Overview
Air Products reimagines what’s possible by leveraging our people, experience, and collaboration to drive innovations. This role provides DT Cybersecurity Leadership and Site Execution, coordinating cybersecurity activities at the site, ensuring readiness, compliance, and effective collaboration among stakeholders.
Responsibilities
- Lead and coordinate cybersecurity activities at the site, including cyber site acceptance testing, cyber hygiene activities, cyber readiness reviews, collection of proof-of-compliance documentation, and closure of cybersecurity implementation gaps.
- Serve as the site-based cybersecurity point of coordination between DT, OT/ICS Cybersecurity, project management, vendors, subcontractors, and NGHC stakeholders.
- Provide day-to-day direction to cybersecurity engineers, external partners, and site-based cyber resources supporting implementation, testing, documentation, and evidence collection.
- Ensure cyber activities align with the project schedule, commissioning priorities, start-up needs, and compliance milestones.
- Coordinate with the DT Project Manager and OT/ICS Cybersecurity team to maintain a consolidated schedule of cybersecurity deliverables, dependencies, risks, and milestones.
Regulatory and Compliance Readiness
- Support execution of cybersecurity activities aligned to applicable regulatory requirements (KSA), including NCA ECC, NCA OTCC, HCIS/SAIS operating permit requirements, and applicable CNI/critical systems obligations.
- Lead collection, organization, quality review, and readiness of Proof of Compliance documentation to support HCIS and NCA compliance activities.
- Coordinate with NGHC on CSAT witnessing, evidence review, documentation feedback, and comment resolution.
- Support NGHC in preparing cybersecurity evidence packages and responses for regulatory submission, recognizing that NGHC submits documentation to HCIS and NCA while Air Products/APEPC supports project delivery and evidence readiness.
- Ensure compliance documentation is complete, traceable, controlled, and organized for audit, regulatory review, and stakeholder approval.
Stakeholder Interface and Governance
- Interface with the OT/ICS Cybersecurity team and align with PDO on-site cyber resources performing CSAT, cyber hygiene, and vendor-related compliance activities.
- Conduct routine coordination meetings with OT/ICS Cybersecurity, DT, NGHC, and project stakeholders to align cyber execution activities, risks, blockers, and decisions.
- Communicate cybersecurity status, risks, issues, dependencies, and escalation items to senior management and project leadership.
- Translate technical cybersecurity and compliance topics into clear, actionable updates for project executives, DT leadership, NGHC, PDO, and external partners.
- Support governance meetings, executive cyber oversight reviews, and compliance readiness discussions.
Third-Party and Vendor Oversight
- Manage and supervise external partners engaged to design, purchase, implement, document, test, or support cybersecurity solutions for the GHE scope.
- Oversee on-site work by external cybersecurity implementation partners and ensure deliverables meet Air Products, NGHC, NCA, HCIS, and project requirements.
- Coordinate third-party support between CSAT, commissioning, start-up, and handover to NGHC.
- Track, review, document, and escalate vendor/subcontractor cybersecurity deliverables when gaps or delays affect compliance or project readiness.
- Support review of vendor documentation, cyber execution plans, network/security architecture, hardening evidence, access control matrices, SIEM/monitoring documentation, and POC packages.
DT, OT, and Project Integration
- Serve as the interface between DT infrastructure activities and site cybersecurity activities.
- Support alignment across OT systems, industrial DMZs, site network architecture, identity/access controls, monitoring, cyber hygiene, and cyber readiness activities.
- Identify scope gaps, accountability gaps, technical blockers, and documentation gaps that could affect regulatory compliance, start-up readiness, or handover.
- Partner with site engineering, process controls, and project management to integrate cybersecurity activities into site work plans and commissioning sequences.
- Support handover readiness by ensuring documentation, evidence, operating assumptions, and support responsibilities are clearly defined.
Required Qualifications and Experience
- Strong understanding of KSA cybersecurity regulations and regulatory expectations, including NCA and HCIS requirements.
- Understanding of contractual cybersecurity obligations between Air Products/APEPC and NGHC.
- Experience leading OT/ICS cybersecurity activities in industrial, energy, chemical, utility, critical infrastructure, or large capital project environments.
- Experience with cybersecurity site acceptance testing, proof-of-compliance documentation, regulatory evidence collection, cyber risk assessment closure, and audit readiness.
- Ability to manage multiple concurrent priorities across project execution, stakeholder coordination, regulatory compliance, vendor management, and site readiness.
- Strong written and verbal communication skills in English; Arabic language capability a plus.
- Ability to communicate effectively with senior management while directing detailed day-to-day site work activities.
- Strong stakeholder management skills across project, engineering, cybersecurity, operations, vendors, and external/customer organizations.
- Familiarity with OT/ICS security principles, including segmentation, industrial DMZs, secure remote access, access control, hardening, monitoring, and incident readiness.
- Ability to operate in a complex, multi-party environment involving Air Products, NGHC, PDO, DT, EPC contractors, vendors, and regulatory stakeholders.