Technical Cybersecurity Execution
- Support implementation, validation, and documentation of cybersecurity controls across GHE site systems, OT/ICS environments, industrial networks, cybersecurity tools, and supporting DT infrastructure.
- Support cyber site acceptance testing activities, including preparation, execution support, evidence capture, defect logging, issue tracking, and closeout documentation.
- Assist with proof‑of‑compliance documentation collection, validation, indexing, and quality review.
- Review and support cybersecurity evidence related to network diagrams, system architecture, firewall rules, hardening standards, access control matrices, asset inventories, SIEM/monitoring configurations, and vendor compliance deliverables.
- Support cyber hygiene activities with third‑party vendors, subcontractors, and site teams.
- Assist in tracking remediation of cybersecurity gaps, Cyber SAT findings, Cyber Risk Assessment recommendations, POC evidence gaps, and vendor documentation deficiencies.
OT/ICS and Site Technical Support
- Support OT/ICS cybersecurity activities including system hardening, firewall configuration review, password management standards, secure remote access controls, endpoint/security tooling validation, DMZ implementation support, and network segmentation verification.
- Participate in walkthroughs, field verification, technical reviews, and cybersecurity control validation activities.
- Support evaluation of vendor and subcontractor deliverables for compliance with project cybersecurity requirements, Air Products standards, NCA/HCIS expectations, and approved architecture.
- Work with process controls, DT infrastructure, plant computing, and vendor teams to resolve cybersecurity issues impacting commissioning, start‑up, or handover readiness.
- Support documentation of technical decisions, implementation status, deviations, risk acceptance items, compensating controls, and open action items.
Compliance Documentation and Evidence Management
- Collect, organize, and maintain technical cybersecurity evidence needed for proof of compliance and regulatory readiness.
- Support preparation of CSAT and POC documentation packages for review by the Cyber Lead, OT Cybersecurity, DT, NGHC, and external assessors.
- Ensure documentation is complete, technically accurate, consistent, and traceable to applicable requirements.
- Support responses to NGHC comments, third‑party assessor findings, and follow‑up requests related to cybersecurity evidence.
- Maintain accurate trackers for cyber issues, documentation gaps, evidence status, and remediation actions.
Vendor and Third‑Party Support
- Coordinate with cybersecurity vendors, EPC subcontractors, OEMs, and external implementation partners during onsite execution, testing, and documentation activities.
- Support external partners responsible for cybersecurity solution implementation, testing, documentation, and transition support.
- Review vendor‑submitted evidence and elevate incomplete, inconsistent, or non‑compliant documentation to the Cyber Lead.
- Support site supervision of third‑party activities when required, including validation that field work aligns with approved cyber design and project requirements.
Coordination and Reporting
- Provide status updates to the Cyber Lead on technical progress, blockers, risks, documentation gaps, and open actions.
- Participate in weekly coordination meetings with OT Cybersecurity, DT, site project management, and other cyber stakeholders.
- Support preparation of concise technical updates for project reporting, cyber oversight meetings, and senior management summaries.
- Coordinate with DT infrastructure teams and site teams to ensure cybersecurity activities are integrated with broader implementation and commissioning work.
Required Qualifications And Experience
- Strong understanding of OT/ICS cybersecurity principles, industrial networks, plant systems, industrial DMZs, secure remote access, system hardening, access control, monitoring, and cyber hygiene.
- Working knowledge of KSA cybersecurity requirements related to NCA and HCIS, or ability to rapidly apply these requirements in an industrial project environment.
- Experience supporting cybersecurity testing, audit readiness, proof‑of‑compliance documentation, or regulatory evidence collection.
- Experience reviewing technical cybersecurity documentation such as network diagrams, firewall rules, system architecture, control matrices, asset inventories, hardening checklists, and monitoring configurations.
- Ability to manage multiple technical tasks and documentation workstreams at the same time.
- Strong written and verbal communication skills in English; Arabic language skills preferred.
- Ability to work effectively with site teams, engineering teams, vendors, subcontractors, DT resources, and senior cybersecurity stakeholders.
- Ability to operate in a fast‑paced project environment with changing priorities, regulatory expectations, and commissioning dependencies.
Preferred Qualifications
- Experience with NCA ECC, OTCC, HCIS/SAIS, IEC 62443, ISO 27001, NIST, CIS Controls, or similar cybersecurity control frameworks.
- Experience in energy, industrial gas, chemical, utility, power generation, renewable energy, or critical infrastructure projects.
- Experience with SIEM, OT monitoring, firewall rule review, PAM, vulnerability management, asset inventory, endpoint security, secure remote access, and industrial network segmentation.
- Certifications such as GICSP, IEC 62443, Security+, CISSP Associate, CISM, CEH, or equivalent are preferred.
- Prior Saudi Arabia, GCC, NEOM, or critical infrastructure project experience is preferred.
Success Measures
- CSAT and POC evidence are collected, validated, organized, and maintained in a usable format.
- Cybersecurity documentation gaps, technical issues, and remediation actions are tracked and closed.
- Vendor and subcontractor cybersecurity deliverables are reviewed for completeness and quality.
- Technical cybersecurity controls are validated against approved design, project requirements, and compliance expectations.
- Cyber Lead, DT Project Manager, PDO Cybersecurity, and NGHC stakeholders receive accurate technical status updates.
- Site cybersecurity activities support commissioning, start‑up readiness, and regulatory compliance objectives.