إير برودكتس تعلن عن وظيفة مهندس أمن سيبراني ICS في ضباء
تفاصيل الوظيفة
شركة إير برودكتس، الرائدة عالمياً في مجال الغازات الصناعية، تعلن عن وظيفة مهندس أمن سيبراني لأنظمة التحكم الصناعي (ICS Cybersecurity Engineer) للعمل في مشروع نيوم للهيدروجين الأخضر في مدينة ضبا، المملكة العربية السعودية. سيكون المهندس جزءاً من فريق أمن سيبراني مسؤول عن التحقق الميداني للأصول السيبرانية لضمان الامتثال للمواصفات ومعايير القبول في الموقع، والعمل بنظام المناوبة 8 أسابيع عمل / أسبوعين إجازة.
المهام والمسؤوليات
- التحقق الميداني من تصميم وتنفيذ واختبار الأصول السيبرانية للامتثال لمعايير الأمن السيبراني والمتطلبات التنظيمية والتقنيات والإجراءات والمواصفات، وذلك لنقل أصول المشروع إلى مراحل التشغيل والبدء والتسليم النهائي للعميل.
- تطوير وتوثيق وصيانة سجل الأصول السيبرانية والمخرجات الرئيسية الأخرى وفق توجيهات قائد الأمن السيبراني في الموقع أو مدير الأمن السيبراني.
- تنظيم وقيادة/تيسير إجراء تقييمات المخاطر السيبرانية وتنفيذ توصياتها لتصميم إير برودكتس ولأنظمة التحكم في الحزم/المعدات.
- دعم فرق ما قبل التشغيل والتشغيل من خلال التحقق من قواعد جدار الحماية، والوصول عن بُعد الآمن، وتصلب نقاط النهاية، والتحقق من قائمة الأصول، وتنفيذ التحكم في الوصول، والتسجيل قبل تشغيل النظام.
- الإشراف على تطوير وتنفيذ واختبار المعايير المعمارية وإجراءات FAT و SAT و CSAT.
- ضمان التحقق والموافقة على احتياجات الوصول لأجهزة الطرف الثالث حسب طلب المقاولين من الباطن والموردين كجزء من متطلبات التشغيل والبدء لحزم الموردين.
- المشاركة في اجتماعات التنسيق الفني مع الفرق متعددة الوظائف حسب توجيهات قائد الأمن السيبراني في الموقع.
- التنسيق مع الموردين وفريق الهندسة في إير برودكتس لحل وإغلاق نقاط الملاحظات التي تم تحديدها أثناء التحقق الميداني من الأصول السيبرانية.
- التنسيق ومساعدة قائد الأمن السيبراني في الموقع في أنشطة إدارة التغيير لضمان مراجعة التصميم والمشتريات والتركيب والتشغيل والبدء لنطاق الأمن السيبراني من حيث الجدول الزمني والامتثال للميزانية.
- إعداد تحديثات أسبوعية ولوحة بيانات وتقديمها إلى قائد الأمن السيبراني في الموقع وقائد تعاون الأمن السيبراني في المشروع.
- تحديد المخاطر والفرص ورفعها، وجمع الدروس المستفادة والإبلاغ عنها أثناء زيارات الموردين للموقع وتنفيذ المشروع.
- دعم تسليم الأمن السيبراني لأنظمة التحكم التشغيلية (OT) إلى العمليات، بما في ذلك الإجراءات وسجلات الأصول وإدارة الوصول ومواءمة الاستجابة للحوادث.
- المساهمة في نموذج تشغيل الأمن السيبراني لأنظمة OT، بما في ذلك المراقبة والتصحيح والنسخ الاحتياطي واستعادة الكوارث والدعم عن بُعد الآمن.
الشروط والمتطلبات
- درجة البكالوريوس في الهندسة (يفضل تخصص الإلكترونيات والاتصالات، أو الأجهزة/أتمتة العمليات) أو ما يعادلها.
- خبرة لا تقل عن 10 إلى 15 سنة في مجال التكنولوجيا التشغيلية (OT) أو مجال ذي صلة، مع 3 سنوات على الأقل متخصصة في تصميم أو بناء أو التحقق من تصميم/تنفيذ الأمن السيبراني لأنظمة التحكم الصناعية والشبكات.
- خبرة في تنفيذ مشاريع تلتزم بالمعايير السيبرانية السعودية HCIS، NCA، CRA، ومعايير ISA 62443 الصناعية والمواصفات واللوائح وأفضل الممارسات.
- شهادات اعتماد ذات صلة بالأمن السيبراني لأنظمة OT/ICS مثل ISA/IEC62443 أو SANS أو غيرها من الشهادات المعترف بها دولياً (يفضل).
- شهادات أمن سيبراني إضافية مثل CISSP، CISM، ISO 27001 تعتبر ميزة إضافية.
- العمل بنظام المناوبة: 8 أسابيع عمل / أسبوعين إجازة في موقع المشروع بمدينة ضبا.
المهارات المطلوبة
- معرفة وفهم قويين لأنظمة التحكم (SCADA/DCS/PLCs وغيرها) والبروتوكولات ذات الصلة (Modbus، PROFINET، DNP3، IEC61850 وغيرها) والتقنيات الرئيسية مثل جدران الحماية وأنظمة كشف التسلل ومكافحة الفيروسات وتقييمات الثغرات في شبكات ICS/OT.
- مهارات متقدمة في أدوات مايكروسوفت أوفيس مثل Teams، SharePoint، Word، Excel، PowerPoint وVisio.
