Enable job alerts via email!
A healthcare organization in Kuala Lumpur is looking for a professional to enhance data security measures and ensure compliance with PDPA. Responsibilities include conducting audits, managing data breaches, and training staff on data protection principles. Candidates should have a degree in information security and at least 3 years of experience in data protection, especially in a healthcare setting. Strong communication and problem-solving skills are essential.
System-Specific Data Protection & Enhancement: Review and enhance data security measures for current systems, including Dynamics 365 Business Central (ERP), Xilnex Point of Sale (POS), company‑owned mobile apps, and the primary Clinical System.
Collaborate with IT and vendors to ensure PDPA compliance, data encryption, access control, and audit trails.
Monitoring and Auditing: Conduct regular compliance assessments and data protection audits; develop and maintain a data processing inventory.
Risk and Incident Management: Lead incident response for data breaches; notify the Personal Data Protection Commissioner within 72 hours and affected individuals within 7 days.
Training and Awareness: Conduct training programs on PDPA principles, especially for staff handling sensitive medical data.
Patient Rights Management: Manage patient requests for data access, correction, and portability.
Implementation & Testing: Collaborate with development teams to implement new modules, upgrades, and integrations; develop and execute test plans; lead UAT and support end‑users.
Training & Documentation: Conduct training sessions; create and update documentation (process flows, technical guides, training materials).
• Bachelor’s degree in information security, Data Governance, or related discipline.
• Minimum 3 years in data protection, compliance, or IT risk management (preferably in healthcare or regulated sectors).
• Strong familiarity with Dynamics 365 Business Central, Xilnex POS, mobile app platforms, and clinical systems.
• Strong understanding of PDPA and healthcare‑specific privacy needs.
• Experience conducting system‑level data protection assessments.
• Excellent communication, stakeholder engagement, and documentation skills.
• Ability to coordinate cross‑functional teams including IT, Legal, and Clinical.
• Strong problem‑solving skills and ability to troubleshoot system issues effectively.
• Excellent interpersonal skills, liaising between business and technical teams.