Lead - Information Security and GRC

Birla Carbon

Maharashtra

On-site

INR 3,000,000 - 6,000,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Aditya Birla Group is seeking a Lead - Information Security and GRC in Thane, India. You will own enterprise information security governance, risk management, policy development and regulatory compliance across multiple IT domains.

The role requires coordinating security assessments, threat modelling, DevSecOps integration, cloud and infrastructure security, and incident management while driving continuous improvement and executive reporting.

Responsibilities

  • Own and operate the Enterprise Information Security Governance & IT Risk Management program aligned to ISO 27001:2022, NIST CSF and DPDP Act.
  • Develop, review and renew policies, standards and SOPs; maintain the policy renewal tracker and secure stakeholder/management approvals.
  • Evaluate the organization’s security posture periodically and report to stakeholders.
  • Conduct InfoSec assessments for new/existing projects and applications on a Secure-by-Design basis — review architecture, data flows and controls, and perform threat modelling.
  • Assess controls, identify gaps, provide residual-risk assessments and track risk-treatment actions.
  • Validate implementation (controls, VAPT, secure code review, logging/monitoring) and provide initial and final production sign-offs.
  • Govern application & API security — assess against InfoSec/AppSec checklists, oversee VA, PT and secure code reviews, and drive DevSecOps integration.
  • Maintain MBSS / Secure Configuration Documents (SCD); oversee configuration VA and compliance reviews.
  • Maintain infrastructure security baselines, assess assets periodically, track and close observations with stakeholders.
  • Lead the Enterprise Vulnerability Management program across applications, infrastructure and configurations.
  • Prioritise vulnerabilities by severity, business impact and exploitability; manage exceptions and track closure of identified risks.
  • Monitor remediation progress and ensure timely closure and reporting.
  • Implement and oversee cloud security best practices across AWS & Azure — IAM, encryption, network security and logging.
  • Conduct cloud security, gap and compliance assessments for IaaS/PaaS/SaaS and remediate misconfigurations.
  • Monitor and manage CNAPP tooling (CSPM, CIEM, CWPP) for continuous cloud posture management.
  • Govern SIEM/SOC monitoring — asset onboarding, monthly reconciliation, use-case/detection enhancement and alert triage & closure.
  • Oversee operational management of security tools (SIEM, EDR, DLP, WAF, IDS/IPS).
  • Own incident management — detection, RCA, mitigation, monthly incident reporting and a learning matrix driving preventive controls.
  • Manage internal, statutory, regulatory and certification audits — coordinate evidence, provide management responses/remediation plans and track observations to closure.
  • Address queries from Compliance, Internal/External Audit and Regulators; implement policy/process updates for regulatory changes.
  • Participate in CAB and assess the security implications of planned and emergency changes.
  • Maintain the annual DR drill calendar and secure committee approvals; govern DR drills for critical applications/infrastructure.
  • Validate RTO/RPO achievement, close DR observations and maintain DR documentation for audit/regulatory purposes (BIA, BCRA, FRP, IT DR drills).
  • Drive Vendor Risk Assessment (VRA) and TPRM — maintain vendor inventory & criticality and the annual review calendar.
  • Ensure timely completion of vendor assessments, review risk ratings and track closure of identified risks.
  • Run monthly awareness campaigns, annual training and phishing simulations with targeted remediation; execute annual CCMP tabletop / IR simulations.
  • Prepare and present ITSC, IT Strategy Committee, RMC and Board reporting — InfoSec metrics, risk dashboards, KPI/KRI, compliance and audit status, and incident summaries; track decisions and action closure.

Job description

At the Aditya Birla Group, our Corporate Vision is aligned and intricately woven with our People Vision.

Lead - Information Security and GRC

Designation :

Location : India Maharashtra G-Corp Tech Park, Thane

Job Description:
Job Description

4) Key Result Areas

Key results expected from the job and the supporting actions for each key result area.

Key Result Areas

Supporting Actions

ISMS & Security Governance

  • Own and operate the Enterprise Information Security Governance & IT Risk Management program aligned to ISO 27001:2022, NIST CSF and DPDP Act.
  • Develop, review and renew policies, standards and SOPs; maintain the policy renewal tracker and secure stakeholder/management approvals.
  • Evaluate the organization’s security posture periodically and report to stakeholders.

Security Assessment & Technology Due Diligence

  • Conduct InfoSec assessments for new/existing projects and applications on a Secure-by-Design basis — review architecture, data flows and controls, and perform threat modelling.
  • Assess controls, identify gaps, provide residual-risk assessments and track risk-treatment actions.
  • Validate implementation (controls, VAPT, secure code review, logging/monitoring) and provide initial and final production sign-offs.

