وصف الوظيفة
يضبط مدير مشروع الأمن السيبراني واجهة تقديم يومية بين RTA والمتعهد والجهات الداخلية في KM، مع ضمان أن الحوكمة والمعالم والتسليمات وأدلة القبول تفي بالمتطلبات التعاقدية وRFP. تكون مسؤوليته عن التخطيط والتنسيق لجميع مداخل التشغيل المطلوبة للتنفيذ في بيئة سكة حديد حية، بما في ذلك السيطرة على تغييرات KM. عادةً ما يتم التنفيذ ضمن فترات وصول هندسي مقيدة، ويتطلب اختبارات استعدادية ومهارات اتصال وخطط طوارئ وقدرة على التراجع بشكل منضبط.
المسؤوليات الأساسية
استراتيجي
- قيادة التسليم من البداية للنهاية للمبادرات السيبرانية الممولة من RTA، مع ضمان أن الحوكمة والمواعيد والتسليمات تتوافق مع RFP والعقد ومعايير القبول المتفق عليها.
- الحفاظ على نهج آمن بالتصميم عبر مراحل دورة حياة المشروع، مع بناء متطلبات الأمن السيبراني مبكرًا وإثباتها من خلال الاختبارات والتوثيق.
- ضمان توافق الحلول مع المعايير المحلية والدولية المعمول بها للأمن السيبراني وتوقعات صناعة السكك الحديدية للبيئات الحرجة من حيث السلامة، بما في ذلك DESC ISR v3.1، DESC ICS v1.0، ISO/IEC 27001:2022، IEC 62443، وCLC/TS 50701:2023.
- العمل بالشراكة مع حوكمة قسم صيانة السكك الحديدية RTA (RMD)
- التشغيل ضمن حوكمة يرأسها RTA (عادة RTA RMD)، مع توقيع مفاتيح المعالم وقرارات القبول بشكل مشترك من RTA وKeolis-MHI بما يتماشى مع العقد وRFP
المالية
- إدارة التسليم وفق خط الأساس المبلغ والجدول الزمني للمشروعات الكبيرة، بما في ذلك التنبؤات وتحليل الانحرافات والتحكم في التغييرات.
- التحكم في النطاق وتكاليف التأثيرات من خلال إدارة الانحرافات والادعاءات والاعتماديات بشكل منضبط، بالتعاون مع قسم المشروع والابتكار على مؤشرات الأداء الرئيسية والضوابط التجارية وعرض العقوبة.
- مراقبة أداء المقاول مقابل مؤشرات الأداء ووجود الدلائل المرحلية، مع تصعيد الانحرافات من خلال حوكمة قسم المشروع والابتكار.
أصحاب المصلحة / العملاء
- العمل كواجهة المدير اليومي الأساسية لإدارة المشروع لـ RTA والمتعهد، مع ضمان شفافبة الاتصال وتتبع الإجراءات والتصعيد في الوقت المناسب.
- التنسيق القوي مع رئيس الأمن السيبراني وفريق الأمن السيبراني لضمان توافق التسليم مع حوكمة الأمن واحتياجات التشغيل
- مواءمة أصحاب المصلحة الداخليين عبر تكنولوجيا المعلومات وتكنولوجيا العمليات والتشغيل والصيانة والسلامة والجودة والصحة والبيئة والسلامة المهنية لضمان أن يكون التسليم عملياً في بيئة مترو حية.
التشغيلي
- إنشاء والحفاظ على حزمة رقابة المشروع الكاملة، بما في ذلك الجدول المتكامل، سجل RAID (المخاطر والافتراضات والمشكلات والاعتماديات)، سجل القرار، سجل التغييرات، ومتعقب القبول.
- قيادة تخطيط وتنفيذ التسليم للأعمال المنجزة في نوافذ وصول مقيدة، عادة ساعات الهندسة، مع ضمان الترتيب الصحيح والاستعداد وخطة التراجع.
