Job description
Role Overview
ICS Cybersecurity Engineer at Air Products, based at project site in Duba, Tabuk Region, Saudi Arabia, working on rotation of 8 weeks ON / 2 weeks OFF.
Company Overview
Air Products is a world-leading industrial gases company founded in 1940, with a proud history of innovation, operational excellence, and an unwavering commitment to safety and environmental stewardship. The NEOM Green Hydrogen Project is a flagship project at scale for Air Products, executing an EPC Contract with NEOM Green Hydrogen Company (NGHC). Air Products has responsibility to design, build and deliver Process Controls / Process Automation System and IT/Digital Technology infrastructure scope, including compliance with local laws and regulations on cybersecurity.
Role Purpose
The ICS Cybersecurity Engineer plays a key member of a Cybersecurity task force team to undertake field verification of cyber assets to comply with project specifications and site acceptance criteria. The role supports large-scale construction, pre-commissioning, commissioning, startup and handover phases, ensuring cybersecurity controls are implemented without impacting schedule critical activities. The Engineer acts as the technical interface between Air Products project execution, commissioning teams and vendors during field verification of cyber assets, and coordinates with Engineering, Pre-Commissioning, Commissioning and Client operations teams related to Cyber Security field verifications.
Key Responsibilities
Field Verification & Asset Management
- Perform field verification of the design, implementation and testing of cyber assets to meet cybersecurity standards, regulatory requirements, technologies, processes, procedures and specifications.
- Develop, document, and maintain cybersecurity asset register and other key deliverables as guided by the Site Cybersecurity Lead or Cybersecurity Manager.
- Ensure transition of project assets to commissioning, start-up and final handover to the client.
Risk & Security Assessment
- Organize and lead or facilitate the resolution and implementation of cybersecurity risk assessment exercises.
- Implement risk assessment recommendations for Air Products design and for vendor/skid package control systems.
- Support pre-commissioning and commissioning teams by validating firewall rules, secure remote access, endpoint hardening, asset inventory validation, access control execution, and logging before system energization.
Standards & Testing Procedures
- Lead and oversee architecture, standards and FAT/SAT/CSAT procedures development, execution and performance testing.
- Ensure verification and approval of 3rd party device access needs as requested by subcontractors and vendors as part of commissioning and start-up requirements on vendor packages.
Cross-Functional Coordination
- Participate in technical coordination meetings with cross-functional teams as guided by the Site Cybersecurity lead.
- Coordinate with vendors and Air Products engineering team to resolve and liquidate punch points identified during field verification of cyber assets.
- Coordinate and assist the Site Cybersecurity Lead with change management activities to ensure design, procurement, installation, commissioning, and startup of cybersecurity scope are reviewed for schedule and budget compliance.
Reporting & Risk Management
- Prepare weekly updates and dashboard to the Site Cybersecurity lead and the Project Cybersecurity Collaboration Lead.
- Identify and escalate risks and opportunities.
- Collect and report lessons learned during vendor site visits and project execution.
Operations Handover & Support
- Support OT cybersecurity handovers to operations, including procedures, asset inventories, access management, and incident response alignment.
- Contribute to OT Cybersecurity Operations Model, including monitoring, patching, backup, disaster recovery, and secure remote support.
Qualifications & Experience
- Bachelor's degree in engineering (Electronics & Communication, Instrumentation or Process Automation background preferred) or equivalent.
- Minimum 10 to 15 years' experience in Operational Technology (OT) or related field.
- At least 3 years focused on designing, building, or validating the design/implementation of cybersecurity for industrial control systems and networks.
- Project implementation experience of Saudi cyber standards HCIS, NCA, CRA compliance, ISA 62443 Industry standards, specifications, regulations, and best practices.
Skills & Competencies
- Strong knowledge and understanding of control systems (SCADA/DCS/PLCs, etc.).
- Knowledge of relevant protocols (Modbus, PROFINET, DNP3, IEC61850, etc.).
- Knowledge of key technologies including Firewalls, IDS, Anti-Virus, and Vulnerabilities assessments in ICS/OT networks.
- OT/ICS cybersecurity relevant accreditations such as ISA/IEC62443, SANS or other internationally recognized certifications are preferred.
- Additional cybersecurity certifications such as CISSP, CISM, ISO 27001, etc., will be an added advantage.
- Advanced skills in Microsoft Office tools such as Teams, SharePoint, Word, Excel, PowerPoint and Visio.
- Excellent written and verbal communication skills with ability to communicate appropriately at all levels of the organization.