Application, API & Infrastructure Security

  • Govern application & API security — assess against InfoSec/AppSec checklists, oversee VA, PT and secure code reviews, and drive DevSecOps integration and application-layer attack mitigation.
  • Maintain MBSS / Secure Configuration Documents (SCD); oversee configuration VA and compliance reviews.
  • Maintain infrastructure security baselines, assess assets periodically, track and close observations with stakeholders.

Enterprise Vulnerability Management

  • Lead the Enterprise Vulnerability Management program across applications, infrastructure and configurations.
  • Prioritise vulnerabilities by severity, business impact and exploitability; manage exceptions and track closure of identified risks.
  • Monitor remediation progress and ensure timely closure and reporting.

Cloud Security Governance

  • Implement and oversee cloud security best practices across AWS & Azure — IAM, encryption, network security and logging.
  • Conduct cloud security, gap and compliance assessments for IaaS/PaaS/SaaS and remediate misconfigurations.
  • Monitor and manage CNAPP tooling (CSPM, CIEM, CWPP) for continuous cloud posture management.

Security Operations, SIEM & Incident Management

  • Govern SIEM/SOC monitoring — asset onboarding, monthly reconciliation, use-case/detection enhancement and alert triage & closure.
  • Oversee operational management of security tools (SIEM, EDR, DLP, WAF, IDS/IPS).
  • Own incident management — detection, RCA, mitigation, monthly incident reporting and a learning matrix driving preventive controls.

Audit, Compliance & Regulatory Management

  • Manage internal, statutory, regulatory and certification audits — coordinate evidence, provide management responses/remediation plans and track observations to closure.
  • Address queries from Compliance, Internal/External Audit and Regulators; implement policy/process updates for regulatory changes.
  • Participate in CAB and assess the security implications of planned and emergency changes.

Business Continuity & Disaster Recovery

  • Maintain the annual DR drill calendar and secure committee approvals; govern DR drills for critical applications/infrastructure.
  • Validate RTO/RPO achievement, close DR observations and maintain DR documentation for audit/regulatory purposes (BIA, BCRA, FRP, IT DR drills).

Third-Party Risk & Vendor Governance

  • Drive Vendor Risk Assessment (VRA) and TPRM — maintain vendor inventory & criticality and the annual review calendar.
  • Ensure timely completion of vendor assessments, review risk ratings and track closure of identified risks.

Awareness, Resilience & Executive Reporting

  • Run monthly awareness campaigns, annual training and phishing simulations with targeted remediation; execute annual CCMP tabletop / IR simulations.
  • Prepare and present ITSC, IT Strategy Committee, RMC and Board reporting — InfoSec metrics, risk dashboards, KPI/KRI, compliance and audit status, and incident summaries; track decisions and action closure.
  • Discover more about life at Aditya Birla Group
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead - Information Security and GRC
Lead - Information Security and GRC

ABC - Aditya Birla Housing Finance Limited • Maharashtra

On-site
INR 2,400,000 - 4,200,000
Lead - Information Security and GRC
Lead - Information Security and GRC

ABC - Aditya Birla Housing Finance Limited • Maharashtra

On-site
INR 1,200,000 - 1,800,000
Team Lead - Information Security
Team Lead - Information Security

Birla Carbon • Mumbai

On-site
INR 2,600,000 - 4,200,000
Manager - Information Security
Manager - Information Security

Birla Carbon • Mumbai

On-site
INR 1,500,000 - 2,100,000
Module Lead Information Security
Module Lead Information Security

IDfy • Mumbai

On-site
INR 350,000 - 550,000
Lead - Internal Audit
Lead - Internal Audit

Birla Carbon • India

On-site
INR 1,800,000 - 2,400,000
Lead - Cybersecurity
Lead - Cybersecurity

Adani Group • Rangareddy

On-site
INR 4,000,000 - 7,000,000
Lead - Offsite Audit & Continuous Control Monitoring
Lead - Offsite Audit & Continuous Control Monitoring

Birla Carbon • India

On-site
INR 2,500,000 - 4,000,000
Information Security Specialist
Information Security Specialist

Birla Carbon • Mumbai

On-site
INR 1,200,000 - 1,800,000
Senior Role - GRC & Infosec
Senior Role - GRC & Infosec

NPCI Bharat BillPay Limited • Mumbai

On-site
INR 2,000,000 - 3,000,000