- امتلاك وإدارة جميع الموافقات المطلوبة للتنفيذ في بيئات البنية التحتية الحرجة، بما في ذلك:
- تنسيق RTA CIMP (عملية إدارة تأثير التغيير) للحصول على موافقات RTA للخدمات والواجهات المتأثرة.
- ACCA (تطبيق تعديل تكوين الأصل) البدء، التنسيق، التتبع والإغلاق ضمن سيطرة التغيير في KM.
- PTW (إذن العمل) الإدارة لضمان أن الأعمال في الموقع لا تواصل إلا بعد التفويض الرسمي وبشكل آمن ومراقب.
- ضمان أن المقاول يوفر حزم أعمال مطابقة وكاملة، مثل بيانات المنهج وتقييمات المخاطر procedures الاختبار وأدلة جاهزية الموقع.
- فرض الفصل بين شبكات الأعمال ICT والسكك الحديدية OT والتأكد من أن أنظمة Rail OT تبقى معزولة ومفصولة جواً ما لم تتم الموافقة صراحة من خلال التحكم في التغيير وحوكمة الأمن.
- إدارة ضمان الجودة عبر مراحل التسليم بما في ذلك، على سبيل المثال لا الحصر:
- مراجعات التصميم
- FA T (اختبار قبول المصنع)
- PICO (فحص ما بعد التثبيت)
- SAT (اختبار قبول الموقع)
- SIT (اختبار تكامل النظام)
- UAT (اختبار قبول المستخدم)
- اختبار الأمن، تخطيط الانتقال، والتسليم
- ضمان أن مخرجات التسليم تدعم استدامة التشغيل، بما في ذلك تكامل RTA SOC (مصادر السجل، التنبيهات، حالات الاستخدام)، دفاتر التشغيل، ونماذج الدعم.
القدرات / الأشخاص
- قيادة فرق المصفوفة عبر KM وتوجيه فريق التسليم لدى المقاول من خلال حوكمة منظمة وإدارة التسليم.
- فرض الانضباط في التسليم، جودة الوثائق، والقبول المستند إلى الأدلة عبر جميع خطوط العمل.
- تعزيز ثقافة السلامة والأمن، بما في ذلك الحق والالتزام بإيقاف العمل إذا لم تتحقق شروط السلامة أو الأمن.
الأبعاد
- نموذج تسليم متعدد أصحاب المصلحة: راعٍ من RTA ورئيس مجلس KM للمشروع، والمتعهد كطرف تنفيذ ضمن اتفاق ثلاثي.
- سياق التسليم: بيئة مترو وترام تشغيلية، قيود البنية التحتية الحرجة، فترات وصول مقيدة، والتحكمات الصارمة في التغيير والتفويض بالعمل.
- العمل ليلاً أو في عطلات نهاية الاسبوع حسب الحاجة لإكمال المشروع في الوقت المحدد بما يتوافق مع سياسة الموارد البشرية والقانون الإماراتي.
- بيئة مكتبية. قد يلزم السفر في بعض الأحيان.
المؤهلات الدنيا
الحد الأدنى
المطلوب
المرغوب فيه
التعليم
- درجة البكالوريوس في الهندسة، نظم المعلومات، علوم الحاسوب، الأمن السيبراني، أو تخصص ذي صلة.
- مؤهل دراسات عليا في إدارة المشاريع، الأمن السيبراني، أو هندسة الأنظمة.
الخبرة
Job description
The Project Manager Cybersecurity controls the day-to-day delivery interface between RTA, the contractor, and internal KM stakeholders, ensuring governance, milestones, deliverables, and acceptance evidence meet the contractual requirements and the RFP. The role is accountable for planning and coordinating all operational gating required for implementation within a live rail environment, including KM change control. Delivery is typically executed within restricted engineering access windows, and requires disciplined readiness checks, testing, communications, contingency planning, and rollback capability.
