إير برودكتس تعلن عن وظيفة مهندس أمن سيبراني ICS في ضباء
تفاصيل الوظيفة
في شركة «إير برودكتس»، نبحث عن مهندس أمن سيبراني لأنظمة التحكم الصناعية (ICS Cybersecurity Engineer) للعمل في مشروع الهيدروجين الأخضر NEOM في دبا، منطقة تبوك، المملكة العربية السعودية. سيكون المهندس جزءاً من فريق أمن سيبراني مكلف بالتحقق الميداني للأصول السيبرانية لضمان الامتثال لمواصفات المشروع ومعايير القبول في الموقع.
المهام والمسؤوليات
- التحقق الميداني من تصميم وتنفيذ واختبار الأصول السيبرانية وفقاً لمعايير الأمن السيبراني والمتطلبات التنظيمية والتقنيات والإجراءات، لضمان انتقال أصول المشروع إلى مرحلة التشغيل والتسليم النهائي للعميل.
- تطوير وتوثيق وصيانة سجل الأصول السيبرانية والمخرجات الرئيسية الأخرى بتوجيه من قائد الأمن السيبراني في الموقع أو مدير الأمن السيبراني.
- تنظيم وقيادة/تيسير حل وتنفيذ تمارين تقييم المخاطر السيبرانية، وتنفيذ توصيات تقييم المخاطر لتصميم إير برودكتس وأنظمة التحكم الخاصة بالبائعين/الحزم.
- دعم فرق ما قبل التشغيل والتشغيل من خلال التحقق من صحة قواعد جدار الحماية، والوصول عن بُعد الآمن، وتصلب نقاط النهاية، والتحقق من مخزون الأصول، وتنفيذ التحكم في الوصول، وتسجيل الدخول قبل تشغيل النظام.
- قيادة والإشراف على تطوير المعايير والهندسة المعمارية وإجراءات اختبار FAT/SAT/CSAT وتنفيذها واختبار الأداء.
- ضمان التحقق والموافقة على احتياجات الوصول لأجهزة الطرف الثالث التي يطلبها المقاولون من الباطن والبائعون كجزء من متطلبات التشغيل والتشغيل على حزم البائعين.
- المشاركة في اجتماعات التنسيق الفني مع الفرق متعددة الوظائف بتوجيه من قائد الأمن السيبراني في الموقع.
- التنسيق مع البائعين وفريق الهندسة في إير برودكتس لحل وإغلاق نقاط القصور التي تم تحديدها أثناء التحقق الميداني من الأصول السيبرانية.
- التنسيق ومساعدة قائد الأمن السيبراني في الموقع في أنشطة إدارة التغيير لضمان مراجعة نطاق الأمن السيبراني من حيث التصميم والمشتريات والتركيب والتشغيل والبدء، والامتثال للجدول الزمني والميزانية.
- إعداد تحديثات أسبوعية ولوحة معلومات لقائد الأمن السيبراني في الموقع وقائد تعاون الأمن السيبراني للمشروع.
- تحديد ورفع المخاطر والفرص، وجمع الدروس المستفادة والإبلاغ عنها أثناء زيارات البائعين للموقع وتنفيذ المشروع.
- دعم تسليم الأمن السيبراني لتقنية التشغيل (OT) إلى عمليات التشغيل، بما في ذلك الإجراءات وسجلات الأصول وإدارة الوصول ومواءمة الاستجابة للحوادث.
- المساهمة في نموذج تشغيل الأمن السيبراني لتقنية التشغيل (OT)، بما في ذلك المراقبة والتصحيح والنسخ الاحتياطي والتعافي من الكوارث والدعم عن بُعد الآمن.
الشروط والمتطلبات
- درجة البكالوريوس في الهندسة (يفضل تخصص الإلكترونيات والاتصالات أو الأجهزة/أتمتة العمليات) أو ما يعادلها.
- خبرة لا تقل عن 10 إلى 15 سنة في مجال تقنية التشغيل (OT) أو مجال ذي صلة، مع خبرة لا تقل عن 3 سنوات في تصميم أو بناء أو التحقق من تصميم/تنفيذ الأمن السيبراني لأنظمة التحكم الصناعية والشبكات.
- خبرة في تنفيذ المشاريع المتوافقة مع معايير الأمن السيبراني السعودية HCIS وNCA وCRA ومعايير ISA 62443 واللوائح وأفضل الممارسات.
- معرفة قوية وفهم لأنظمة التحكم (SCADA وDCS وPLCs وغيرها)، والبروتوكولات ذات الصلة (Modbus وPROFINET وDNP3 وIEC61850 وغيرها)، والتقنيات الرئيسية بما في ذلك جدران الحماية وأنظمة كشف التسلل ومكافحة الفيروسات وتقييم الثغرات في شبكات ICS/OT.
المهارات المطلوبة
- يفضل الحصول على اعتمادات ذات صلة بأمن تقنية التشغيل/أنظمة التحكم الصناعية مثل ISA/IEC62443 أو SANS أو غيرها من الشهادات المعترف بها دولياً.
- تُعد شهادات أمن إضافية مثل CISSP أو CISM أو ISO 27001 ميزة إضافية.
- مهارات متقدمة في أدوات Microsoft Office مثل Teams وSharePoint وWord وExcel وPowerPoint وVisio.
- مهارات تواصل ممتازة كتابياً وشفهياً، والقدرة على التواصل بشكل مناسب مع جميع مستويات المؤسسة.
