📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

وظيفة مسؤول الامتثال لأمن المعلومات شاغرة لدى DallahHealth بالرياض

Information Security Compliance Officer
🏢 DallahHealth
🕒 نُشرت: (اليوم) 📍 الرياض وظائف الهندسة والتقنية
التقديم على الوظيفة من المصدر الرسمي ↗

تفاصيل الوظيفة

شركة DallahHealth تعلن عن وظيفة Information Security Compliance Officer في الرياض.

نبذة عن الوظيفة

ضمان التزام المستشفى بالمتطلبات التنظيمية للأمن السيبراني، وسياسات أمن المعلومات، وأفضل الممارسات في المجال. يتولى هذا الدور مراقبة وتقييم وتنفيذ عمليات حوكمة الأمن السيبراني لحماية بيانات المرضى وأنظمة المستشفى والبنية التحتية الحيوية، مع دعم أهداف الأمن السيبراني للرعاية الصحية الوطنية.

المهام والمسؤوليات

  • ضمان أداء العمل بناءً على السياسات والإجراءات والتعليمات المعتمدة.
  • تحديد فرص التحسين المستمر للأنظمة والعمليات والممارسات مع مراعاة الممارسات الرائدة وخفض التكاليف وزيادة الإنتاجية.
  • ضمان أداء المهام اليومية بشكل صحيح وفقًا للسياسات والإجراءات.
  • متابعة الحالات/المشكلات المرفوعة من المرؤوسين لضمان إغلاقها بكفاءة وفي الوقت المناسب.
  • إجراء تقييمات الفجوات للتحقق من الامتثال للمعايير الأمنية الوطنية والدولية.
  • تتبع التغييرات التنظيمية وتحديث سياسات الأمن السيبراني الداخلية وفقًا لذلك.
  • تطوير وتحديث وتنفيذ سياسات أمن المعلومات والإجراءات وبروتوكولات التشغيل القياسية (SOPs).
  • ضمان التطبيق المتسق لضوابط الأمن السيبراني عبر أقسام المستشفى وبيئات تقنية المعلومات.
  • قيادة عمليات التدقيق الداخلي للأمن السيبراني، وإعداد أدلة الامتثال، والتنسيق للرد على المراجعين الخارجيين.
  • تسهيل عمليات تدقيق وزارة الصحة (MOH) والمركز السعودي لاعتماد المنشآت الصحية (CBAHI) واللجنة الدولية المشتركة (JCI) والهيئة الوطنية للأمن السيبراني (NCA) والهيئة العامة للغذاء والدواء (SFDA) من خلال توفير التوثيق وتنسيق مشاركة أصحاب المصلحة.
  • إجراء تقييمات المخاطر بشكل دوري والحفاظ على سجل المخاطر لأنظمة تقنية المعلومات والأجهزة الطبية والموردين الخارجيين.
  • الإبلاغ عن مخاطر الأمن السيبراني وحالة الامتثال إلى رئيس أمن المعلومات ومدير تقنية المعلومات مع توضيح إجراءات التخفيف.
  • تنفيذ برامج التوعية بالأمن السيبراني لموظفي المستشفى، وتعزيز أفضل الممارسات لخصوصية البيانات والاستخدام الآمن للأنظمة.
  • تسهيل التمارين السنوية للأمن السيبراني وتقييمات المعرفة.
  • ضمان أن عملية الاستجابة للحوادث تتبع السياسات الوثائقية ومتطلبات الإبلاغ.
  • مراقبة سجلات الحوادث، وضمان التوثيق السليم، والمساعدة في مراجعات الامتثال بعد الحوادث.

الشروط والمتطلبات

  • خبرة من 3 إلى 5 سنوات في الامتثال للأمن السيبراني أو إدارة المخاطر أو الحوكمة، ويفضل أن تكون في بيئة رعاية صحية.
  • درجة البكالوريوس في تقنية المعلومات أو علوم الحاسب أو مجال ذي صلة.