KEY RESPONSIBILITIES
Strategic
- Lead end-to-end delivery of RTA-sponsored cybersecurity initiatives, ensuring project governance, milestones, and deliverables align with the RFP, contract, and agreed acceptance criteria.
- Maintain a secure-by-design approach across project life cycle stages, ensuring cybersecurity requirements are built in early and evidenced through testing and documentation.
- Ensure solutions align with applicable local and international cybersecurity standards, and rail industry expectations for safety-critical environments, including DESC ISR v3.1, DESC ICS v1.0, ISO/IEC 27001:2022, IEC 62443, and CLC/TS 50701:2023.
- Work in partnership with RTA RMD (Rail Maintenance Department) governance
- Operate within governance chaired by RTA (typically RTA RMD), ensuring key milestones and acceptance decisions are jointly signed off by RTA and Keolis-MHI in line with the contract and RFP
Financial
- Manage delivery to agreed budget and schedule baselines for large programmes, including forecasting, variance analysis, and change control.
- Control scope and cost impacts through disciplined management of variations, claims, and dependencies, working with the Project and Innovation Department on KPIs, commercial controls, and penalty exposure.
- Monitor contractor performance against delivery KPIs and milestone evidence, escalating deviations through the Project and Innovation Department governance.
Stakeholder / Customer
- Act as KM’s primary day-to-day project manager interface for RTA and the contractor, ensuring transparent communication, clear action tracking, and timely escalation.
- Coordinate strongly with the Head of Cybersecurity and the cybersecurity team to align delivery with security governance and operational needs
- Align internal stakeholders across IT, OT, Operations, Maintenance, Safety, and QHSE to ensure delivery is practical for a live metro environment.
Operational
- Establish and maintain the full project controls pack, including integrated schedule, RAID log (risks, assumptions, issues, dependencies), decision log, change register, and acceptance tracker.
- Lead delivery planning and execution for work performed in constrained access windows, typically engineering hours, ensuring correct sequencing, readiness, and rollback planning.
- Own and manage all approvals required for implementation in critical infrastructure environments, including:
- RTA CIMP (Change Impact Management Process) coordination to secure RTA approvals for impacted services and interfaces.
- ACCA (Asset Configuration Change Application) initiation, coordination, tracking, and closure within KM change control.
- PTW (Permit to Work) management to ensure site works only proceed when formally authorised, safe, and controlled.
- Ensure the contractor provides compliant and complete work packs, such as method statements, risk assessments, test procedures, and site readiness evidence.
- Enforce separation between Business ICT and Rail OT networks and ensure Rail OT systems remain isolated and air-gapped unless explicitly approved through change control and security governance.
- Manage quality assurance across delivery stages including but not limited to:
- design reviews
- FAT (Factory Acceptance Test)
- PICO (Post-installation Check-Out
- SAT (Site Acceptance Test)
- SIT (System Integration Testing)
- UAT (User Acceptance Test)
- Security testing, cutover planning, and handover.
- Ensure delivery outputs support operational sustainment, including RTA SOC integration (log sources, alerts, use cases), runbooks, and support models.
Capability / People
- Lead matrix teams across KM and direct the contractor delivery team through structured governance and delivery management.
- Drive delivery discipline, documentation quality, and evidence-based acceptance across all workstreams.
- Promote a safety and security culture, including the right and obligation to stop work if safety or security conditions are not met.
DIMENSIONS
- Multi-stakeholder delivery model: RTA sponsor and chair, KM project manager, contractor as delivery party under the 3-partite agreement.
- Delivery context: operational metro and tram environment, critical infrastructure constraints, restricted access windows, and strict change and work authorisation controls.
- Working at night or during weekends as required for timely project completion in line with HR Policy and UAE Law.
- Office environment. Occasional travel may be required.
MINIMUM QUALIFICATIONS
Min.
Required
Desirable
Education
- Bachelor’s degree in engineering, Information Systems, Computer Science, Cybersecurity, or related discipline.
- Postgraduate qualification in project management, cybersecurity, or systems engineering.
Experience