حول Air Products
Air Products، التي تأسست في عام 1940، هي شركة عالمية رائدة في مجال الغازات الصناعية معروفة بتاريخها الطويل في الابتكار، والتميز التشغيلي، والالتزام الثابت بالسلامة والحماية البيئية. تركز الشركة على خلق حلول تدعم صناعات مختلفة، بدءاً من استكشاف الفضاء وحتى الرعاية الصحية ومرافق الإنتاج كبيرة النطاق، من خلال استغلال خبرة دافعة ومشتركة بين أفرادها.
الفرصة: NGHP IT/DT Cybersecurity Lead
تبحث Air Products عن NGHP IT/DT Cybersecurity Lead للانضمام إلى فريقها في دبي، تبوك، المملكة العربية السعودية. يتطلب هذا الدور بدوام كامل 5-10 سنوات من الخبرة ويشمل قيادة أنشطة الأمن السيبراني لمشروع هام، مع ضمان الامتثال والجاهزية التشغيلية.
المسؤوليات الرئيسية
- قيادة وتنسيق أنشطة الأمن السيبراني في الموقع، بما في ذلك اختبار قبول الموقع، النظافة السيبرانية، مراجعات الجاهزية، وإغلاق ثغرات التنفيذ.
- العمل كنقطة تنسيق الأمن السيبراني المعتمدة في الموقع بين DT، الأمن السيبراني OT/ICS، إدارة المشروع، ضوابط العمليات، البائعين، المقاولين، وأصحاب المصلحة NGHC.
- توفير التوجيه اليومي لمهندسي الأمن السيبراني، الشركاء الخارجيين، وموارد السيبراني في الموقع.
- ضمان توافق أنشطة الأمن السيبراني مع جداول المشروع، أولويات التكليف، احتياجات البدء، ومعالم الامتثال.
- إدارة وإشراف الشركاء الخارجيين المشاركين في تصميم، تنفيذ، توثيق، اختبار، أو دعم حلول الأمن السيبراني.
- الإشراف على الأعمال في الموقع التي يقوم بها شركاء تنفيذ الأمن السيبراني الخارجيين لضمان مطابقة النتائج لمتطلبات Air Products، NGHC، NCA، HCIS، والمشروع.
- تنسيق الدعم من طرف ثالث بين CSAT، التكليف، البدء، وتسليم NGHC.
- تتبع ومراجعة وتوثيق وتصعيد تسليمات الأمن السيبراني للبائع/المقاول من الباطن عندما تؤثر الثغرات أو التأخيرات على الامتثال أو جاهزية المشروع.
- العمل كواجهة بين أنشطة بنية تحتية DT والأنشطة المتعلقة بالأمن السيبراني في الموقع.
- دعم التوافق عبر أنظمة OT، مناطق DMZ الصناعية، هندسة شبكة الموقع،Controls الهوية/الوصول، والمراقبة، النظافة السيبرانية، وأنشطة الجاهزية السيبرانية.
- تحديد ثغرات النطاق، ثغرات المساءلة، العوائق التقنية، وثغرات التوثيق التي قد تؤثر على الامتثال التنظيمي، جاهزية البدء، أو التسليم.
- الشراكة مع فرق الهندسة في الموقع، ومراقبة العمليات، وإدارة المشروع لدمج أنشطة الأمن السيبراني في خطط عمل الموقع وتتابعات التكليف.
- دعم جاهزية التسليم من خلال ضمان وضوح التوثيق، الأدلة، الافتراضات التشغيلية، ومسؤوليات الدعم.
الامتثال التنظيمي والمشاركة مع أصحاب المصلحة
- دعم تنفيذ أنشطة الأمن السيبراني بما يتوافق مع المتطلبات التنظيمية المعمول بها في المملكة العربية السعودية، بما في ذلك NCA ECC، NCA OTCC، متطلبات تصاريح التشغيل HCIS/SAIS، والالتزامات CNI/الأنظمة الحساسة.
- قيادة جمع وتنظيم ومراجعة جودة وجاهزية مستندات إثبات الامتثال المطلوبة لامتثال HCIS وNCA.
