Enter a job title or keyword

Lead Governance, Risk & Compliance- IT (JB 9)

Cement


Job Location:

Mumbai - India

Monthly Salary: Not provided by the employer
Posted: 3 July 2026 (30+ days ago)
Application Deadline: 30 September 2026
Vacancies: 1 Vacancy

Job Summary

Job Purpose

The Lead GRC is responsible for implementing the organizations Information Security Program across business units to ensure it operates effectively efficiently and in compliance with relevant regulations policies and standards. This role involves proactive monitoring and analysis of security events and alerts taking immediate actions to contain incidents and minimize potential damage. Additionally the Lead GRC participates in technology scanning evaluates new security solutions and recommends implementations to reduce overall cyber risk thereby supporting a resilient and compliant security posture aligned with organizational objectives.

Job Context & Major Challenges

Cement Business has enhanced its capacity to 180 mtpa in recent years. As a business enabler Information Technology plays an important role in facilitating business plans. With increasing demands for flexibility and mobility in information access the exposure to security vulnerabilities has escalated. Information is a vital business asset that requires protection to maintain availability integrity and confidentiality critical to business success. Robust Information Security policies procedures and guidelines are essential to govern people processes and technology effectively.

To uphold compliance with industry standards the Lead GRC must ensure stringent implementation and monitoring of ISMS programs across all units. This includes managing internal and external audits while continuously identifying and mitigating risks in an evolving technology landscape. The role demands coordination across dispersed locations vigilant governance and proactive risk management to support a strong and resilient security posture aligned with organizational objectives.

Major Challenges:

  • Keeping pace with evolving regulatory requirements and emerging cyber threats while ensuring consistent compliance across multiple locations and business units.
  • Coordinating effective governance and risk management programs in a complex operational environment overcoming resistance to change and driving security awareness among diverse stakeholders.
Key Result Areas

4) KeyResultAreas/Accountabilities:

KeyResult Areas/Accountabilities

Supporting Actions

  • Governance

  • Establish and maintain effective governance structures to drive Information Security across the organization.
  • Develop communicate and oversee implementation of security procedures and guidelines aligned with the Information Security Policy for all stakeholders.
  • Identify and implement process improvements within the GRC framework to enhance effectiveness and efficiency.
  • Assist units in preparing for and maintaining IS compliance and ISO 27001 certification; develop mechanisms to monitor and report security control status.
  • Monitor security events from various tools ensure completion of root cause analysis and recommend remediation actions.
  • Preparing budget and tracking spend

Risk Management

  • Develop implement and continuously improve a comprehensive risk management framework aligned with organizational objectives.
  • Identify assess prioritize and report risks to senior management and stakeholders while working with relevant teams to develop mitigation strategies.
  • Manage and maintain the Risk Register and ensure timely tracking and closure of risk mitigation plans.

Compliance Management

  • Stay informed on regulatory changes impacting the organizations security and privacy environment.
  • Develop and implement compliance programs and related processes to meet applicable standards and regulatory requirements.
  • Plan coordinate and support internal and external information security audits across units and offices to ensure adherence to compliance requirements.
  • Compile and analyze audit findings identify focus areas derive actionable plans and track observations through closure.
  • Periodically review and update audit checklists based on relevant control frameworks and evolving industry standards.

User Awareness and Training

  • Develop coordinate and deliver targeted training programs to educate employees on cybersecurity risks compliance requirements and their roles in maintaining a secure environment.
  • Continuously evaluate organizational training needs related to cyber risk and compliance and implement improved communication methods including advisories mailers and mobile notifications.
  • Promote a culture of security awareness among internal users and the third-party ecosystem through regular communication and engagement initiatives.

Technology Evaluation and Vendor Coordination

  • Remain up to date on emerging information security trends technologies and solutions to address evolving risks.
  • Engage with vendors and customers to evaluate new security technologies coordinate proof of concepts (POCs) with internal teams and provide objective technical comparisons and recommendations.
  • Support the CISO in selecting and implementing technologies to strengthen the overall cybersecurity posture and reduce cyber risk.

6)Relationships:

Relationship Type (InternalorExternal)

Frequency & Nature

Internal

Business Functions

Regular

Understand key security concerns compliance requirement and provide solution/suggestions as applicable

Plant Instrumentation Teams

Regular

Understand existing Cyber Security risks and compliance requirements on OT systems and provide necessary guidelines & support in implementation

DIT Team

Regular

Keeping them updated on existing risks and guiding for better security posture

Group IT

Regular

For inputs validation POC & implementation

External

Consultants

Regular

For getting inputs on best practices

Vendors

Regular

For execution of IS projects

3rd party Service Providers

Periodic

Security Compliance Audit

Dealers Transporters

Periodic

To provide Info Sec awareness

Industry Peers

Regular

For information sharing on latest IS happenings benchmarking







Required Experience:

Manager


About Company

Company Logo

Discover a world of financial solutions at Aditya Birla Capital – your trusted partner for investments, insurance, loans, and a wide range of financial services in India.

View Profile View Profile