Maintain compliance with ACWA policies local regulatory requirements.
Assist the project teams during design review of IT/OT architecture to make sure that plant design is as per ACWA Power Cybersecurity guidelines (OTS exhibits normally) + plant is designed as per the local legal cybersecurity directives.
Ensure the implementation of cybersecurity policies, procedures, standards.
Implement ACWA Power IT/OT SOP (Standard Operating Procedures) framework across critical systems in the respective cluster.
Develop maintain asset log / register fall cybersecurity components (equipment’s) to perform vulnerability assessment implement risk mitigation actions.
Develop disaster recovery plans execute routine disaster recovery drills.
Develop implement routine backup (online offline) management fIT OT systems.
Develop obsolescence / life cycle management plan fIT OT devices with regard to cybersecurity focusing spares availability, patch deployment, etc.
Lead the IT/OT internal audit fthe region take ownership in closure of all open action items.
Contribute to Conduct risk assessments follow up on the status of risks actions taken in coordination with stakeholders.
Implementing the cybersecurity awareness training program measuring the extent of employees’ commitment to cybersecurity awareness.
Follow up on cyber security monitoring systems to ensure their stability availability submit reports to describe their status.
Ensuring the integration of all critical systems with the corporate (SIEM)
Collect cybersecurity events in the information technology assets of the Cybersecurity Event Logs Management Monitoring (SIEM) system, analyze the logs, identify cybersecurity risks.
Handling cyber security incidents following up on their closure, escalation of existing events that exceed a defined service level agreement.
Continuous evaluation of vulnerabilities follow-up application of security packages settings.
Arrange Contribute to the periodic penetration tests on all internal externally provided services their technical components to assess the level of cybersecurity.
Managing Logical Access to Information Technology Assets by defining cybersecurity requirements fmanaging access identities permissions, documenting implementing them.
install the required endpoint protection such as anti-virus, firewalls, etc. based on the gaps identified in the analysis conducted by ACWA.
Ensure that endpoint security solution is implemented across the systems (IT OT) in the plant identify inconsistencies.
Maintain up-to-date signatures on the endpoint security agents (IT OT).
Conduct periodic scanning checksum to ensure the security status (i.e. YARA rules, queries).
Conduct periodic simulated phasing attacks.
Evaluate the network security controls, protocols, topologies, device configurations.
Analyze log files related to network traffic, firewalls, IDS, IPS, DNS. Identify any suspicious activity its effect on the plant data systems.
Implement test the firewalls, IDS, IPS systems.
Conduct periodic network security audits.
Participate in incident response business continuity management.
Manage VPN profiles access.
Identify the list of network devices managed the Cybersecurity Operations function maintain an updated asset inventory defining the criticality ownership.
Maintain a baseline configuration fthe network security assets such as internal/external firewalls, IPS/IDS, NAC systems, anti-DDOS, VPN test firewall IDS/IPS logs against forensics requirements.
Establish guidelines fencrypting email communications digitally signing emails integrate with DLP solution once deployed.
Schedule periodic configuration reviews to ensure network device configurations follow best practices.
Document a process fnetwork devices to align with approved security configurations.
Contribute to the annual budget fcybersecurity as well as the annual budget of the project company the plant in the respective site.
Manage monitthe financial performance against the approved budget.
Follow up with EPC the project company during the construction phase to ensure the implementation of cybersecurity requirements in the OTS O&M agreement.
Lead the internal external cybersecurity audits implement the resolution of observations.
Contribute to the annual audit of the ISO 27001 ISMS certification.
Deploy all the requirements of ISO certifications including information security digital business continuity management.
Ensure data gathering from all critical IT/OT systems to ACWA Power data lake in coordination with digital operations, cybersecurity, I&C teams.
Minimum Qualifications:
• Bachelor’s Degree in IT Engineering Computer Science
Minimum Experience:
• 5+ years total experience in the IT / Cybersecurity operation
More