Search by job, company or skills

Information Security Compliance Officer

  • Posted 20 hours ago
  • Be among the first 10 applicants

Job Description

Job Purpose:

Ensures the hospital's adherence to cybersecurity regulatory requirements, information security policies, and industry best practices. This role monitors, assesses, and enforces cybersecurity governance processes to protect patient data, hospital systems, and critical infrastructure while supporting national healthcare cybersecurity objectives.

Roles and Responsibilities:

  • Ensure work is performed based on approved policies, processes, procedures, and instructions
  • Identify opportunities for continuous improvement of systems, processes and practices taking into account leading practices, cost reduction and productivity improvement
  • Ensure day-to-day activities are properly performed in line with policies and procedures
  • Follow-up on escalated cases/issues of subordinates to ensure they are closed efficiently and in a timely manner
  • Conduct gap assessments to evaluate compliance against national and international security standards.
  • Track regulatory changes and update internal cybersecurity policies accordingly.
  • Develop, update, and enforce information security policies, procedures, and standard operating protocols (SOPs).
  • Ensure consistent application of cybersecurity controls across hospital departments and IT environments.
  • Lead internal cybersecurity audits, prepare evidence of compliance, and coordinate responses to external auditors.
  • Facilitate MOH, CBAHI, JCI, NCA, and SFDA audits by providing documentation and coordinating stakeholder involvement.
  • Perform regular risk assessments and maintain the risk register for IT systems, medical devices, and third-party vendors.
  • Report cybersecurity risks and compliance status to the Head of Information Security and IT Director, highlighting mitigation actions.
  • Conduct cybersecurity awareness training programs for hospital staff, promoting best practices for data privacy and secure system usage.
  • Facilitate annual cybersecurity drills and knowledge assessments.
  • Ensure the incident response process follows documented policies and reporting requirements.
  • Monitor incident logs, ensure proper documentation, and assist in post-incident compliance reviews.

Requirements:

Knowledge and Experience:

3–5 years of experience in cybersecurity compliance, risk management, or governance—preferably in healthcare setting.

Education and Certifications:

Bachelor's degree in Information Technology, Computer Science, or related field.

Skills:

Excellent administrative and organizational skills.

Good communication skills in Arabic and English (verbal and written).

Strong proficiency in Microsoft Office (Word, Excel, PowerPoint, Outlook).

Ability to prepare clear reports, meeting minutes, and maintain accurate records.

Time management skills with attention to detail and accuracy.

Basic knowledge of IT service workflows and healthcare IT systems is desirable.

Ability to manage confidential information professionally.

Attitude:

Strong Work Ethic

Dependability and Responsibility

Possessing a Positive Attitude

Adaptability

Honesty and Integrity

Self-Motivated

Motivated to Grow and Learn

Strong Self-Confidence

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 152544405

Beware of Scammers

We don’t charge money for job offers