المزايا
- جدول عمل دوري: 8 أسابيع عمل / 2 أسبوع إجازة.
عرض النص الأصلي للإعلان
في شركة «إير برودكتس»، نعيد تصور ما هو ممكن. من خلال الاستفادة من حماس موظفينا وخبرتنا الجماعية، نبتكر الأفكار والابتكارات التي تدفعنا إلى الأمام. عندما نجتمع معًا - حيث تُسمع كل صوت ويشعر الجميع بالانتماء والأهمية - نبتكر حلولًا تنقل البشر إلى الفضاء، وتدعم الرعاية المنقذة للحياة في المستشفيات، وتتيح إنشاء منشآت إنتاج رائدة على نطاق عالمي.
إعادة تصور ما هو ممكن
NEOM Green Hydrogen Project is part of the most complex capital project and a flagship project at scale for Air Products. Air Products is executing a EPC Contract with the customer - NEOM Green Hydrogen Company (NGHC). Air Products have the responsibility to design, build and delivery Process Controls / Process Automation System and IT/Digital Technology infrastructure scope. This scope shall comply with the local laws and regulations on cybersecurity, which is a crucial part in the project’s safety, security and overall compliance.
The incumbent in this position based at project site, as ICS Cyber Security Engineer, plays a key member of a Cybersecurity task force team to undertake the field verification of the cyber assets to comply with the project specifications and the site acceptance criteria.
The Engineer is also responsible for coordinating with Engineering, Pre-Commissioning, Commissioning and Client operations team related to Cyber Security field verifications.
The Cyber Security engineer acts as the technical interface between Air Products project execution, commissioning teams and the vendors, during the field verification of cyber assets.
Experience in supporting large scale construction, pre commissioning, commissioning, startup and handover phases, ensuring cybersecurity controls are implemented without impacting schedule critical activities
The position is based out of Duba, Tabuk Region, Saudi Arabia working on rotation of 8 Weeks ON / 2 Weeks OFF.
The position will be a site-based role with the below duties:
Perform the field verification of the design, implementation and testing of the cyber assets to meet the cybersecurity standards, regulatory requirements and technologies, processes/procedures and specifications to transition the project assets to commissioning, start-up and final handover to the client.
Develop, document, and maintain cybersecurity asset register and other key deliverables as guided by the Site Cybersecurity Lead or Cybersecurity Manager.
Organize and lead/facilitate the resolution and implementation of the cybersecurity risk assessment exercises and implement risk assessment recommendations for Air Products design and also for vendor/ skid package control system
Support pre‑commissioning and commissioning teams by validating firewall rules, secure remote access, endpoint hardening, Asset inventory validation, Access control execution, and logging before system energization.
Lead and oversee architecture, standards and FAT/SAT/CSAT procedures development, execution and performance testing.
Ensure the verification and approval of the 3rd party device access needs as requested by the subcontractor and vendors as part of the commissioning and start-up requirements on the vendor packages.
Participate in technical coordination meetings with cross-functional teams as guided by the Site Cybersecurity lead.
Coordinate with vendors and Air Products engineering team to resolve and liquidate the punch points identified during the field verification of the cyber assets.
Coordinate and assist the Site Cybersecurity Lead with the change management activities to ensure design, procurement, installation, commissioning, and startup of cybersecurity scope are reviewed for schedule, and budget compliance.
Prepare weekly updates and dashboard to the Site cybersecurity lead and the Project Cybersecurity Collaboration Lead.
Identify and escalate risks and opportunities, Collect and report lessons learned during vendor site visits and project execution.
Support OT cybersecurity handovers to operations, including procedures, asset inventories, access management, and incident response alignment.
Contribute to OT Cybersecurity Operations Model, including monitoring, patching, backup, disaster recovery, and secure remote support.
Minimum Requirements:
Bachelor’s degree in engineering (electronics & communication, (or) instrumentation / process automation background is preferred) or equivalent.
Minimum 10 to 15 years’ experience in Operational Technology (OT), or related field with at least 3 years focused on designing (or) building (or) validating the design/implementation of the cybersecurity for industrial control systems and networks.
Project implementation experience of Saudi cyber standards HCIS, NCA, CRA compliance, ISA 62443 Industry standards, specifications, regulations, best practices.
Strong knowledge and understanding of controls systems (SCADA/DCS/PLCs, etc.,), relevant protocols (Modbus, PROFINET, DNP3, IEC61850, etc.), key technologies including Firewalls, IDS, Anti-Virus, Vulnerabilities assessments, etc. in the ICS/OT networks
OT/ICS cybersecurity relevant accreditations such as ISA/IEC62443, SANS or other internationally recognized certifications are preferred.
Additional cybersecurity certifications such as CISSP, CISM, ISO 27001, etc., will be an added advantage
Advanced skills in Microsoft Office tools such as Teams, SharePoint, Word, Excel, Power point and Visio etc.,
Excellent communication skills and the ability to communicate appropriately at all levels of the organization; this includes written and verbal communications
#LI-LG1
تأسست شركة Air Products في عام 1940، وهي شركة رائدة عالمياً في مجال الغازات الصناعية ولديها تاريخ حافل بالابتكار والتميز التشغيلي، مع التزام راسخ بالسلامة والإدارة البيئية. من خلال العمل معاً، نستغل شغفنا وخلفياتنا المتنوعة للمضي قدماً في إعادة تصور ما هو ممكن وخلق مستقبل أنظف لعملائنا ومجتمعاتنا والعالم.
رقم الإعلان لدى المصدر: JR-2026-20570