Air Products تعلن عن وظيفة مهندس أمن سيبراني IT/DT في ضبا
NGHP IT/DT Cybersecurity Engineer
تفاصيل الوظيفة
شركة Air Products تعلن عن وظيفة مهندس الأمن السيبراني لتقنية المعلومات والتحول الرقمي (NGHP IT/DT Cybersecurity Engineer) في موقع ضبا، تبوك، المملكة العربية السعودية.
المهام والمسؤوليات
- دعم تنفيذ والتحقق وتوثيق ضوابط الأمن السيبراني عبر أنظمة الموقع وبيئات OT/ICS والشبكات الصناعية وأدوات الأمن والبنية التحتية الداعمة.
- دعم أنشطة اختبار القبول للأمن السيبراني في الموقع، بما في ذلك التحضير والتنفيذ وجمع الأدلة وتسجيل العيوب وتتبع المشكلات وإغلاق الوثائق.
- المساعدة في جمع ومراجعة وتوثيق أدلة الامتثال لإثبات المطابقة التنظيمية.
- مراجعة أدلة الأمن السيبراني المتعلقة بمخططات الشبكات وهندسة الأنظمة وقواعد جدران الحماية ومعايير التصليب ومصفوفات التحكم في الوصول وقوائم الأصول وإعدادات SIEM والمراقبة وتسجيلات الموردين.
- دعم أنشطة النظافة السيبرانية مع موردين خارجيين ومقاولين من الباطن وفرق الموقع.
- المساعدة في تتبع معالجة الثغرات الأمنية ونتائج اختبارات (Cyber SAT) وتوصيات تقييم المخاطر وفجوات أدلة (POC) ونواقص وثائق الموردين.
- دعم أنشطة أمن OT/ICS بما في ذلك تصليب الأنظمة ومراجعة إعدادات جدران الحماية ومعايير إدارة كلمات المرور وضوابط الوصول عن بُعد والتحقق من أدوات الأمن ودعم تنفيذ المنطقة المجردة (DMZ) والتحقق من تجزئة الشبكة.
- المشاركة في الجولات الميدانية والتحقق التقني ومراجعات واختبار صحة ضوابط الأمن السيبراني.
- دعم تقييم تسليمات الموردين والمقاولين من حيث الامتثال لمتطلبات مشروع الأمن السيبراني ومعايير Air Products وتوقعات (NCA/HCIS) والهندسة المعتمدة.
- العمل مع فرق التحكم في العمليات والبنية التحتية لتقنية المعلومات وأنظمة المصنع والموردين لحل مشكلات الأمن السيبراني التي تؤثر على التشغيل والبدء أو الاستعداد للتسليم.
- توثيق القرارات الفنية وحالة التنفيذ والانحرافات وبنود قبول المخاطر والضوابط التعويضية والإجراءات المفتوحة.
- جمع وتنظيم وصيانة أدلة الأمن السيبراني الفنية اللازمة لإثبات الامتثال والجاهزية التنظيمية.
- إعداد حزم توثيق (CSAT) و(POC) لمراجعتها من قبل قائد الأمن السيبراني وفريق OT وفريق DT والمشروع (NGHC) والمقيّمين الخارجيين.
- ضمان اكتمال الوثائق ودقتها الفنية واتساقها وإمكانية تتبعها للمتطلبات المطبقة.
- الرد على تعليقات NGHC ونتائج المقيّمين الخارجيين وطلبات المتابعة المتعلقة بأدلة الأمن السيبراني.
- الحفاظ على متتبعات دقيقة للمشكلات السيبرانية وفجوات التوثيق وحالة الأدلة وإجراءات المعالجة.
- التنسيق مع موردي الأمن السيبراني ومقاولي EPC والمصنّعين الأصليين (OEMs) وشركاء التنفيذ الخارجيين أثناء الأنشطة الميدانية والاختبار والتوثيق.
- دعم الشركاء الخارجيين المسؤولين عن تنفيذ حلول الأمن السيبراني واختبارها وتوثيقها ودعم الانتقال.
- مراجعة أدلة الموردين المقدمة ورفع أي وثائق غير كاملة أو غير متسقة أو غير ممتثلة إلى قائد الأمن السيبراني.
- تقديم تحديثات الحالة لقائد الأمن السيبراني حول التقدم التقني والعوائق والمخاطر وفجوات التوثيق والإجراءات المفتوحة.