- التنسيق مع NGHC بشأن شهادة CSAT، مراجعة الأدلة، ملاحظات التوثيق، وحل التعليقات.
- دعم NGHC في إعداد حزم أدلة الأمن السيبراني والردود للجهات التنظيمية.
- التأكد من أن وثائق الامتثال مكتملة وقابلة للتتبع وم controlled ومنظمة للمراجعة التنظيمية والموافقة من المعنيين.
- التواصل المنتظم مع فريق OT/ICS Cybersecurity، بما في ذلك التوافق مع الموارد السيبرانية في الموقع على PDO.
- عقد اجتماعات تنسيق روتينية مع OT/ICS Cybersecurity، DT، NGHC، وأصحاب المصلحة في المشروع لمواءمة أنشطة التنفيذ الرقمي، المخاطر، المعوقات، والقرارات.
- التواصل الفعال لحالة الأمن السيبراني، المخاطر، القضايا، الاعتماديات، وعناصر التصعيد للإدارة العليا وقيادة المشروع.
- ترجمة مواضيع الأمن السيبراني والتوافق إلى تحديثات واضحة وعملية لمديري المشروع، قيادة DT، NGHC، PDO، والشركاء الخارجيين.
- دعم اجتماعات الحوكمة، ومراجعات الرقابة السيبرانية التنفيذية، ومناقشات جاهزية الامتثال.
المؤهلات والخبرة المطلوبة
- فهم قوي للوائح الأمن السيبراني ومتطلباتها في السعودية، بما في ذلك NCA ومتطلبات HCIS.
- فهم الالتزامات التعاقدية في الأمن السيبراني بين Air Products/APEPC وNGHC.
- 5-10 سنوات من الخبرة في قيادة أنشطة الأمن السيبراني OT/ICS في بيئات صناعية، طاقوية، كيميائية، مرافق حيوية، أو مشاريع بنية تحتية كبيرة.
- خبرة في اختبار قبول مواقع الأمن السيبراني، توثيق إثبات الامتثال، جمع الأدلة التنظيمية، إغلاق تقييم مخاطر السيبران، والجاهزية للتدقيق.
المهارات والسمات
- القدرة على إدارة أولويات متعددة متزامنة عبر تنفيذ المشروع، تنسيق أصحاب المصلحة، الامتثال التنظيمي، إدارة الموردين، وجاهزية الموقع.
- مهارات كتابة وتواصل قوية بالإنجليزية؛ وجود مهارة العربية ميزة إضافية.
- القدرة على التواصل بفعالية مع الإدارة العليا مع فهم وتوجيه أنشطة العمل اليومية التفصيلية في الموقع.
- مهارات قوية في إدارة أصحاب المصلحة عبر المشروع، الهندسة، الأمن السيبراني، العمليات، البائعين، والمنظمات الخارجية/العملاء.
- الاطلاع على مبادئ أمان OT/ICS، بما في ذلك التقسيم، مناطق DMZ الصناعية، الوصول الآمن عن بُعد، التحكم في الوصول، التقوية، المراقبة، وجاهزية الحوادث.
- القدرة على العمل في بيئة معقدة متعددة الأطراف تشمل Air Products، NGHC، PDO، DT، مقاولين EPC، بائعين، وأصحاب مصلحة تنظيميين.
About Air Products
Air Products, founded in 1940, is a world-leading industrial gases company recognized for its history of innovation, operational excellence, and unwavering commitment to safety and environmental stewardship. The company focuses on creating solutions that support various industries, from space exploration to healthcare and large-scale production facilities, by leveraging the collective experience and motivation of its people.
The Opportunity: NGHP IT/DT Cybersecurity Lead
Air Products is seeking an NGHP IT/DT Cybersecurity Lead to join its team in Duba, Tabuk, Saudi Arabia. This full-time role requires 5-10 years of experience and involves leading cybersecurity activities for a significant project, ensuring compliance and operational readiness.