- مهارات اتصال ممتازة والقدرة على التواصل بشكل مناسب مع جميع مستويات المؤسسة، شفوياً وكتابياً.
عرض النص الأصلي للإعلان
في شركة «إير برودكتس»، نعيد تصور ما هو ممكن. من خلال الاستفادة من حماس موظفينا وخبرتنا الجماعية، نبتكر الأفكار والابتكارات التي تدفعنا إلى الأمام. عندما نجتمع معًا - حيث تُسمع كل صوت ويشعر الجميع بالانتماء والأهمية - نبتكر حلولًا تنقل البشر إلى الفضاء، وتدعم الرعاية المنقذة للحياة في المستشفيات، وتتيح إنشاء منشآت إنتاج رائدة على نطاق عالمي.
إعادة تصور ما هو ممكن
NEOM Green Hydrogen Project is part of the most complex capital project and a flagship project at scale for Air Products. Air Products is executing a EPC Contract with the customer - NEOM Green Hydrogen Company (NGHC). Air Products have the responsibility to design, build and delivery Process Controls / Process Automation System and IT/Digital Technology infrastructure scope. This scope shall comply with the local laws and regulations on cybersecurity, which is a crucial part in the project’s safety, security and overall compliance.
The incumbent in this position based at project site, as ICS Cyber Security Engineer, plays a key member of a Cybersecurity task force team to undertake the field verification of the cyber assets to comply with the project specifications and the site acceptance criteria.
The Engineer is also responsible for coordinating with Engineering, Pre-Commissioning, Commissioning and Client operations team related to Cyber Security field verifications.
The Cyber Security engineer acts as the technical interface between Air Products project execution, commissioning teams and the vendors, during the field verification of cyber assets.
Experience in supporting large scale construction, pre commissioning, commissioning, startup and handover phases, ensuring cybersecurity controls are implemented without impacting schedule critical activities
The position is based out of Duba, Tabuk Region, Saudi Arabia working on rotation of 8 Weeks ON / 2 Weeks OFF.
The position will be a site-based role with the below duties:
Perform the field verification of the design, implementation and testing of the cyber assets to meet the cybersecurity standards, regulatory requirements and technologies, processes/procedures and specifications to transition the project assets to commissioning, start-up and final handover to the client.
Develop, document, and maintain cybersecurity asset register and other key deliverables as guided by the Site Cybersecurity Lead or Cybersecurity Manager.
Organize and lead/facilitate the resolution and implementation of the cybersecurity risk assessment exercises and implement risk assessment recommendations for Air Products design and also for vendor/ skid package control system
Support pre‑commissioning and commissioning teams by validating firewall rules, secure remote access, endpoint hardening, Asset inventory validation, Access control execution, and logging before system energization.
Lead and oversee architecture, standards and FAT/SAT/CSAT procedures development, execution and performance testing.
Ensure the verification and approval of the 3rd party device access needs as requested by the subcontractor and vendors as part of the commissioning and start-up requirements on the vendor packages.
Participate in technical coordination meetings with cross-functional teams as guided by the Site Cybersecurity lead.
Coordinate with vendors and Air Products engineering team to resolve and liquidate the punch points identified during the field verification of the cyber assets.
Coordinate and assist the Site Cybersecurity Lead with the change management activities to ensure design, procurement, installation, commissioning, and startup of cybersecurity scope are reviewed for schedule, and budget compliance.
Prepare weekly updates and dashboard to the Site cybersecurity lead and the Project Cybersecurity Collaboration Lead.
Identify and escalate risks and opportunities, Collect and report lessons learned during vendor site visits and project execution.
Support OT cybersecurity handovers to operations, including procedures, asset inventories, access management, and incident response alignment.
Contribute to OT Cybersecurity Operations Model, including monitoring, patching, backup, disaster recovery, and secure remote support.
Minimum Requirements:
Bachelor’s degree in engineering (electronics & communication, (or) instrumentation / process automation background is preferred) or equivalent.
Minimum 10 to 15 years’ experience in Operational Technology (OT), or related field with at least 3 years focused on designing (or) building (or) validating the design/implementation of the cybersecurity for industrial control systems and networks.
Project implementation experience of Saudi cyber standards HCIS, NCA, CRA compliance, ISA 62443 Industry standards, specifications, regulations, best practices.
Strong knowledge and understanding of controls systems (SCADA/DCS/PLCs, etc.,), relevant protocols (Modbus, PROFINET, DNP3, IEC61850, etc.), key technologies including Firewalls, IDS, Anti-Virus, Vulnerabilities assessments, etc. in the ICS/OT networks
OT/ICS cybersecurity relevant accreditations such as ISA/IEC62443, SANS or other internationally recognized certifications are preferred.
Additional cybersecurity certifications such as CISSP, CISM, ISO 27001, etc., will be an added advantage
Advanced skills in Microsoft Office tools such as Teams, SharePoint, Word, Excel, Power point and Visio etc.,
Excellent communication skills and the ability to communicate appropriately at all levels of the organization; this includes written and verbal communications
#LI-LG1
تأسست شركة Air Products في عام 1940، وهي شركة رائدة عالمياً في مجال الغازات الصناعية ولديها تاريخ حافل بالابتكار والتميز التشغيلي، مع التزام راسخ بالسلامة والإدارة البيئية. من خلال العمل معاً، نستغل شغفنا وخلفياتنا المتنوعة للمضي قدماً في إعادة تصور ما هو ممكن وخلق مستقبل أنظف لعملائنا ومجتمعاتنا والعالم.
رقم الإعلان لدى المصدر: JR-2026-20571