- المشاركة في اجتماعات التنسيق الأسبوعية مع فرق OT Cybersecurity وDT وإدارة المشروع في الموقع وأصحاب المصلحة الآخرين.
الشروط والمتطلبات
- فهم قوي لمبادئ أمن OT/ICS والشبكات الصناعية وأنظمة المصانع والمناطق المجردة الصناعية والوصول الآمن عن بُعد وتصليب الأنظمة والتحكم في الوصول والمراقبة والنظافة السيبرانية.
- معرفة عملية بمتطلبات الأمن السيبراني في المملكة العربية السعودية المتعلقة بـ NCA و HCIS، أو القدرة على تطبيق هذه المتطلبات بسرعة في بيئة مشروع صناعي.
- خبرة في دعم اختبارات الأمن السيبراني والجاهزية للتدقيق وأدلة الامتثال وجمع الأدلة التنظيمية.
- خبرة في مراجعة الوثائق الفنية للأمن السيبراني مثل مخططات الشبكات وقواعد جدران الحماية وهندسة الأنظمة ومصفوفات التحكم وقوائم الأصول وقوائم التصليب وإعدادات المراقبة.
- القدرة على إدارة مهام فنية متعددة وسير عمل توثيقية في وقت واحد.
- مهارات تواصل كتابية وشفهية قوية باللغة الإنجليزية؛ يُفضّل إجادة اللغة العربية.
- القدرة على العمل بفعالية مع فرق الموقع وفرق الهندسة والموردين والمقاولين من الباطن وموارد DT وأصحاب المصلحة الكبار في الأمن السيبراني.
- القدرة على العمل في بيئة مشروع سريعة الخطى مع أولويات متغيرة وتوقعات تنظيمية وتبعيات التشغيل.
- يفضّل خبرة مع أطر عمل مثل NCA ECC وOTCC وHCIS/SAIS وIEC 62443 وISO 27001 وNIST وCIS Controls أو ما يماثلها.
- يفضّل خبرة في مشاريع الطاقة أو الغازات الصناعية أو البتروكيماويات أو المرافق أو توليد الطاقة أو الطاقة المتجددة أو البنية التحتية الحيوية.
- يفضّل خبرة مع أدوات مثل SIEM ومراقبة OT ومراجعة قواعد جدران الحماية وPAM وإدارة الثغرات وجرد الأصول وأمن نقاط النهاية والوصول الآمن عن بُعد وتجزئة الشبكات الصناعية.
- يفضّل الحصول على شهادات مثل GICSP أو IEC 62443 أو Security+ أو CISSP Associate أو CISM أو CEH أو ما يعادلها.
- يفضّل خبرة سابقة في المملكة العربية السعودية أو دول الخليج أو مشاريع NEOM أو البنية التحتية الحيوية.
عرض النص الأصلي للإعلان
At Air Products, we reimagine what’s possible. By tapping into the motivation of our people and our collective experience, we create the ideas and innovations that drive us forward. When we come together - where every voice is heard and everyone knows they belong and matter - we create solutions that launch people into space, support lifesaving care in hospitals, and enable the construction of groundbreaking, world scale production facilities.
Reimagine What’s Possible
Technical Cybersecurity Execution
Reimagine What’s Possible
Technical Cybersecurity Execution
- Support implementation, validation, and documentation of cybersecurity controls across GHE site systems, OT/ICS environments, industrial networks, cybersecurity tools, and supporting DT infrastructure.
- Support cyber site acceptance testing activities, including preparation, execution support, evidence capture, defect logging, issue tracking, and closeout documentation.
- Assist with proof-of-compliance documentation collection, validation, indexing, and quality review.
- Review and support cybersecurity evidence related to network diagrams, system architecture, firewall rules, hardening standards, access control matrices, asset inventories, SIEM/monitoring configurations, and vendor compliance deliverables.
- Support cyber hygiene activities with third-party vendors, subcontractors, and site teams.
- Assist in tracking remediation of cybersecurity gaps, Cyber SAT findings, Cyber Risk Assessment recommendations, POC evidence gaps, and vendor documentation deficiencies.
- Support OT/ICS cybersecurity activities including system hardening, firewall configuration review, password management standards, secure remote access controls, endpoint/security tooling validation, DMZ implementation support, and network segmentation verification.
