دله الصحية تعلن عن وظيفة مسؤول الامتثال لأمن المعلومات في الرياض
تفاصيل الوظيفة
مسؤول ضمان الامتثال لمتطلبات الأمن السيبراني التنظيمية وسياسات أمن المعلومات وأفضل الممارسات في مستشفى دله الصحية بالرياض، لحماية بيانات المرضى والأنظمة والبنية التحتية الحيوية ودعم أهداف الأمن السيبراني الصحية الوطنية.
المهام والمسؤوليات
- ضمان تنفيذ العمل بناءً على السياسات والعمليات والإجراءات والتعليمات المعتمدة
- تحديد فرص التحسين المستمر للأنظمة والعمليات والممارسات مع مراعاة الممارسات الرائدة وخفض التكاليف وزيادة الإنتاجية
- ضمان تنفيذ الأنشطة اليومية بشكل صحيح وفقًا للسياسات والإجراءات
- متابعة الحالات/القضايا المرفوعة من المرؤوسين وضمان إغلاقها بكفاءة وفي الوقت المناسب
- إجراء تقييمات الفجوات لتقييم الامتثال للمعايير الأمنية الوطنية والدولية
- تتبع التغييرات التنظيمية وتحديث سياسات الأمن السيبراني الداخلية وفقًا لذلك
- تطوير وتحديث وتنفيذ سياسات وإجراءات أمن المعلومات وبروتوكولات التشغيل القياسية (SOPs)
- ضمان التطبيق المتسق لضوابط الأمن السيبراني عبر أقسام المستشفى وبيئات تقنية المعلومات
- قيادة عمليات التدقيق الداخلي للأمن السيبراني، وإعداد أدلة الامتثال، والتنسيق للرد على المدققين الخارجيين
- تسهيل عمليات التدقيق من وزارة الصحة والمركز السعودي لاعتماد المنشآت الصحية واللجنة الدولية المشتركة والهيئة الوطنية للأمن السيبراني والهيئة العامة للغذاء والدواء من خلال توفير الوثائق والتنسيق مع أصحاب المصلحة
- إجراء تقييمات المخاطر بشكل دوري والحفاظ على سجل المخاطر لأنظمة تقنية المعلومات والأجهزة الطبية والبائعين الخارجيين
- الإبلاغ عن مخاطر الأمن السيبراني وحالة الامتثال إلى رئيس قسم أمن المعلومات ومدير تقنية المعلومات مع تسليط الضوء على إجراءات التخفيف
- إجراء برامج تدريبية للتوعية بالأمن السيبراني لموظفي المستشفى، وتعزيز أفضل الممارسات لخصوصية البيانات والاستخدام الآمن للأنظمة
- تسهيل التدريبات السنوية للأمن السيبراني وتقييمات المعرفة
- ضمان اتباع عملية الاستجابة للحوادث للسياسات الموثقة ومتطلبات الإبلاغ الوطنية
- مراقبة سجلات الحوادث، وضمان التوثيق السليم، والمساعدة في مراجعات الامتثال بعد الحوادث
الشروط والمتطلبات
- خبرة من 3 إلى 5 سنوات في الامتثال للأمن السيبراني أو إدارة المخاطر أو الحوكمة، ويفضل أن تكون في بيئة الرعاية الصحية
- درجة البكالوريوس في تقنية المعلومات أو علوم الحاسب أو مجال ذي صلة
المهارات المطلوبة
- مهارات إدارية وتنظيمية ممتازة
- مهارات تواصل جيدة باللغة العربية والإنجليزية (شفهيًا وكتابيًا)
- إتقان قوي لبرامج Microsoft Office (Word, Excel, PowerPoint, Outlook)
- القدرة على إعداد تقارير واضحة ومحاضر الاجتماعات والحفاظ على سجلات دقيقة
- مهارات إدارة الوقت مع الاهتمام بالتفاصيل والدقة
- معرفة أساسية بسير عمل خدمات تقنية المعلومات وأنظمة تقنية المعلومات في الرعاية الصحية (مستحسن)
- القدرة على إدارة المعلومات السرية بشكل احترافي
- أخلاقيات عمل قوية
- الاعتمادية والمسؤولية
- امتلاك موقف إيجابي
- القدرة على التكيف
- الصدق والنزاهة
- الدافعية الذاتية
- الدافعية للنمو والتعلم
- ثقة عالية بالنفس
عرض النص الأصلي للإعلان
Job Purpose:
Ensures the hospital’s adherence to cybersecurity regulatory requirements, information security policies, and industry best practices. This role monitors, assesses, and enforces cybersecurity governance processes to protect patient data, hospital systems, and critical infrastructure while supporting national healthcare cybersecurity objectives.
Roles and Responsibilities:
- Ensure work is performed based on approved policies, processes, procedures, and instructions
- Identify opportunities for continuous improvement of systems, processes and practices taking into account leading practices, cost reduction and productivity improvement
- Ensure day-to-day activities are properly performed in line with policies and procedures
- Follow-up on escalated cases/issues of subordinates to ensure they are closed efficiently and in a timely manner
- Conduct gap assessments to evaluate compliance against national and international security standards.
- Track regulatory changes and update internal cybersecurity policies accordingly.
- Develop, update, and enforce information security policies, procedures, and standard operating protocols (SOPs).
- Ensure consistent application of cybersecurity controls across hospital departments and IT environments.
- Lead internal cybersecurity audits, prepare evidence of compliance, and coordinate responses to external auditors.
- Facilitate MOH, CBAHI, JCI, NCA, and SFDA audits by providing documentation and coordinating stakeholder involvement.
- Perform regular risk assessments and maintain the risk register for IT systems, medical devices, and third-party vendors.
- Report cybersecurity risks and compliance status to the Head of Information Security and IT Director, highlighting mitigation actions.
- Conduct cybersecurity awareness training programs for hospital staff, promoting best practices for data privacy and secure system usage.
- Facilitate annual cybersecurity drills and knowledge assessments.
- Ensure the incident response process follows documented policies and national reporting requirements.
- Monitor incident logs, ensure proper documentation, and assist in post-incident compliance reviews.
Knowledge and Experience:
3-5 years of experience in cybersecurity compliance, risk management, or governance-preferably in healthcare setting.
Education and Certifications:
Bachelor’s degree in Information Technology, Computer Science, or related field.
Skills:
Excellent administrative and organizational skills.
Good communication skills in Arabic and English (verbal and written).
Strong proficiency in Microsoft Office (Word, Excel, PowerPoint, Outlook).
Ability to prepare clear reports, meeting minutes, and maintain accurate records.
Time management skills with attention to detail and accuracy.
Basic knowledge of IT service workflows and healthcare IT systems is desirable.
Ability to manage confidential information professionally.
Attitude:
Strong Work Ethic
Dependability and Responsibility
Possessing a Positive Attitude
Adaptability
Honesty and Integrity
Self-Motivated
Motivated to Grow and Learn
Strong Self-Confidenceوظائف أخرى لدى دله الصحية