المهارات المطلوبة

  • مهارات إدارية وتنظيمية ممتازة.
  • مهارات تواصل جيدة باللغتين العربية والإنجليزية (شفهيًا وكتابيًا).
  • كفاءة عالية في استخدام Microsoft Office (Word, Excel, PowerPoint, Outlook).
  • القدرة على إعداد تقارير واضحة ومحاضر اجتماعات والحفاظ على سجلات دقيقة.
  • مهارات إدارة الوقت مع الاهتمام بالتفاصيل والدقة.
  • معرفة أساسية بسير عمل خدمات تقنية المعلومات وأنظمة تقنية المعلومات في الرعاية الصحية (مستحبة).
  • القدرة على إدارة المعلومات السرية بشكل احترافي.
  • أخلاقيات عمل قوية.
  • الاعتمادية والمسؤولية.
  • امتلاك موقف إيجابي.
  • القدرة على التكيف.
  • الصدق والنزاهة.
  • الدافعية الذاتية.
  • الدافعية للتعلم والنمو.
  • ثقة عالية بالنفس.
عرض النص الأصلي للإعلان

Job Purpose:


Ensures the hospital’s adherence to cybersecurity regulatory requirements, information security policies, and industry best practices. This role monitors, assesses, and enforces cybersecurity governance processes to protect patient data, hospital systems, and critical infrastructure while supporting national healthcare cybersecurity objectives.


Roles and Responsibilities:


  • Ensure work is performed based on approved policies, processes, procedures, and instructions
  • Identify opportunities for continuous improvement of systems, processes and practices taking into account leading practices, cost reduction and productivity improvement
  • Ensure day-to-day activities are properly performed in line with policies and procedures
  • Follow-up on escalated cases/issues of subordinates to ensure they are closed efficiently and in a timely manner
  • Conduct gap assessments to evaluate compliance against national and international security standards.
  • Track regulatory changes and update internal cybersecurity policies accordingly.
  • Develop, update, and enforce information security policies, procedures, and standard operating protocols (SOPs).
  • Ensure consistent application of cybersecurity controls across hospital departments and IT environments.
  • Lead internal cybersecurity audits, prepare evidence of compliance, and coordinate responses to external auditors.
  • Facilitate MOH, CBAHI, JCI, NCA, and SFDA audits by providing documentation and coordinating stakeholder involvement.
  • Perform regular risk assessments and maintain the risk register for IT systems, medical devices, and third-party vendors.
  • Report cybersecurity risks and compliance status to the Head of Information Security and IT Director, highlighting mitigation actions.
  • Conduct cybersecurity awareness training programs for hospital staff, promoting best practices for data privacy and secure system usage.
  • Facilitate annual cybersecurity drills and knowledge assessments.
  • Ensure the incident response process follows documented policies and reporting requirements.
  • Monitor incident logs, ensure proper documentation, and assist in post-incident compliance reviews.


Requirements:


Knowledge and Experience:

3-5 years of experience in cybersecurity compliance, risk management, or governance-preferably in healthcare setting.


Education and Certifications:

Bachelor’s degree in Information Technology, Computer Science, or related field.

Skills:

Excellent administrative and organizational skills.

Good communication skills in Arabic and English (verbal and written).

Strong proficiency in Microsoft Office (Word, Excel, PowerPoint, Outlook).

Ability to prepare clear reports, meeting minutes, and maintain accurate records.

Time management skills with attention to detail and accuracy.

Basic knowledge of IT service workflows and healthcare IT systems is desirable.

Ability to manage confidential information professionally.


Attitude:


Strong Work Ethic

Dependability and Responsibility

Possessing a Positive Attitude

Adaptability

Honesty and Integrity

Self-Motivated

Motivated to Grow and Learn

Strong Self-Confidence

المصدر: LinkedIn - أُضيفت للموقع في 18 أغسطس 2026

وظائف أخرى لدى DallahHealth