- Participate in walkthroughs, field verification, technical reviews, and cybersecurity control validation activities.
- Support evaluation of vendor and subcontractor deliverables for compliance with project cybersecurity requirements, Air Products standards, NCA/HCIS expectations, and approved architecture.
- Work with process controls, DT infrastructure, plant computing, and vendor teams to resolve cybersecurity issues impacting commissioning, start-up, or handover readiness.
- Support documentation of technical decisions, implementation status, deviations, risk acceptance items, compensating controls, and open action items.
- Collect, organize, and maintain technical cybersecurity evidence needed for proof of compliance and regulatory readiness.
- Support preparation of CSAT and POC documentation packages for review by the Cyber Lead, OT Cybersecurity, DT, NGHC, and external assessors.
- Ensure documentation is complete, technically accurate, consistent, and traceable to applicable requirements.
- Support responses to NGHC comments, third-party assessor findings, and follow-up requests related to cybersecurity evidence.
- Maintain accurate trackers for cyber issues, documentation gaps, evidence status, and remediation actions.
- Coordinate with cybersecurity vendors, EPC subcontractors, OEMs, and external implementation partners during onsite execution, testing, and documentation activities.
- Support external partners responsible for cybersecurity solution implementation, testing, documentation, and transition support.
- Review vendor-submitted evidence and escalate incomplete, inconsistent, or non-compliant documentation to the Cyber Lead.
- Support site supervision of third-party activities when required, including validation that field work aligns with approved cyber design and project requirements.
- Provide status updates to the Cyber Lead on technical progress, blockers, risks, documentation gaps, and open actions.
- Participate in weekly coordination meetings with OT Cybersecurity, DT, site project management, and other cyber stakeholders.
- Support preparation of concise technical updates for project reporting, cyber oversight meetings, and senior management summaries.
- Coordinate with DT infrastructure teams and site teams to ensure cybersecurity activities are integrated with broader implementation and commissioning work.
- Strong understanding of OT/ICS cybersecurity principles, industrial networks, plant systems, industrial DMZs, secure remote access, system hardening, access control, monitoring, and cyber hygiene.
- Working knowledge of KSA cybersecurity requirements related to NCA and HCIS, or ability to rapidly apply these requirements in an industrial project environment.
- Experience supporting cybersecurity testing, audit readiness, proof-of-compliance documentation, or regulatory evidence collection.
- Experience reviewing technical cybersecurity documentation such as network diagrams, firewall rules, system architecture, control matrices, asset inventories, hardening checklists, and monitoring configurations.
- Ability to manage multiple technical tasks and documentation workstreams at the same time.
- Strong written and verbal communication skills in English; Arabic language skills preferred.
- Ability to work effectively with site teams, engineering teams, vendors, subcontractors, DT resources, and senior cybersecurity stakeholders.
- Ability to operate in a fast-paced project environment with changing priorities, regulatory expectations, and commissioning dependencies.
- Experience with NCA ECC, OTCC, HCIS/SAIS, IEC 62443, ISO 27001, NIST, CIS Controls, or similar cybersecurity control frameworks.
- Experience in energy, industrial gas, chemical, utility, power generation, renewable energy, or critical infrastructure projects.
- Experience with SIEM, OT monitoring, firewall rule review, PAM, vulnerability management, asset inventory, endpoint security, secure remote access, and industrial network segmentation.
- Certifications such as GICSP, IEC 62443, Security+, CISSP Associate, CISM, CEH, or equivalent are preferred.
- Prior Saudi Arabia, GCC, NEOM, or critical infrastructure project experience is preferred.
- CSAT and POC evidence are collected, validated, organized, and maintained in a usable format.
- Cybersecurity documentation gaps, technical issues, and remediation actions are tracked and closed.
- Vendor and subcontractor cybersecurity deliverables are reviewed for completeness and quality.
- Technical cybersecurity controls are validated against approved design, project requirements, and compliance expectations.
- Cyber Lead, DT Project Manager, PDO Cybersecurity, and NGHC stakeholders receive accurate technical status updates.
- Site cybersecurity activities support commissioning, start-up readiness, and regulatory compliance objectives.
المصدر: LinkedIn - أُضيفت للموقع في 28 أغسطس 2026
رقم الإعلان لدى المصدر: 4441277139
رقم الإعلان لدى المصدر: 4441277139