Job description
At Air Products, we reimagine what’s possible. By tapping into the motivation of our people and our collective experience, we create the ideas and innovations that drive us forward. When we come together – where every voice is heard and everyone knows they belong and matter – we create solutions that launch people into space, support lifesaving care in hospitals, and enable the construction of groundbreaking, world scale production facilities.
Reimagine What’s Possible
DT Cybersecurity Leadership and Site Execution
- Lead and coordinate cybersecurity activities at site, including cyber site acceptance testing, cyber hygiene activities, cyber readiness reviews, proof-of-compliance documentation collection, and closure of cybersecurity implementation gaps.
- Serve as the site-based cybersecurity point of coordination between DT, OT/ICS Cybersecurity, project management, process controls, vendors, subcontractors, and NGHC stakeholders.
- Provide day-to-day direction to cybersecurity engineers, external partners, and site-based cyber resources supporting implementation, testing, documentation, and evidence collection.
- Ensure cyber activities are aligned to the project schedule, commissioning priorities, start-up needs, and compliance milestones.
- Coordinate with the DT Project Manager and OT/ICS Cybersecurity team to maintain a consolidated schedule of cybersecurity deliverables, dependencies, risks, and milestones.
Regulatory and Compliance Readiness
- Support execution of cybersecurity activities aligned to applicable KSA regulatory requirements, including NCA ECC, NCA OTCC, HCIS/SAIS operating permit requirements, and applicable CNI/critical systems obligations.
- Lead collection, organization, quality review, and readiness of Proof of Compliance documentation required to support HCIS and NCA compliance activities.
- Coordinate with NGHC on CSAT witnessing, evidence review, documentation feedback, and comment resolution.
- Support NGHC in preparing cybersecurity evidence packages and responses for regulatory submission, recognizing that NGHC is expected to submit documentation to HCIS and NCA while Air Products/APEPC supports project delivery and evidence readiness.
- Ensure compliance documentation is complete, traceable, controlled, and organized for audit, regulatory review, and stakeholder approval.
Stakeholder Interface and Governance
- Interface regularly with the OT/ICS Cybersecurity team, including alignment with PDO on-site cyber resources performing CSAT, cyber hygiene, and vendor-related compliance activities.
- Conduct routine coordination meetings with OT/ICS Cybersecurity, DT, NGHC, and project stakeholders to align cyber execution activities, risks, blockers, and decisions.
- Communicate cybersecurity status, risks, issues, dependencies, and escalation items effectively to senior management and project leadership.
- Translate technical cybersecurity and compliance topics into clear, actionable updates for project executives, DT leadership, NGHC, PDO, and external partners.
- Support governance meetings, executive cyber oversight reviews, and compliance readiness discussions.
Third-Party and Vendor Oversight
- Manage and supervise external partners engaged to design, purchase, implement, document, test, or support cybersecurity solutions for the GHE scope.
- Oversee on-site work performed by external cybersecurity implementation partners and ensure deliverables meet Air Products, NGHC, NCA, HCIS, and project requirements.
- Coordinate third-party support between CSAT, commissioning, start-up, and handover to NGHC.
- Ensure vendor/subcontractor cybersecurity deliverables are tracked, reviewed, documented, and escalated when gaps or delays affect compliance or project readiness.
- Support review of vendor documentation, cyber execution plans, network/security architecture, hardening evidence, access control matrices, SIEM/monitoring documentation, and POC packages.
DT, OT, and Project Integration
- Serve as the interface between DT infrastructure activities and cybersecurity-related activities at site.
- Support alignment across OT systems, industrial DMZs, site network architecture, identity/access controls, monitoring, cyber hygiene, and cyber readiness activities.
- Identify scope gaps, accountability gaps, technical blockers, and documentation gaps that could affect regulatory compliance, start-up readiness, or handover.
- Partner with site engineering, process controls, and project management teams to ensure cybersecurity activities are integrated into site work plans and commissioning sequences.
- Support handover readiness by ensuring documentation, evidence, operating assumptions, and support responsibilities are clearly defined.
Skills
Required Qualifications and Experience
- Strong understanding of KSA cybersecurity regulations and regulatory expectations, including NCA and HCIS requirements.
- Understanding of contractual cybersecurity obligations between Air Products/APEPC and NGHC.
- Experience leading OT/ICS cybersecurity activities in industrial, energy, chemical, utility, critical infrastructure, or large capital project environments.
- Experience with cybersecurity site acceptance testing, proof-of-compliance documentation, regulatory evidence collection, cyber risk assessment closure, and audit readiness.
- Ability to manage multiple concurrent priorities across project execution, stakeholder coordination, regulatory compliance, vendor management, and site readiness.
- Strong written and verbal communication skills in English; Arabic language capability a plus.
- Ability to communicate effectively with senior management while also understanding and directing detailed day-to-day work activities at site.
- Strong stakeholder management skills across project, engineering, cybersecurity, operations, vendors, and external/customer organizations.
- Familiarity with OT/ICS security principles, including segmentation, industrial DMZs, secure remote access, access control, hardening, monitoring, and incident readiness.
- Ability to operate in a complex, multi-party environment involving Air Products, NGHC, PDO, DT, EPC contractors, vendors, and regulatory stakeholders.
وصف الوظيفة
في Air Products، نعيد تصور ما هو ممكن. من خلال الاستفادة من دافع موظفينا وخبرتنا الجماعية، نبتكر الأفكار والابتكارات التي تدفعنا للأمام. عندما نجتمع معاً — حيث يُسمَع كل صوت ويعرف الجميع أنهم ينتمون ويهمون — نخلق حلولاً تطلق الأشخاص إلى الفضاء، وتدعم الرعاية المنقذة للحياة في المستشفيات، وتمكن من بناء مرافق إنتاج على مستوى العالم تُحدث ثورة في القطاع.
