Lead Governance, Risk & Compliance- IT (JB 9)
Job Summary
The Lead GRC is responsible for implementing the organizations Information Security Program across business units to ensure it operates effectively efficiently and in compliance with relevant regulations policies and standards. This role involves proactive monitoring and analysis of security events and alerts taking immediate actions to contain incidents and minimize potential damage. Additionally the Lead GRC participates in technology scanning evaluates new security solutions and recommends implementations to reduce overall cyber risk thereby supporting a resilient and compliant security posture aligned with organizational objectives.
Cement Business has enhanced its capacity to 180 mtpa in recent years. As a business enabler Information Technology plays an important role in facilitating business plans. With increasing demands for flexibility and mobility in information access the exposure to security vulnerabilities has escalated. Information is a vital business asset that requires protection to maintain availability integrity and confidentiality critical to business success. Robust Information Security policies procedures and guidelines are essential to govern people processes and technology effectively.
To uphold compliance with industry standards the Lead GRC must ensure stringent implementation and monitoring of ISMS programs across all units. This includes managing internal and external audits while continuously identifying and mitigating risks in an evolving technology landscape. The role demands coordination across dispersed locations vigilant governance and proactive risk management to support a strong and resilient security posture aligned with organizational objectives.
Major Challenges:
- Keeping pace with evolving regulatory requirements and emerging cyber threats while ensuring consistent compliance across multiple locations and business units.
- Coordinating effective governance and risk management programs in a complex operational environment overcoming resistance to change and driving security awareness among diverse stakeholders.
4) KeyResultAreas/Accountabilities: | |
KeyResult Areas/Accountabilities | Supporting Actions |
|
|
Risk Management |
|
Compliance Management |
|
User Awareness and Training |
|
Technology Evaluation and Vendor Coordination |
|
6)Relationships: | |||
Relationship Type (InternalorExternal) | Frequency & Nature | ||
Internal | |||
Business Functions | Regular | Understand key security concerns compliance requirement and provide solution/suggestions as applicable | |
Plant Instrumentation Teams | Regular | Understand existing Cyber Security risks and compliance requirements on OT systems and provide necessary guidelines & support in implementation | |
DIT Team | Regular | Keeping them updated on existing risks and guiding for better security posture | |
Group IT | Regular | For inputs validation POC & implementation | |
External | |||
Consultants | Regular | For getting inputs on best practices | |
Vendors | Regular | For execution of IS projects | |
3rd party Service Providers | Periodic | Security Compliance Audit | |
Dealers Transporters | Periodic | To provide Info Sec awareness | |
Industry Peers | Regular | For information sharing on latest IS happenings benchmarking | |
Required Experience:
Manager
About Company
Discover a world of financial solutions at Aditya Birla Capital – your trusted partner for investments, insurance, loans, and a wide range of financial services in India.