وصف الوظيفة
Role Overview
NGHP IT/DT Cybersecurity Engineer at Air Products, supporting cybersecurity implementation and compliance activities on a major industrial project.
Company Overview
Air Products is a world-leading industrial gases company founded in 1940, with a proud history of innovation, operational excellence, and an unwavering commitment to safety and environmental stewardship.
Role Purpose
Provide technical cybersecurity execution support across GHE site systems, OT/ICS environments, and digital transformation infrastructure, ensuring proof of compliance, regulatory readiness, and alignment with approved cybersecurity design and project requirements.
Key Responsibilities
Technical Cybersecurity Execution
- Support implementation, validation, and documentation of cybersecurity controls across GHE site systems, OT/ICS environments, industrial networks, cybersecurity tools, and supporting DT infrastructure.
- Support cyber site acceptance testing activities, including preparation, execution support, evidence capture, defect logging, issue tracking, and closeout documentation.
- Assist with proof-of-compliance documentation collection, validation, indexing, and quality review.
- Review and support cybersecurity evidence related to network diagrams, system architecture, firewall rules, hardening standards, access control matrices, asset inventories, SIEM/monitoring configurations, and vendor compliance deliverables.
- Support cyber hygiene activities with third-party vendors, subcontractors, and site teams.
- Assist in tracking remediation of cybersecurity gaps, Cyber SAT findings, Cyber Risk Assessment recommendations, POC evidence gaps, and vendor documentation deficiencies.
OT/ICS and Site Technical Support
- Support OT/ICS cybersecurity activities including system hardening, firewall configuration review, password management standards, secure remote access controls, endpoint/security tooling validation, DMZ implementation support, and network segmentation verification.
- Participate in walkthroughs, field verification, technical reviews, and cybersecurity control validation activities.
- Support evaluation of vendor and subcontractor deliverables for compliance with project cybersecurity requirements, Air Products standards, NCA/HCIS expectations, and approved architecture.
- Work with process controls, DT infrastructure, plant computing, and vendor teams to resolve cybersecurity issues impacting commissioning, start-up, or handover readiness.
- Support documentation of technical decisions, implementation status, deviations, risk acceptance items, compensating controls, and open action items.
Compliance Documentation and Evidence Management
- Collect, organize, and maintain technical cybersecurity evidence needed for proof of compliance and regulatory readiness.
- Support preparation of CSAT and POC documentation packages for review by the Cyber Lead, OT Cybersecurity, DT, NGHC, and external assessors.
- Ensure documentation is complete, technically accurate, consistent, and traceable to applicable requirements.
- Support responses to NGHC comments, third-party assessor findings, and follow-up requests related to cybersecurity evidence.
- Maintain accurate trackers for cyber issues, documentation gaps, evidence status, and remediation actions.
Vendor and Third-Party Coordination
- Coordinate with cybersecurity vendors, EPC subcontractors, OEMs, and external implementation partners during onsite execution, testing, and documentation activities.
- Support external partners responsible for cybersecurity solution implementation, testing, documentation, and transition support.
- Review vendor-submitted evidence and escalate incomplete, inconsistent, or non-compliant documentation to the Cyber Lead.
- Support site supervision of third-party activities when required, including validation that field work aligns with approved cyber design and project requirements.
Coordination and Reporting
- Provide status updates to the Cyber Lead on technical progress, blockers, risks, documentation gaps, and open actions.
- Participate in weekly coordination meetings with OT Cybersecurity, DT, site project management, and other cyber stakeholders.
- Support preparation of concise technical updates for project reporting, cyber oversight meetings, and senior management summaries.
- Coordinate with DT infrastructure teams and site teams to ensure cybersecurity activities are integrated with broader implementation and commissioning work.
Qualifications & Experience
- Strong understanding of OT/ICS cybersecurity principles, industrial networks, plant systems, industrial DMZs, secure remote access, system hardening, access control, monitoring, and cyber hygiene.
- Working knowledge of KSA cybersecurity requirements related to NCA and HCIS, or ability to rapidly apply these requirements in an industrial project environment.
- Experience supporting cybersecurity testing, audit readiness, proof-of-compliance documentation, or regulatory evidence collection.
- Experience reviewing technical cybersecurity documentation such as network diagrams, firewall rules, system architecture, control matrices, asset inventories, hardening checklists, and monitoring configurations.
Skills & Competencies
- Ability to manage multiple technical tasks and documentation workstreams simultaneously.
- Strong written and verbal communication skills in English; Arabic language skills preferred.
- Ability to work effectively with site teams, engineering teams, vendors, subcontractors, DT resources, and senior cybersecurity stakeholders.
- Ability to operate in a fast-paced project environment with changing priorities, regulatory expectations, and commissioning dependencies.
Additional Information
Preferred Qualifications
- Experience with NCA ECC, OTCC, HCIS/SAIS, IEC 62443, ISO 27001, NIST, CIS Controls, or similar cybersecurity control frameworks.
- Experience in energy, industrial gas, chemical, utility, power generation, renewable energy, or critical infrastructure projects.
- Experience with SIEM, OT monitoring, firewall rule review, PAM, vulnerability management, asset inventory, endpoint security, secure remote access, and industrial network segmentation.
- Certifications such as GICSP, IEC 62443, Security+, CISSP Associate, CISM, CEH, or equivalent.
- Prior Saudi Arabia, GCC, NEOM, or critical infrastructure project experience.