Information Security Manager
الوصف الوظيفي
About My Clinic
My Clinic stands as the premier multispecialty outpatient care provider in Saudi Arabia, dedicated to enhancing the health and well-being of our communities. Since our establishment in 2017, we have been at the forefront of healthcare innovation, driven by a mission to empower individuals to lead longer, healthier, and happier lives. Our commitment to care, collaboration, ambition, and responsibility defines our approach to delivering exceptional healthcare services. As we continue to expand our reach and capabilities, we are seeking a dynamic and forward-thinking Information Security Manager to join our team and safeguard our digital infrastructure and sensitive patient data.
Job Overview
The Information Security Manager will play a pivotal role in leading My Clinic’s information and cybersecurity initiatives, with a strong emphasis on Governance, Risk, and Compliance (GRC). This position is instrumental in protecting sensitive patient data, ensuring adherence to cybersecurity regulations, and maintaining the integrity of our operations. The ideal candidate will be responsible for developing and executing robust security and risk management strategies, managing the information security team, and collaborating closely with IT and business leadership to mitigate risks and uphold compliance with industry standards such as CIS, NIST, and the National Cybersecurity Authority (NCA) controls.
Key Responsibilities
- Governance and Policy Development: Design, implement, and maintain comprehensive information security and data protection policies, procedures, and guidelines. Ensure alignment with industry standards (CIS, NIST, NCA) and regulatory requirements, including Saudi Arabia’s Personal Data Protection Law (PDPL).
- Risk Management: Lead enterprise-wide risk assessments to identify, analyze, and prioritize cybersecurity and data protection risks. Develop and maintain a risk register, implement risk mitigation strategies, and monitor risk treatment plans to safeguard critical systems and sensitive data.
- Security Operations Center (SOC) Oversight: Oversee the outsourced SOC operations from My Clinic’s perspective, ensuring the third-party provider effectively monitors, detects, and responds to cybersecurity threats. Review and enforce key performance indicators (KPIs) for the SOC, evaluate incident handling processes, and align SOC activities with My Clinic’s security objectives and compliance requirements.
- Compliance Oversight: Ensure organizational compliance with relevant cybersecurity frameworks (CIS, NIST, NCA) and data protection regulations, including PDPL. Conduct regular compliance reviews to align with the requirements of regulatory bodies such as the Saudi Data and Artificial Intelligence Authority (SDAIA) and the National Cybersecurity Authority (NCA).
- Data Protection Impact Assessments (DPIAs): Perform DPIAs to evaluate and mitigate risks associated with processing personal and sensitive data, ensuring adherence to data protection principles and regulatory obligations.
- Incident Response and Management: Oversee the development and execution of incident response plans for cybersecurity and data breach incidents. Ensure timely investigation, mitigation, and reporting to relevant authorities within regulatory timeframes. Incorporate lessons learned into risk management processes and coordinate with the outsourced SOC provider.
- Training and Awareness Programs: Design and deliver organization-wide training and awareness programs to foster a culture of cybersecurity, risk management, and data protection compliance among employees and stakeholders.
- Third-Party Risk Management: Evaluate and monitor contracts with third-party vendors, data processors, and partners to ensure compliance with cybersecurity and data protection requirements, including PDPL and other relevant standards.
- Auditing and Monitoring: Conduct regular audits of cybersecurity practices, data processing activities, and GRC controls to ensure ongoing compliance with internal policies and external regulations. Provide actionable recommendations to address identified gaps.
- Advisory and Collaboration: Serve as a trusted advisor to senior management, the risk committee, and IT leadership on cybersecurity best practices, emerging threats, and strategic initiatives to enhance information security posture.
Qualifications and Experience
To excel in this role, candidates should possess a bachelor’s degree in Information Security, Cybersecurity, Computer Science, or a related field. A minimum of 7-10 years of progressive experience in information security, with at least 3-5 years in a managerial or leadership capacity, is required. Professional certifications such as CISSP, CISM, CRISC, or equivalent are highly desirable. The ideal candidate will have a deep understanding of cybersecurity frameworks (CIS, NIST, NCA), data protection regulations (PDPL), and risk management principles. Strong leadership, communication, and stakeholder management skills are essential to drive security initiatives and foster a culture of security awareness across the organization.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.
ℹ️ إخلاء مسؤولية توظيف:
موقع وظائف السعودية (ksajobshub.com) هو محرك بحث ومجمع لإعلانات الوظائف من المصادر والشركات الرسمية في المملكة العربية السعودية. نحن لا نتقاضى أي مبالغ مالية أو رسوم من الباحثين عن عمل، وتتم عمليات التقديم مباشرة عبر الانتقال للرابط الأصلي للجهة المعلنة.