Qure.ai is one of the fastest-growing startups in India, which develops Artificial Intelligence enabled products and platforms for healthcare diagnostics. We create cutting-edge solutions that positively impact patients lives in various care domains, including lung cancer, tuberculosis, and stroke. To date, our innovative technologies have reached over 12 million individuals across 75+ countries worldwide. Qure.ai is an equal-opportunity employer.
Role Summary
As a Cybersecurity Compliance Associate, you will play a pivotal role in ensuring that Qure.ai\u2019s cybersecurity practices align with international regulatory and compliance standards. This position emphasizes compliance-oriented responsibilities over technical operations. You will collaborate across functions to document, assess, and improve compliance frameworks, ensuring the company\u2019s information security posture remains robust and aligned with standards like ISO 27001, HIPAA, and SOC 2.
Key Responsibilities
Compliance Documentation and Audits
Develop, maintain, and manage documentation for ISO 27001, HIPAA, SOC 2, and other regulatory frameworks.
Contribute to FDA cybersecurity submissions.
Ensure compliance with non-information security audits, including MDSAP and QMS.
Participate in internal and external audits (ISO 27001, HIPAA, SOC 2, MDSAP) and ensure successful outcomes.
Author and revise policies, procedures, and standards to align with regulatory requirements.
Risk Management and Due Diligence
Conduct and document risk assessments for information security frameworks (e.g., ISO 27001, HIPAA, SOC 2).
Respond to due diligence questionnaires from clients, ensuring timely and accurate submissions.
Create and manage vendor due diligence processes related to information security.
Cross-Functional Collaboration
Work closely with Engineering, IT, HR, Product, and Client Success teams to enhance Qure.ai\u2019s cybersecurity posture.
Support the implementation of cybersecurity tools in collaboration with the IT team (e.g., Intunes).
Assist in improving processes related to change management, access management, and general technology controls.
Employee Awareness and Training
Promote information security awareness across the organization.
Manage and deliver security and privacy training programs.
Key Achievements Expected
Ensure successful completion of audits related to ISO 27001, HIPAA, and SOC 2.
Support FDA clearance for products by contributing to cybersecurity documentation.
Implement and maintain an effective ISMS (Information Security Management System).
Identify vulnerabilities and ensure timely remediation.
Skills and Expertise
Strong interest in healthcare and regulatory compliance.
Experience in developing and managing process documents, especially in the medical device industry.
Proven ability to work independently and collaboratively in a fast-paced environment.
Familiarity with regulatory frameworks, including ISO 27001, HIPAA, SOC 2, FDA, MDSAP, and QMS.
Excellent communication and organizational skills.