img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About DallahHealth and the Opportunity

DallahHealth is seeking an Information Security Compliance Officer to join its team in Riyadh, Saudi Arabia. This is a full-time position focused on ensuring robust cybersecurity governance within the hospital environment.

Role Purpose

The primary purpose of this role is to ensure the hospital's adherence to cybersecurity regulatory requirements, information security policies, and industry best practices. The officer will monitor, assess, and enforce cybersecurity governance processes to protect patient data, hospital systems, and critical infrastructure, while supporting national healthcare cybersecurity objectives.

Key Responsibilities

  • Ensure all work is performed in accordance with approved policies, processes, procedures, and instructions.
  • Identify opportunities for continuous improvement in systems, processes, and practices, considering leading practices, cost reduction, and productivity.
  • Develop, update, and enforce information security policies, procedures, and Standard Operating Protocols (SOPs).
  • Ensure consistent application of cybersecurity controls across hospital departments and IT environments.
  • Conduct cybersecurity awareness training programs for hospital staff, promoting best practices for data privacy and secure system usage.
  • Facilitate annual cybersecurity drills and knowledge assessments.
  • Ensure the incident response process adheres to documented policies and reporting requirements.
  • Monitor incident logs, ensure proper documentation, and assist in post-incident compliance reviews.
  • Follow up on escalated cases/issues to ensure efficient and timely resolution.

Compliance, Audit, and Risk Management

  • Conduct gap assessments to evaluate compliance against national and international security standards.
  • Track regulatory changes and update internal cybersecurity policies accordingly.
  • Lead internal cybersecurity audits, prepare evidence of compliance, and coordinate responses to external auditors.
  • Facilitate audits by MOH, CBAHI, JCI, NCA, and SFDA by providing documentation and coordinating stakeholder involvement.
  • Perform regular risk assessments and maintain the risk register for IT systems, medical devices, and third-party vendors.
  • Report cybersecurity risks and compliance status to the Head of Information Security and IT Director, highlighting mitigation actions.

Required Experience

Candidates should possess 2 to 5 years of relevant experience in information security compliance or a related field.

Application Process

We invite qualified candidates to submit their applications for this full-time role in Riyadh.


Requirements

  • Requires 2-5 Years experience

Similar Jobs