Information Technology Security Officer
Kanad Hospital · al-Ain, Abu Dhabi, Vereinigte Arabische Emirate
Company Description
Kanad Hospital, established in 1960 as the first hospital in Abu Dhabi Emirate, is a not-for-profit healthcare institution renowned for its exceptional obstetrics and pediatric care. Committed to providing whole-person healthcare with love and compassion, Kanad Hospital follows the teachings of Jesus and aims to serve women, children, and their families in the community. The hospital has achieved JCI accreditation and is globally recognized for its innovative care programs, such as the treatment of Respiratory Distress Syndrome in newborns. Located in Al Ain, Kanad Hospital continues its mission to deliver quality healthcare while upholding its core values of love, integrity, service, and excellence.
Role Description
The Information Security & Data Protection Officer (IS/DPO) is responsible for overseeing Kanad Hospital’s information security, data protection, and privacy program in compliance with UAE laws, ADHICS standards, and international best practices. The role ensures lawful and secure processing of Personal Identifiable Information (PII) and Personal Health Information (PHI), implements privacy-by-design principles in clinical, administrative, and digital workflows, and leads key security projects including SOC, SIEM, and Data Loss Prevention (DLP) initiatives.
Essential Job Functions
- Develop, implement, and monitor a strategic, comprehensive data protection, enterprise information security, and IT risk management program aligned with ADHICS, UAE privacy laws, and international standards.
- Ensure no conflict of interest in execution of DPO duties and act as primary contact for data subjects and regulatory authorities.
- Maintain a data processing register and oversee Data Protection Impact Assessments (DPIA) for systems processing PII and PHI, including automated, profiling, or large-scale data processing.
- Implement and monitor mechanisms to support data subject rights:
- Access to PHI/PII processing information
- Data transfer to data subjects or other controllers in machine-readable format
- Correction or deletion of PII/PHI4.4.4.Restriction of processing and retention for legal claims.
- Objection to automated decisions and profiling outcomes
- Maintain records of disclosures and data sharing involving PII and PHI.
- Review and appropriately reject data subject requests when:
- Interferes with judicial investigations or public interest
- Deletion conflicts with legal requirements
- Restriction undermines information security protection efforts
- Violates others’ privacy or confidentiality
- Automated processing is covered by valid consent or legal basis
- Execute periodic and ad-hoc compliance checks, privacy audits, and cyber risk assessments.
- Recommend and implement remedial actions for security, privacy, and compliance gaps.
- Contribute to Risk Management Framework documentation and activities, including secure system lifecycle support and PHI handling.
- Participate in risk governance committees and report security and data protection risks to hospital leadership.
- Lead and monitor implementation of SOC, SIEM, and PHI monitoring systems to identify threats and unauthorized access.
- Oversee and enhance DLP governance for PHI/PII, including detection, prevention, and incident response controls.
- Conduct privacy and cyber security awareness training for clinical, frontline, and administrative staff.
- Collaborate with IT, clinical, and operational departments to ensure privacy-by-design in system rollouts, vendor assessments, and digital transformation projects.
- Investigate and coordinate responses to data breaches involving PII and PHI, ensuring timely notification and reporting.
- Act as liaison with legal counsel, regulatory authorities, and certification bodies regarding data protection and ADHICS assessments.
- Define and enforce security protocols, policies, and procedures, ensuring compliance with UAE regulations and international standards.
Qualifications
Bachelor’s Degree in Information Technology, Computer Science, or Cybersecurity. Diploma holders with strong relevant experience may be considered.
3–5 years of professional experience in Information Security. Minimum 2 years of hands-on experience with DLP and SOC/SIEM projects.
Salary range: 12 to 15KAED/month
Über den Arbeitgeber

al-Ain · Vereinigte Arabische Emirate
Kanad Hospital (formerly known as Oasis Hospital) was established in 1960 by Doctors Pat and Mariam Kennedy at the request of HH Sheikh Zayed Al Nahyan. The Kennedys were physicians from the United States whose primary goal was to honor God by providing loving healthcare to those in this region. Ever since our launch, Kanad has been known for its excellent obstetric and pediatric care, and we are proud to be recognized as one of the premier healthcare providers for women and children in the Middle East. We are honored to be the birthplace of many of the leaders of our great nation including HH Sheikh Mohamed bin Zayed Al Nahyan. Kanad Hospital is a not-for-profit hospital that strives to diligently follow the teachings of Jesus in the way that we care for women, children, and their families. We have the privilege of being the first hospital established in the Abu Dhabi Emirate and the first private hospital in the Emirate to attain JCI accreditation. Additionally, we are the first hospital in the world to obtain JCI Clinical Care Program Certifications for our treatment program for Respiratory Distress Syndrome in newborns and for our Natural Birth after Cesarean Section program for mothers. Our Hope: Healthy communities transformed by the love of the God. Our Purpose: To honor God by providing exceptional whole person healthcare to the community with the love and compassion of Jesus Christ. Core Values: LOVE I.S. C.A.R.E Love God and love one another Integrity through truth and transparency Serving others first Courage to Advocate for those in need Acknowledge our need for God and each other Rooted in Community Excellence in Care
Ähnliche Stellen
- SOC LeadDynamed Healthcare Solutions · Abu Dhabi, Vereinigte Arabische Emirate
- Network EngineerAl Salama Hospital · Dschidda, Saudi-Arabien
- IT SpecialistFakeeh Care Group · Dschidda, Saudi-Arabien
- Installation & Upgrade SpecialistGE HealthCare · Riyadh Region, Saudi-Arabien
- Information Technology, Web Developer, Graphic DesignerMagenta Investments · Dubai, Vereinigte Arabische Emirate
- IT Specialist - Healthcare & AestheticsSeline Clinic Dubai · Dubai, Vereinigte Arabische Emirate