Alyve Health
Website:
alyve.health
Job details:
Location: Delhi
Work mode: Hybrid
Experience: 2 years
Opening: One
About Alyve?
Alyve Health is building India’s prevention-first health operating system, the infrastructure that
enables enterprises, insurers and other institutions to deliver everyday healthcare through one
connected experience.
We exist because healthcare should not begin with a hospitalization or a health scare. It should
help people take the right steps earlier whether that means speaking to a doctor, getting a
diagnostic test, managing a condition or building healthier habits. Alyve makes everyday health
and wellness more accessible, cashless, configurable and guided, while turning every interaction
into a better next step.
Today, Alyve Health powers healthcare journeys for 2.5 million+ lives across 750+ enterprise
clients. Our ambition is simple and large: to help a billion Indians live fuller lives
The Opportunity
We are looking for a proactive, detail-oriented Information Security and Privacy Lead to own
Alyve Health's end-to-end ISMS and Privacy programme - certification management, client
security audits and continuous audit readiness - acting as the central coordination point between
leadership, internal teams, consultants and auditors.
What You Will Own
1. Certification and Audit Management (ISO 27001, ISO 42001, SOC 2 Type II, HIPAA,
GDPR, DPDP Act)
• Own end-to-end acquisition and renewal of Alyve Health's certifications, coordinating with
external consultants through the full lifecycle.
• Run gap analyses against each framework's requirements; drive closure with clear action
plans, owners and deadlines.
• Draft and maintain the policies, SOPs, and evidence needed to demonstrate control
effectiveness. • Coordinate with Finance, Product, Engineering, Legal, Growth and Customer Experience to
collect evidence and confirm each function's adherence to policies.
• Conduct Internal Audits and represent Alyve Health in external audits by external agencies,
clients and certifications bodies.Run gap analyses against each framework's requirements;
drive closure with clear action plans, owners, and deadlines.
2. Client Security and Privacy Audits
• Complete TPRM questionnaires and due-diligence requests from corporate clients with
supporting documentation and policies.
• Represent Alyve Health in client-led security and privacy audits and close any gaps raised,
coordinating with relevant internal teams.
3. Controls Maintenance and Audit Readiness
• Create and maintain the annual controls calendar and drive owners to complete each recurring
activity on time.
• Keep Alyve Health continuously audit-ready.
• Maintain controls trackers and a leadership dashboard covering obligations, audits, and open
items; prepare periodic MIS updates.
• Deliver internal controls training, with role-specific sessions.
• Own policy renewals, keeping each policy aligned to actual practice at the time of renewal.
• Maintain DPIAs, data processing records, and data subject requests; monitor cloud (GCP) and
third-party integrations for data-privacy.
4. Vendor Security
• Conduct due diligence on new and existing vendors.
• Ensure vendor contracts and SLAs carry the necessary security and data-protection clauses.
What Will Make You Effective
• Certifications:ISO 27001 Lead Auditor (LA) & ISO 27001 Lead Implementer (LI) (highly
preferred),ISO 27001 Foundation & DPDP / Data Privacy Practitioner (preferred).
• 2 years of experience in information security governance, risk management, or a related
domain.
• Hands-on experience in leading and coordinating certification audits, including ISO 27001,
SOC 2, HIPAA, and DPDPA, along with information security and privacy controls
implementation, control calendars and policy management.
• Working knowledge of ISO 27001, ISO 42001, DPDP Act 2023, HIPAA, SOCX and
cybersecurity requirements.
• Familiarity with cloud controls posture (GCP / AWS / Azure) and GRC tools
• Discretion and integrity in handling sensitive member health data and contractual information.
Click on Apply to know more.