إير برودكتس تعلن عن وظيفة مهندس أمن سيبراني ICS في ضباء
تفاصيل الوظيفة
في شركة «إير برودكتس»، نبحث عن مهندس أمن سيبراني لأنظمة التحكم الصناعية (ICS) للعمل في مشروع نيوم للهيدروجين الأخضر في دبا، المملكة العربية السعودية. سيكون المرشح جزءاً من فريق أمن سيبراني مسؤول عن التحقق الميداني من الأصول السيبرانية والامتثال للمواصفات.
نبذة عن الوظيفة
تعمل شركة إير برودكتس على تنفيذ عقد EPC مع شركة نيوم للهيدروجين الأخضر (NGHC)، وتتحمل مسؤولية تصميم وبناء وتقديم أنظمة التحكم في العمليات / الأتمتة والبنية التحتية للتقنية الرقمية. يعد الامتثال للوائح الأمن السيبراني المحلية جزءاً أساسياً من السلامة والأمن والامتثال العام للمشروع. يشغل شاغل هذه الوظيفة في موقع المشروع دور عضو رئيسي في فريق عمل الأمن السيبراني للتحقق الميداني من الأصول السيبرانية وفقاً لمواصفات المشروع ومعايير القبول في الموقع. يعمل المهندس كواجهة تقنية بين فرق تنفيذ المشروع والتشغيل والتشغيل التجريبي من جهة والموردين من جهة أخرى. الموقع في دبا، منطقة تبوك، المملكة العربية السعودية، بنظام دوام 8 أسابيع عمل / أسبوعين إجازة.
المهام والمسؤوليات
- إجراء التحقق الميداني من تصميم وتنفيذ واختبار الأصول السيبرانية للامتثال لمعايير الأمن السيبراني والمتطلبات التنظيمية والتقنيات والإجراءات والمواصفات لنقل أصول المشروع إلى مراحل التشغيل التجريبي والبدء والتسليم النهائي للعميل.
- تطوير وتوثيق وصيانة سجل الأصول السيبرانية والمخرجات الرئيسية الأخرى وفقاً لتوجيهات قائد الأمن السيبراني في الموقع أو مدير الأمن السيبراني.
- تنظيم وقيادة/تيسير حل وتنفيذ تمارين تقييم مخاطر الأمن السيبراني وتنفيذ توصيات تقييم المخاطر لتصميم إير برودكتس وأنظمة التحكم للبائعين/الحزم المرفقة.
- دعم فرق ما قبل التشغيل التجريبي والتشغيل التجريبي من خلال التحقق من قواعد جدار الحماية (firewall rules)، والوصول الآمن عن بُعد (secure remote access)، وتقوية نقاط النهاية (endpoint hardening)، والتحقق من جرد الأصول، وتنفيذ التحكم في الوصول (access control)، وتسجيل الدخول (logging) قبل تنشيط النظام.
- قيادة والإشراف على تطوير المعايير والهندسة وإجراءات FAT و SAT و CSAT وتنفيذها واختبار الأداء.
- ضمان التحقق من احتياجات الوصول للأجهزة التابعة لجهات خارجية والموافقة عليها حسب طلب المقاولين من الباطن والموردين كجزء من متطلبات التشغيل التجريبي والبدء على حزم الموردين.
- المشاركة في اجتماعات التنسيق الفني مع الفرق متعددة الوظائف وفقاً لتوجيهات قائد الأمن السيبراني في الموقع.
- التنسيق مع الموردين وفريق الهندسة في إير برودكتس لحل وإغلاق نقاط الملاحظات (punch points) التي تم تحديدها أثناء التحقق الميداني من الأصول السيبرانية.
- التنسيق ومساعدة قائد الأمن السيبراني في الموقع في أنشطة إدارة التغيير لضمان مراجعة نطاق الأمن السيبراني من التصميم والمشتريات والتركيب والتشغيل التجريبي والبدء من حيث الجدول الزمني والامتثال للميزانية.
