Senior Data Security Analyst
Listed on 2026-03-04
-
IT/Tech
Cybersecurity, Data Security, Information Security, IT Consultant
Every healthcare system is built on trust.
Every digital system either protects it, or quietly crumble it.
At the Saudi Commission for Health Specialties, our role goes beyond regulation.
We exist to safeguard the credibility of healthcare professionals, the integrity of data, and the of society, especially as analytics and AI become inseparable from modern healthcare governance.
This role exists to ensure that progress never outruns responsibility.
Why this role mattersAs healthcare data grows more powerful, the risk of misuse goes higher.
In this role, you are not responding to isolated incidents.
You are shaping how trust is preserved by design.
Your work directly supports:
- Responsible use of AI in healthcare regulation
- Protection of Saudi personal and sensitive health data
- Compliance with PDPL and national cybersecurity mandates
- Vision 2030’s commitment to secure, ethical digital transformation
Quietly, consistently, and with long-term impact.
What you will contribute inYou will operate where technology, regulation, and ethics intersect.
You will:
- Protect data before it becomes a risk, not after it becomes a headline
- Strengthen safeguards that allow innovation to move forward safely
- Influence on how systems are designed, assessed, and approved
- Carry responsibility that extends beyond a single system or team
This is work that prevents harm, not just detects it.
What enables you to do this work wellWe understand that responsibility of this level requires stability, trust, and balance. Not constant friction.
That’s why we provide:
- Financial recognition that grows with your impact, through structured annual increments and performance-based rewards
- Security for the people who matter to you, including comprehensive health coverage that extends to your parents
- Support for your family’s future, through schooling allowances that reduce personal trade-offs
- Flexibility built on trust, with agile working arrangements that respect how professionals actually perform at their best
- Time to recover and think clearly, with generous leave that protects judgment and sustainability
- Continuous development, so your expertise stays ahead of regulation, not behind it
- A healthy, professional environment, where security and privacy decisions are respected — not overridden
These are not perks, these are enablers. Designed so you can focus on work that demands clarity and integrity.
Final noteYou won’t see your impact immediately!
But you will know it’s there in the incidents that never happen, the risks that barely escalates, and the trust that remains intact.
Role ObjectiveTo safeguard sensitive and personal data processed by the Saudi Commission for Health Specialties by implementing and governing advanced data protection, data loss prevention, and privacy-by-design controls across enterprise and AI-enabled systems, ensuring full compliance with PDPL, NCA requirements, and national data governance mandates.
Duties & Responsibilities- Design, implement, and continuously tune data leakage detection and prevention controls using DAM, DLP, and data classification technologies.
- Conduct Data Protection Impact Assessments (DPIA) for AI systems processing Saudi personal data and maintain regulatory documentation.
- Enforce encryption, tokenization, and data masking controls in compliance with NCA-ECC before data is used in analytics or AI environments.
- Review and assess data processing agreements with AI vendors and third parties, ensuring cross-border data transfer compliance.
- Lead advanced data leakage investigations, identify recurrence patterns and root causes, and recommend corrective actions.
- Coordinate with Incident Response, IAM/PAM, Application, and Data Governance teams during data security incidents.
- Integrate data security platforms with SIEM, IAM/PAM, and EDR systems to enhance monitoring and detection capabilities.
- Execute periodic data leakage simulations and scenario-based testing.
- Perform pre-go-live data protection reviews for new systems prior to production deployment.
- Prepare executive and stakeholder reports on data exposure, risks, and compliance posture.
- Bachelor’s degree in Cybersecurity, Information Technology.
- 3–6 years of hands‑on experience in data protection, DLP, or information security roles.
- Practical experience with at least one enterprise DLP/DAM platform (e.g., Forcepoint, Microsoft Purview, Symantec, Imperva).
- Solid understanding of databases, operating systems, and data flows.
- CISSP, CCSA, CCSE. (Preferred)
- Ability to prepare and maintain Records of Processing Activities (ROPA) for AI systems.
If that kind of contribution matters to you,
Apply
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).