Role summary
Assist in design review for new projects, installation, operation, and support IT/OT security systems and controls to ensure they operate properly and remain secure from outside intrusion. Enhance capabilities and lifecycle/obsolescence management of IT/OT assets from cybersecurity perspective.
Responsibilities
- Maintain compliance with ACWA policies and local regulatory requirements
- Assist project teams during design review of IT/OT architecture
- Ensure implementation of cybersecurity policies, procedures, and standards
- Implement ACWA Power IT/OT Standard Operating Procedures framework across critical systems
- Develop and maintain asset log/register for all cybersecurity components
- Develop disaster recovery plans and execute routine disaster recovery drills
- Develop and implement routine backup management for IT and OT systems
- Develop obsolescence/lifecycle management plan for IT and OT devices
- Lead IT/OT internal audit for the region and own closure of all open action items
- Contribute to risk assessments and follow up on risk status
- Implement cybersecurity awareness and training program
- Follow up on cybersecurity monitoring systems to ensure stability and availability
- Ensure integration of all critical systems with corporate SIEM
- Collect and analyze cybersecurity events from IT and technology assets
- Handle cybersecurity incidents and follow up on closure and escalation
- Continuous evaluation of vulnerabilities and security update implementation
- Arrange and contribute to periodic penetration tests on all services
- Manage logical access to IT and technology assets by defining cybersecurity requirements
- Create and install required endpoint protection such as antivirus and firewalls
- Ensure endpoint security solution is implemented across IT and OT systems
- Maintain up-to-date signatures on endpoint security agents
- Conduct periodic scanning and checksum to ensure security status
- Conduct periodic simulated phishing attacks
- Evaluate network security controls, protocols, topologies, and device configurations
- Analyze log files related to network traffic, firewalls, IDS, IPS, and DNS
- Identify suspicious activity and its effect on plant data and systems
- Implement and test firewalls, IDS, and IPS systems
- Conduct periodic network security audits
- Participate in incident response and business continuity management
- Manage VPN profiles and access
- Identify list of network devices managed by cybersecurity operations function
- Maintain updated asset inventory defining criticality and ownership
- Maintain baseline configuration for network security assets including firewalls, IPS/IDS, NAC systems, anti-DDOS, and VPN
- Test firewall and IDS/IPS logs against forensics requirements
- Establish guidelines for encrypting email communications and digital signing
- Schedule periodic configuration reviews to ensure best practices
- Document process for network devices to align with approved security configurations
- Contribute to annual cybersecurity budget and project company/plant budget
- Manage and monitor financial performance against approved budget
- Follow up with EPC and project company during construction phase
- Lead internal and external cybersecurity audits and implement observation resolutions
- Contribute to annual ISO 27001 ISMS certification audit
- Deploy all requirements of ISO certifications including information security and digital business continuity management
- Ensure data gathering from all critical IT/OT systems to ACWA Power data lake
Qualifications
- Bachelor's Degree in IT Engineering or Computer Science
Education
Bachelor's Degree in IT Engineering or Computer Science
Experience
5+ years total experience in IT/Cybersecurity operation
Skills
- Strong understanding of multiple IT technologies and processes
- Direct skills of cybersecurity operations
Education · Experience · Type
Bachelor'sRequires 5+ yearsSalary not stated