إعادة تصور ما هو ممكن
قيادة DT للأمن السيبراني وتنفيذ الموقع
- قيادة وتنسيق أنشطة الأمن السيبراني في الموقع، بما في ذلك اختبار القبول السيبراني للموقع، أنشطة النظافة السيبرانية، مراجعات جاهزية الأمن السيبراني، جمع وثائق إثبات الالتزام، وإغلاق فجوات تنفيذ الأمن السيبراني.
- العمل كنقطة التنسيق الأمنية السيبرانية في الموقع بين DT وOT/ICS Security وادارة المشروع وعمليات التحكم والموردين وأصحاب المصلحة في NGHC.
- توفير التوجيه اليومي لمهندسي الأمن السيبراني والشركاء الخارجيين وموارد الأمن السيبراني في الموقع التي تدعم التنفيذ والاختبار والتوثيق وجمع الأدلة.
- ضمان توافق أنشطة الأمن السيبراني مع جدول المشروع وأولويات التكليف واحتياجات البدء ومعايير الامتثال.
- التنسيق مع مدير مشروع DT وفريق OT/ICS Cybersecurity للحفاظ على جدول موحد لتسليمات الأمن السيبراني والاعتماديات والمخاطر والمعالم.
الجاهزية التنظيمية والامتثال
- دعم تنفيذ أنشطة الأمن السيبراني المتوافقة مع المتطلبات التنظيمية المعمول بها في المملكة العربية السعودية، بما في ذلك NCA ECC وNCA OTCC ومتطلبات تصاريح التشغيل HCIS/SAIS والالتزامات المطبقة على الأنظمة الحيوية/الأنظمة الحرجة.
- قيادة جمع وتنظيم ومراجعة جودة واستعداد وثائق إثبات الامتثال اللازمة لدعم امتثال HCIS وNCA.
- التنسيق مع NGHC في الشهادة CSAT ومراجعة الأدلة وتغذية التغذية المرتدة للوثائق وحل التعليقات.
- دعم NGHC في إعداد حزم أدلة الأمن السيبراني والردود للجهات التنظيمية، مع الاعتراف بأن NGHC من المتوقع أن يقدم الوثائق إلى HCIS وNCA بينما تدعم Air Products/APEPC تسليم المشروع واستعداد الأدلة.
- تأكيد اكتمال وثائق الامتثال وتتبعها وسيطرتها وتنظيمها للمراجعة التدقيقية والمراجعة التنظيمية والموافقة من أصحاب المصلحة.
واجهة أصحاب المصلحة والحوكمة
- التواصل باستمرار مع فريق OT/ICS Cybersecurity، بما في ذلك التوافق مع الموارد السيبرانية على الموقع Performing CSAT وcyber hygiene وأنشطة الامتثال المرتبطة بالموردين.
- عقد اجتماعات تنسيق روتينية مع OT/ICS Cybersecurity وDT وNGHC وأصحاب المصلحة في المشروع لتوافق أنشطة التنفيذ الأمني والسياسات والمخاطر والعوائق والقرارات.
- التواصل الفعّال لحالة الأمن السيبراني والمخاطر والقضايا والاعتماديات وعناصر التصعيد للإدارة العليا وقيادة المشروع.
- ترجمة مواضيع الأمن السيبراني والامتثال الفنية إلى تحديثات واضحة وقابلة للتنفيذ لمديري المشروع والقيادة في DT وNGHC وPDO والشركاء الخارجيين.
- دعم اجتماعات الحوكمة ومراجعات الرقابة التنفيذية للأمن السيبراني ومناقشات جاهزية الامتثال.
الإشراف على الأطراف الثالثة والموردين
- إدارة والإشراف على الشركاء الخارجيين المكلفين بتصميم وشراء وتنفيذ وتوثيق واختبار أو دعم حلول الأمن السيبراني ضمن نطاق GHE.
- الإشراف على الأعمال الميدانية التي ينفذها شركاء تنفيذ الأمن السيبراني من الطرف الثالث والتأكد من أن النتائج تفي بمتطلبات Air Products وNGHC وNCA وHCIS والمشروع.
- تنسيق دعم الطرف الثالث بين CSAT والتكليف والبدء والتسليم إلى NGHC.
- ضمان تتبع وتوثيق وتوثيق وتطوير حلول الأمن السيبراني لدى الموردين/subcontractors والتصعيد عند وجود فجوات أو تأخيرات تؤثر على الامتثال أو جاهزية المشروع.
- دعم مراجعة وثائق الموردين وخطط تنفيذ الأمن السيبراني وهندسة الشبكات/الأمان وإثباتات التعزيز ومصفوفات التحكم في الوصول ووثائق SIEM/المراقبة وحزم POC.
التكامل DT وOT والمشروع
- العمل كواجهة بين أنشطة بنية DT التحتية والأنشطة ذات الصلة بالأمن السيبراني في الموقع.
- دعم التوافق عبر أنظمة OT وDMZ الصناعية، وهندسة شبكة الموقع، والتحكم في الهوية/الوصول، والمراقبة، والنظافة السيبرانية، واستعداد الأمن السيبراني.
- تحديد ثغرات النطاق ونقاط المساءلة والمعوقات التقنية وثغرات التوثيق التي قد تؤثر على الامتثال التنظيمي أو جاهزية البدء أو التسليم.
- الشراكة مع فرق الهندسة في الموقع، والتحكم في العمليات، وإدارة المشاريع لضمان دمج أنشطة الأمن السيبراني في خطط العمل بالموقع وتسلسلات التكليف.
- دعم جاهزية التسليم من خلال ضمان تعريف واضح للتوثيق، والأدلة، والافتراضات التشغيلية، ومسؤوليات الدعم.