تفاصيل الوظيفة
شركة Meena Health في الرياض تبحث عن مدير أمن سيبراني (Cybersecurity Manager) مسؤول عن الإدارة اليومية وتنفيذ ضوابط الأمن السيبراني، ومراقبة المخاطر، ودعم متطلبات الامتثال، وتنسيق أنشطة الأمن السيبراني عبر بيئات تكنولوجيا المعلومات والرعاية الصحية الرقمية.
المهام والمسؤوليات
- إدارة العمليات اليومية للأمن السيبراني وضوابطه.
- مراقبة ومتابعة أنشطة SOC/SIEM، EDR، إدارة الثغرات، MFA، أمن الأجهزة الطرفية والشبكات والوصول.
- تحديد وتقييم وتنسيق معالجة الثغرات والمخاطر الأمنية.
- التعامل مع الحوادث الأمنية وتنسيق التحقيق والتصعيد والإغلاق.
- تنفيذ وصيانة سياسات وإجراءات وضوابط الأمن السيبراني.
- دعم تقييمات الامتثال وجمع الأدلة لمتطلبات NCA ECC وPDPL وISO 27001 ومتطلبات الرعاية الصحية.
- إجراء مراجعات أمنية دورية لأنظمة HIS/EMR والخدمات السحابية والتطبيقات والتكاملات والأجهزة الطبية.
- إجراء تقييمات أمنية لتغييرات التقنية والمشاريع والحلول الخارجية.
- إدارة مراجعات الوصول للمستخدمين والوصول المميز ومراجعات إعدادات الأمان.
- تنسيق أنشطة اختبار الاختراق وتقييم الثغرات والمعالجة مع الفرق الداخلية والخارجية.
- الحفاظ على توثيق الأمن السيبراني وسجلات المخاطر وسجلات الحوادث وأدلة الامتثال.
- تقديم التوجيه والتوعية في مجال الأمن السيبراني لفرق تقنية المعلومات والأعمال.
الشروط والمتطلبات
- درجة البكالوريوس في الأمن السيبراني أو تقنية المعلومات أو علوم الحاسب أو مجال ذي صلة.
- خبرة عملية من 5 إلى 7 سنوات في مجال الأمن السيبراني، ويفضل في قطاع الرعاية الصحية.
المهارات المطلوبة
- معرفة عملية في مجالات SOC وIAM وإدارة الثغرات وأمن الشبكات/السحابة وأمن الأجهزة الطرفية والاستجابة للحوادث والحوكمة والمخاطر والامتثال (GRC).
- فهم جيد لأنظمة الرعاية الصحية وأنظمة السجلات الطبية الإلكترونية (EMR/HIS) وبيانات المرضى والتكاملات وبيئات الأجهزة الطبية.
- معرفة بمعايير NCA ECC وPDPL؛ ومعرفة معيار ISO 27001 إلزامية.
- الشهادات المهنية ذات الصلة مثل Security+ وCySA+ وCEH وCISM أو CISSP تُعتبر ميزة إضافية.
عرض النص الأصلي للإعلان
Responsible for the day-to-day management and implementation of cybersecurity controls, monitoring security risks, supporting compliance requirements, and coordinating security activities across IT and digital healthcare environments. The role requires broad cybersecurity knowledge, practical technical experience, and an understanding of healthcare systems and data.
Key Responsibilities
- Manage day-to-day cybersecurity operations and security controls.
- Monitor and follow up on SOC/SIEM, EDR, vulnerability management, MFA, endpoint, network, and access security activities.
- Identify, assess, and coordinate remediation of cybersecurity vulnerabilities and risks.
- Handle and coordinate security incidents, including investigation, escalation, and closure.
- Implement and maintain cybersecurity policies, procedures, and technical controls.
- Support compliance assessments and evidence collection for NCA ECC, PDPL, ISO 27001, and healthcare requirements.
- Conduct periodic security reviews of HIS/EMR, cloud services, applications, integrations, and medical devices.
- Perform security assessments of technology changes, projects, and third-party solutions.
- Manage user access reviews, privileged access, and security configuration reviews.
- Coordinate penetration testing, vulnerability assessments, and remediation activities with internal and external teams.
- Maintain cybersecurity documentation, risk registers, incident records, and compliance evidence.
- Provide cybersecurity guidance and awareness to IT and business teams.
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field.
- 5-7 years of practical cybersecurity experience, preferably in healthcare.
- Working knowledge across SOC, IAM, vulnerability management, network/cloud security, endpoint security, incident response, and GRC.
- Good understanding of healthcare systems, EMR/HIS, patient data, integrations, and medical-device environments.
- Knowledge of NCA ECC and PDPL; ISO 27001 knowledge is must.
- Relevant certifications such as Security+, CySA+, CEH, CISM, or CISSP are an advantage.
رقم الإعلان لدى المصدر: 4472443159