of leading cybersecurity design, integration, testing, FAT, SAT, commissioning and operations support, and technical assurance for complex offshore production facilities.
· Cybersecurity engineering leadership: Lead OT cybersecurity scope definition, system architecture, design basis, technical studies, risk assessments, and cybersecurity deliverables across feasibility, concept, pre-FEED, FEED, detailed engineering, EPCI, commissioning, and operations support phases.
· Secure architecture and design: Design and implement secure OT network architectures for topsides ICSS, process control, marine systems, and critical infrastructure environments, including segmentation, Purdue Model alignment, secure remote access, firewalls, data diodes, and secure communication protocols.
· Risk, compliance, and assurance: Lead cyber-risk assessment workshops and CHAZOP sessions, and ensure alignment with ISA/IEC 62443, NIST, ISO 27001, IMO requirements, IACS UR E26/E27, and applicable client, class, and regulatory requirements and implementation of recommendations.
· Vendor and package coordination: Develop technical specifications, perform technical bid evaluations, and review automation, control system, package vendor, and OT cybersecurity solutions for compliance with project requirements.
· Testing and project delivery: Oversee OT cybersecurity FAT, SAT, system hardening verification, security control validation, remediation tracking, commissioning support, handover readiness, and operations support.
· Security operations and incident response: Oversee OT security monitoring, SIEM integration, OT threat-detection platforms, endpoint protection, vulnerability management, incident investigation, containment, remediation, reporting, and continuous resilience improvement.
· Stakeholder engagement: Present technical design justifications, defend risk-mitigation strategies, and communicate recommendations clearly with clients, vendors, classification societies, regulatory bodies, project teams, and senior leadership.
· Team leadership and capability building: Build, mentor, and develop OT cybersecurity capability within the team while driving awareness, training, technical excellence, accountability, and continuous improvement.
· Bachelor’s or master’s degree in Cybersecurity, Instrumentation, Control Systems, Automation, Electrical and Electronics, Computer Science, or a related engineering discipline.
· Minimum20 years of oil and gas engineering experience, with substantial exposure to offshore production facilities, FPSO, FLNG, floating production units, fixed platforms, topsides, or offshore processing facilities.
· Minimum12 years of hands-on OT cybersecurity, ICSS, PLC, SCADA, DCS, SIS, F&G, ESD, or industrial control systems engineering experience.
· Proven experience as a Principal Engineer, Lead Engineer, Technical Authority, or cybersecurity subject matter expert for OT cybersecurity on major FEED, detailed engineering, EPC, EPCI, or EPCIC projects.
· Preferred certifications including Global Industrial Cyber Security Professional (GICSP), Certified Information Systems Security Professional (CISSP), IEC 62443specialist credentials, or equivalent OT cybersecurity certifications.
· Experience delivering cybersecurity scope on at least two FPSO, FLNG, or major offshore facility projects from engineering commencement through construction, integration, commissioning, sail-away, delivery, or start-up support is preferred.
· Strong knowledge of ISA/IEC 62443, ISO/IEC 27001, IEC 61508, IEC 61511, IMO requirements, IACS UR E26/E27, and applicable client, classification society, regulatory, and company requirements.
· Strong understanding of secure OT and ICS architecture, including Purdue Model zoning, zones and conduits, network segmentation, DMZ design, firewalls, data diodes, secure remote access, secure protocols, system hardening, patch management, vulnerability management, backup and recovery, logging, monitoring, and incident response.
· Working knowledge of major ICSS, automation, and control system vendor platforms such as Honeywell, Emerson, Yokogawa, Siemens, ABB, Schneider, Rockwell, or equivalent systems is preferred.
· Experience preparing, reviewing, and approving OT cybersecurity deliverables, including cybersecurity specifications, execution plans, risk assessment reports, asset inventories, security profiles / security level targets, architecture diagrams, network diagrams, firewall rules, hardening procedures, FAT/SAT procedures, vulnerability assessment reports, remediation registers, and vendor documentation.
· Experience leading or participating in cybersecurity risk assessments, CHAZOP, HAZOP, HAZID, design reviews, FAT, SAT, commissioning readiness, and handover activities.
· Strong leadership, mentoring, stakeholder management, decision-making, planning, technical assurance, and multidisciplinary coordination skills in multicultural global project environments.
· Strong analytical and problem-solving skills, with the ability to resolve complex technical, cybersecurity, interface, vendor, construction, commissioning, and site execution issues.
· Ability to communicate effectively with clients, vendors, subcontractors, classification societies, regulatory bodies, project management, engineering teams, operations teams, and senior leadership.
· Abilityto work independently and within multicultural, multidisciplinary global project teams while maintaining accuracy, quality, accountability, and attention to detail. Fluency in English, with strong written, verbal, presentation, client-facing, and technical reporting skills.
Important Information
Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.