مدير الأمن السيبراني
تفاصيل الوظيفة
Responsible for the day-to-day management and implementation of cybersecurity controls, monitoring security risks, supporting compliance requirements, and coordinating security activities across IT and digital healthcare environments. The role requires broad cybersecurity knowledge, practical technical experience, and an understanding of healthcare systems and data.
Key Responsibilities
- Manage day-to-day cybersecurity operations and security controls.
- Monitor and follow up on SOC/SIEM, EDR, vulnerability management, MFA, endpoint, network, and access security activities.
- Identify, assess, and coordinate remediation of cybersecurity vulnerabilities and risks.
- Handle and coordinate security incidents, including investigation, escalation, and closure.
- Implement and maintain cybersecurity policies, procedures, and technical controls.
- Support compliance assessments and evidence collection for NCA ECC, PDPL, ISO 27001, and healthcare requirements.
- Conduct periodic security reviews of HIS/EMR, cloud services, applications, integrations, and medical devices.
- Perform security assessments of technology changes, projects, and third-party solutions.
- Manage user access reviews, privileged access, and security configuration reviews.
- Coordinate penetration testing, vulnerability assessments, and remediation activities with internal and external teams.
- Maintain cybersecurity documentation, risk registers, incident records, and compliance evidence.
- Provide cybersecurity guidance and awareness to IT and business teams.
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field.
- 5–7 years of practical cybersecurity experience, preferably in healthcare.
- Working knowledge across SOC, IAM, vulnerability management, network/cloud security, endpoint security, incident response, and GRC.
- Good understanding of healthcare systems, EMR/HIS, patient data, integrations, and medical-device environments.
- Knowledge of NCA ECC and PDPL; ISO 27001 knowledge is must.
- Relevant certifications such as Security+, CySA+, CEH, CISM, or CISSP are an advantage.
هذا الإعلان منشور على تنقيب السعودية ويُعرض هنا مع الإشارة إلى المصدر. لا نتقاضى أي رسوم من الباحثين عن عمل. إذا كان الإعلان مسيئًا أو احتياليًا، أبلغنا.