- إعداد تحديثات أسبوعية ولوحة بيانات (dashboard) لقائد الأمن السيبراني في الموقع وقائد التعاون في الأمن السيبراني للمشروع.
- تحديد ورفع المخاطر والفرص، وجمع ورفع الدروس المستفادة أثناء زيارات الموردين للموقع وتنفيذ المشروع.
- دعم تسليم الأمن السيبراني لأنظمة التشغيل (OT) إلى العمليات، بما في ذلك الإجراءات وجرد الأصول وإدارة الوصول ومواءمة الاستجابة للحوادث.
- المساهمة في نموذج عمليات الأمن السيبراني لأنظمة التشغيل (OT)، بما في ذلك المراقبة والتصحيح (patching) والنسخ الاحتياطي (backup) والتعافي من الكوارث (disaster recovery) والدعم الآمن عن بُعد (secure remote support).
الشروط والمتطلبات
- درجة البكالوريوس في الهندسة (يفضل تخصص الإلكترونيات والاتصالات أو الأجهزة/أتمتة العمليات) أو ما يعادلها.
- خبرة لا تقل عن 10 إلى 15 سنة في مجال التقنية التشغيلية (OT) أو مجال ذي صلة، مع 3 سنوات على الأقل تركز على تصميم أو بناء أو التحقق من تصميم/تنفيذ الأمن السيبراني لأنظمة التحكم الصناعية والشبكات.
- خبرة في تنفيذ المشاريع وفقاً للمعايير السيبرانية السعودية: HCIS، NCA، CRA، ومعايير ISA 62443 الصناعية والمواصفات واللوائح وأفضل الممارسات.
- معرفة قوية وفهم لأنظمة التحكم (SCADA / DCS / PLCs وغيرها) والبروتوكولات ذات الصلة (Modbus، PROFINET، DNP3، IEC61850 وغيرها) والتقنيات الرئيسية بما في ذلك جدران الحماية (firewalls)، وأنظمة كشف التسلل (IDS)، ومكافحة الفيروسات (Anti-Virus)، وتقييم الثغرات (vulnerabilities assessments) في شبكات ICS/OT.
- يفضل الحصول على اعتمادات مهنية في أمن OT/ICS مثل ISA/IEC62443 أو SANS أو أي شهادات معترف بها دولياً أخرى.
- تعتبر شهادات أمن سيبراني إضافية مثل CISSP أو CISM أو ISO 27001 ميزة إضافية.
- مهارات متقدمة في أدوات Microsoft Office مثل Teams و SharePoint و Word و Excel و PowerPoint و Visio.
- مهارات تواصل ممتازة شفهياً وكتابياً والقدرة على التواصل بشكل مناسب مع جميع مستويات المؤسسة.
عرض النص الأصلي للإعلان
في شركة «إير برودكتس»، نعيد تصور ما هو ممكن. من خلال الاستفادة من حماس موظفينا وخبرتنا الجماعية، نبتكر الأفكار والابتكارات التي تدفعنا إلى الأمام. عندما نجتمع معًا - حيث تُسمع كل صوت ويشعر الجميع بالانتماء والأهمية - نبتكر حلولًا تنقل البشر إلى الفضاء، وتدعم الرعاية المنقذة للحياة في المستشفيات، وتتيح إنشاء منشآت إنتاج رائدة على نطاق عالمي.
إعادة تصور ما هو ممكن
NEOM Green Hydrogen Project is part of the most complex capital project and a flagship project at scale for Air Products. Air Products is executing a EPC Contract with the customer - NEOM Green Hydrogen Company (NGHC). Air Products have the responsibility to design, build and delivery Process Controls / Process Automation System and IT/Digital Technology infrastructure scope. This scope shall comply with the local laws and regulations on cybersecurity, which is a crucial part in the project’s safety, security and overall compliance.
The incumbent in this position based at project site, as ICS Cyber Security Engineer, plays a key member of a Cybersecurity task force team to undertake the field verification of the cyber assets to comply with the project specifications and the site acceptance criteria.
The Engineer is also responsible for coordinating with Engineering, Pre-Commissioning, Commissioning and Client operations team related to Cyber Security field verifications.