Key Responsibilities
- Lead and coordinate site cybersecurity activities, including site acceptance testing, cyber hygiene, readiness reviews, and implementation gap closure.
- Serve as the site-based cybersecurity point of coordination among DT, OT/ICS Cybersecurity, project management, process controls, vendors, subcontractors, and NGHC stakeholders.
- Provide day-to-day direction to cybersecurity engineers, external partners, and site-based cyber resources.
- Ensure cyber activities align with project schedules, commissioning priorities, start-up needs, and compliance milestones.
- Manage and supervise external partners engaged in designing, implementing, documenting, testing, or supporting cybersecurity solutions.
- Oversee on-site work performed by external cybersecurity implementation partners to ensure deliverables meet Air Products, NGHC, NCA, HCIS, and project requirements.
- Coordinate third-party support between CSAT, commissioning, start-up, and handover to NGHC.
- Track, review, document, and escalate vendor/subcontractor cybersecurity deliverables when gaps or delays affect compliance or project readiness.
- Serve as the interface between DT infrastructure activities and cybersecurity-related activities at the site.
- Support alignment across OT systems, industrial DMZs, site network architecture, identity/access controls, monitoring, cyber hygiene, and cyber readiness activities.
- Identify scope gaps, accountability gaps, technical blockers, and documentation gaps that could affect regulatory compliance, start-up readiness, or handover.
- Partner with site engineering, process controls, and project management teams to integrate cybersecurity activities into site work plans and commissioning sequences.
- Support handover readiness by ensuring documentation, evidence, operating assumptions, and support responsibilities are clearly defined.
Regulatory Compliance and Stakeholder Engagement
- Support execution of cybersecurity activities aligned with applicable KSA regulatory requirements, including NCA ECC, NCA OTCC, HCIS/SAIS operating permit requirements, and CNI/critical systems obligations.
- Lead collection, organization, quality review, and readiness of Proof of Compliance documentation required for HCIS and NCA compliance activities.
- Coordinate with NGHC on CSAT witnessing, evidence review, documentation feedback, and comment resolution.
- Support NGHC in preparing cybersecurity evidence packages and responses for regulatory submission.
- Ensure compliance documentation is complete, traceable, controlled, and organized for audit, regulatory review, and stakeholder approval.
- Interface regularly with the OT/ICS Cybersecurity team, including alignment with PDO on-site cyber resources.
- Conduct routine coordination meetings with OT/ICS Cybersecurity, DT, NGHC, and project stakeholders to align cyber execution activities, risks, blockers, and decisions.
- Communicate cybersecurity status, risks, issues, dependencies, and escalation items effectively to senior management and project leadership.
- Translate technical cybersecurity and compliance topics into clear, actionable updates for project executives, DT leadership, NGHC, PDO, and external partners.
- Support governance meetings, executive cyber oversight reviews, and compliance readiness discussions.
Required Qualifications and Experience
- Strong understanding of KSA cybersecurity regulations and regulatory expectations, including NCA and HCIS requirements.
- Understanding of contractual cybersecurity obligations between Air Products/APEPC and NGHC.
- 5-10 years of experience leading OT/ICS cybersecurity activities in industrial, energy, chemical, utility, critical infrastructure, or large capital project environments.
- Experience with cybersecurity site acceptance testing, proof-of-compliance documentation, regulatory evidence collection, cyber risk assessment closure, and audit readiness.
Skills and Attributes
- Ability to manage multiple concurrent priorities across project execution, stakeholder coordination, regulatory compliance, vendor management, and site readiness.
- Strong written and verbal communication skills in English; Arabic language capability is a plus.
- Ability to communicate effectively with senior management while also understanding and directing detailed day-to-day work activities at the site.
- Strong stakeholder management skills across project, engineering, cybersecurity, operations, vendors, and external/customer organizations.
- Familiarity with OT/ICS security principles, including segmentation, industrial DMZs, secure remote access, access control, hardening, monitoring, and incident readiness.
- Ability to operate in a complex, multi-party environment involving Air Products, NGHC, PDO, DT, EPC contractors, vendors, and regulatory stakeholders.