About the Role
Air Products Qudra is seeking a Senior Cybersecurity Specialist to serve as the primary defense for the organization's critical information and assets. This full-time role, based in Al Jubail, involves safeguarding critical infrastructure by planning, designing, implementing, and maintaining various cybersecurity solutions to protect against potential cyber threats.
Key Responsibilities
The Senior Cybersecurity Specialist will be responsible for implementing cybersecurity technologies and ensuring compliance with mandated standards. Key duties include:
- Implementing cybersecurity technologies to safeguard critical infrastructure.
- Ensuring adherence to cybersecurity requirements from SAIS, the National Cybersecurity Authority, High Commission for Industrial Security, and Saudi Aramco applicable standards SAEP-99 and SAEP-100.
- Focusing on operational technology and cybersecurity defense strategies.
Cybersecurity Team Activities
The cybersecurity team, encompassing GRC and Operations "Engineering," performs a range of activities including, but not limited to:
- Asset Management
- Access Management
- Network Management
- Hardening and Patching Management
- Endpoint Protection
- Backup and Disaster Recovery
- Threat Hunting
- Vulnerability Assessment
- Penetration Testing
- Physical Security
- Cybersecurity Drills and Tabletop Exercises
- SIEM Management
Required Skills and Experience
Candidates should possess 6+ years of experience and demonstrate expertise in the following areas:
- Expertise in working with various Operational Technology/Industrial Control Systems.
- Strong hands-on experience in designing, implementing, and maintaining cybersecurity solutions, including network architectural understanding and improvement.
- Proficiency with cybersecurity tools such as Active Directory, firewalls, SIEMs, VPNs, IDS/IPS, endpoint protection, vulnerability assessment, patch management, backup, and recovery.
- Ability to lead on-site projects related to industrial control systems compliance with applicable regulations.
- Good knowledge of national and international cybersecurity standards, policies, and procedures.
- Expertise in vulnerability assessment, patching management, and system hardening.
- Knowledge of designing systems architecture and network diagrams while meeting cybersecurity regulations.
- Skilled in leading cybersecurity drills, tabletop exercises, incident response, and disaster recovery procedures.
- Strong troubleshooting skills to identify and remediate system errors.
- Proactive healthiness checks for detective, preventive, and remediation countermeasures.
Work Environment
The role involves working cooperatively within a plant operational environment, collaborating with safety, process control engineers, operations, maintenance, and other relevant departments.
عن الوظيفة
تسعى شركة إير برودكتس قدرا (Air Products Qudra) لاستقطاب كبير أخصائيي الأمن السيبراني ليكون خط الدفاع الأساسي عن المعلومات والأصول الحيوية للمنظمة. تتضمن هذه الوظيفة ذات الدوام الكامل، ومقرها الجبيل، حماية البنية التحتية الحيوية من خلال تخطيط وتصميم وتطبيق وصيانة حلول الأمن السيبراني المختلفة للحماية من التهديدات السيبرانية المحتملة.
المسؤوليات الرئيسية
سيكون كبير أخصائيي الأمن السيبراني مسؤولاً عن تطبيق تقنيات الأمن السيبراني وضمان الالتزام بالمعايير الإلزامية. تشمل المهام الرئيسية ما يلي:
- تطبيق تقنيات الأمن السيبراني لحماية البنية التحتية الحيوية.
- ضمان الالتزام بمتطلبات الأمن السيبراني الصادرة عن SAIS، والهيئة الوطنية للأمن السيبراني، والهيئة العليا للأمن الصناعي، ومعايير أرامكو السعودية المطبقة SAEP-99 و SAEP-100.
- التركيز على التقنية التشغيلية واستراتيجيات الدفاع السيبراني.
أنشطة فريق الأمن السيبراني
يقوم فريق الأمن السيبراني، الذي يشمل الحوكمة والمخاطر والامتثال (GRC) والعمليات "الهندسية"، بمجموعة من الأنشطة تشمل على سبيل المثال لا الحصر:
- إدارة الأصول
- إدارة الوصول
- إدارة الشبكات
- إدارة التحصين والتحديثات (Patching)
- حماية الأجهزة الطرفية
- النسخ الاحتياطي والتعافي من الكوارث
- صيد التهديدات
- تقييم الثغرات الأمنية
- اختبار الاختراق
- الأمن الفيزيائي
- تمارين وتدريبات الأمن السيبراني الفرضية (Tabletop Exercises)
- إدارة نظام SIEM
المهارات والخبرات المطلوبة
يجب أن يتمتع المرشحون بخبرة لا تقل عن 6 سنوات وإثبات الخبرة في المجالات التالية:
- خبرة متخصصة في العمل مع مختلف أنظمة التقنية التشغيلية/أنظمة التحكم الصناعي.
- خبرة عملية قوية في تصميم وتطبيق وصيانة حلول الأمن السيبراني، بما في ذلك فهم وتحسين بنية الشبكات.
- إجادة التعامل مع أدوات الأمن السيبراني مثل Active Directory، والجدران النارية، وأنظمة SIEM، وشبكات VPN، وأنظمة IDS/IPS، وحماية الأجهزة الطرفية، وتقييم الثغرات، وإدارة التحديثات، والنسخ الاحتياطي، والتعافي.
- القدرة على قيادة المشاريع الميدانية المتعلقة بامتثال أنظمة التحكم الصناعي للوائح المطبقة.
- معرفة جيدة بمعايير وسياسات وإجراءات الأمن السيبراني الوطنية والدولية.
- خبرة عالية في تقييم الثغرات، وإدارة التحديثات، وتحصين الأنظمة.
- معرفة بتصميم هندسة الأنظمة ومخططات الشبكات مع الالتزام بلوائح الأمن السيبراني.
- مهارة في قيادة تدريبات الأمن السيبراني، والتمارين الفرضية، والاستجابة للحوادث، وإجراءات التعافي من الكوارث.
- مهارات قوية في استكشاف الأخطاء وإصلاحها لتحديد أخطاء النظام ومعالجتها.
- فحوصات استباقية للسلامة والجاهزية للتدابير الكشفية والوقائية والعلاجية.
بيئة العمل
تتطلب الوظيفة العمل بشكل تعاوني داخل البيئة التشغيلية للمصنع، والتعاون مع مهندسي السلامة والتحكم في العمليات، والعمليات، والصيانة، والإدارات ذات الصلة الأخرى.