The Cyber Security engineer acts as the technical interface between Air Products project execution, commissioning teams and the vendors, during the field verification of cyber assets.
Experience in supporting large scale construction, pre commissioning, commissioning, startup and handover phases, ensuring cybersecurity controls are implemented without impacting schedule critical activities
The position is based out of Duba, Tabuk Region, Saudi Arabia working on rotation of 8 Weeks ON / 2 Weeks OFF.
The position will be a site-based role with the below duties:
Perform the field verification of the design, implementation and testing of the cyber assets to meet the cybersecurity standards, regulatory requirements and technologies, processes/procedures and specifications to transition the project assets to commissioning, start-up and final handover to the client.
Develop, document, and maintain cybersecurity asset register and other key deliverables as guided by the Site Cybersecurity Lead or Cybersecurity Manager.
Organize and lead/facilitate the resolution and implementation of the cybersecurity risk assessment exercises and implement risk assessment recommendations for Air Products design and also for vendor/ skid package control system
Support pre‑commissioning and commissioning teams by validating firewall rules, secure remote access, endpoint hardening, Asset inventory validation, Access control execution, and logging before system energization.
Lead and oversee architecture, standards and FAT/SAT/CSAT procedures development, execution and performance testing.
Ensure the verification and approval of the 3rd party device access needs as requested by the subcontractor and vendors as part of the commissioning and start-up requirements on the vendor packages.
Participate in technical coordination meetings with cross-functional teams as guided by the Site Cybersecurity lead.
Coordinate with vendors and Air Products engineering team to resolve and liquidate the punch points identified during the field verification of the cyber assets.
Coordinate and assist the Site Cybersecurity Lead with the change management activities to ensure design, procurement, installation, commissioning, and startup of cybersecurity scope are reviewed for schedule, and budget compliance.
Prepare weekly updates and dashboard to the Site cybersecurity lead and the Project Cybersecurity Collaboration Lead.
Identify and escalate risks and opportunities, Collect and report lessons learned during vendor site visits and project execution.
Support OT cybersecurity handovers to operations, including procedures, asset inventories, access management, and incident response alignment.
Contribute to OT Cybersecurity Operations Model, including monitoring, patching, backup, disaster recovery, and secure remote support.
Minimum Requirements:
Bachelor’s degree in engineering (electronics & communication, (or) instrumentation / process automation background is preferred) or equivalent.
Minimum 10 to 15 years’ experience in Operational Technology (OT), or related field with at least 3 years focused on designing (or) building (or) validating the design/implementation of the cybersecurity for industrial control systems and networks.
Project implementation experience of Saudi cyber standards HCIS, NCA, CRA compliance, ISA 62443 Industry standards, specifications, regulations, best practices.
Strong knowledge and understanding of controls systems (SCADA/DCS/PLCs, etc.,), relevant protocols (Modbus, PROFINET, DNP3, IEC61850, etc.), key technologies including Firewalls, IDS, Anti-Virus, Vulnerabilities assessments, etc. in the ICS/OT networks
OT/ICS cybersecurity relevant accreditations such as ISA/IEC62443, SANS or other internationally recognized certifications are preferred.
Additional cybersecurity certifications such as CISSP, CISM, ISO 27001, etc., will be an added advantage
Advanced skills in Microsoft Office tools such as Teams, SharePoint, Word, Excel, Power point and Visio etc.,
Excellent communication skills and the ability to communicate appropriately at all levels of the organization; this includes written and verbal communications
#LI-LG1
تأسست شركة Air Products في عام 1940، وهي شركة رائدة عالمياً في مجال الغازات الصناعية ولديها تاريخ حافل بالابتكار والتميز التشغيلي، مع التزام راسخ بالسلامة والإدارة البيئية. من خلال العمل معاً، نستغل شغفنا وخلفياتنا المتنوعة للمضي قدماً في إعادة تصور ما هو ممكن وخلق مستقبل أنظف لعملائنا ومجتمعاتنا والعالم.
رقم الإعلان لدى المصدر: JR-2026-20569