Lead - Information Security and GRC

Aditya Birla Insulators

Thane

On-site

INR 1,800,000 - 3,000,000

Full time

8 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Aditya Birla Insulators is seeking an experienced information security leader to own and operate the enterprise security program. The role requires aligning governance to ISO 27001:2022, NIST CSF and regulatory requirements, driving threat modelling, policy management and risk remediation.

The incumbent will oversee cloud security across AWS/Azure, vulnerability management, SIEM/EDR/DLP, and incident response, while coordinating audits and business continuity planning.

Qualifications

  • Own and operate the Enterprise Information Security Governance program aligned to ISO 27001:2022 and NIST CSF.
  • Develop, review and renew policies, standards and SOPs; maintain the policy renewal tracker and secure stakeholder/management approvals.
  • Evaluate the organization s security posture periodically and report to stakeholders.
  • Lead threat modelling and secure design reviews for new/existing projects.
  • Oversee incident management, logging, monitoring and learning from incidents.
  • Manage audits, regulatory requirements and certification processes; coordinate responses.
  • Drive cloud security and risk remediation; oversee CNAPP tooling and posture management.
  • Plan and govern business continuity and disaster recovery readiness.

Responsibilities

  • Govern application, API and infrastructure security across DevSecOps practices.
  • Lead enterprise vulnerability management program and remediate findings.
  • Maintain cloud security posture across AWS and Azure, including IAM and encryption.
  • Oversee SIEM/EDR/DLP/WAF tooling, incident detection and response processes.
  • Coordinate internal, statutory and regulatory audits and track remediation actions.
  • Drive third‑party risk assessments and vendor governance programs.
  • Produce executive IT security metrics, risk dashboards and compliance reporting.

Job description

Job Description

4) Key Result Areas

Key results expected from the job and the supporting actions for each key result area.

Key Result Areas

Supporting Actions

ISMS & Security Goverce

  • Own and operate the Enterprise Information Security Goverce & IT Risk Management program aligned to ISO 27001:2022, NIST CSF and DPDP Act.
  • Develop, review and renew policies, standards and SOPs; maintain the policy renewal tracker and secure stakeholder/management approvals.
  • Evaluate the organization s security posture periodically and report to stakeholders.

Security Assessment & Technology Due Diligence

  • Conduct InfoSec assessments for new/existing projects and applications on a SecurebyDesign basis review architecture, data flows and controls, and perform threat modelling.
  • Assess controls, identify gaps, provide residualrisk assessments and track risktreatment actions.
  • Validate implementation (controls, VAPT, secure code review, logging/monitoring) and provide initial and final production signoffs.

Application, API & Infrastructure Security

  • Govern application & API security assess against InfoSec/AppSec checklists, oversee VA, PT and secure code reviews, and drive DevSecOps integration and applicationlayer attack mitigation.
  • Maintain MBSS / Secure Configuration Documents (SCD); oversee configuration VA and compliance reviews.
  • Maintain infrastructure security baselines, assess assets periodically, track and close observations with stakeholders.

Enterprise Vulnerability Management

  • Lead the Enterprise Vulnerability Management program across applications, infrastructure and configurations.
  • Prioritise vulnerabilities by severity, business impact and exploitability; manage exceptions and escalated overdue items.
  • Monitor remediation progress and ensure timely closure and reporting.

Cloud Security Goverce

  • Implement and oversee cloud security best practices across AWS & Azure IAM, encryption, network security and logging.
  • Conduct cloud security, gap and compliance assessments for IaaS/PaaS/SaaS and remediate misconfigurations.
  • Monitor and manage CNAPP tooling (CSPM, CIEM, CWPP) for continuous cloud posture management.

Security Operations, SIEM & Incident Management

  • Govern SIEM/SOC monitoring asset onboarding, monthly reconciliation, usecase/detection enhancement and alert triage & closure.
  • Oversee operational management of security tools (SIEM, EDR, DLP, WAF, IDS/IPS).
  • Own incident management detection, RCA, mitigation, monthly incident reporting and a learning matrix driving preventive controls.

Audit, Compliance & Regulatory Management

  • Manage internal, statutory, regulatory and certification audits coordinate evidence, provide management responses/remediation plans and track observations to closure.
  • Address queries from Compliance, Internal/External Audit and Regulators; implement policy/process updates for regulatory changes.
  • Participate in CAB and assess the security implications of planned and emergency changes.

Business Continuity & Disaster Recovery

  • Maintain the annual DR drill calendar and secure committee approvals; govern DR drills for critical applications/infrastructure.
  • Validate RTO/RPO achievement, close DR observations and maintain DR documentation for audit/regulatory purposes (BIA, BCRA, FRP, IT DR drills).

ThirdParty Risk & Vendor Goverce

  • Drive Vendor Risk Assessment (VRA) and TPRM maintain vendor inventory & criticality and the annual review calendar.
  • Ensure timely completion of vendor assessments, review risk ratings and track closure of identified risks.

Awareness, Resilience & Executive Reporting

  • Run monthly awareness campaigns, annual training and phishing simulations with targeted remediation; execute annual CCMP tabletop / IR simulations.
  • Prepare and present ITSC, IT Strategy Committee, RMC and Board reporting InfoSec metrics, risk dashboards, KPI/KRI, compliance and audit status, and incident summaries; track decisions and action closure.

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead - Information Security and GRC
Lead - Information Security and GRC

ABC - Aditya Birla Housing Finance Limited • Maharashtra

On-site
INR 2,400,000 - 4,200,000
Sr Security GRC & ISO 27001 Manager
Sr Security GRC & ISO 27001 Manager

UST • Thiruvananthapuram

On-site
INR 2,500,000 - 4,000,000
Senior Manager - IT GRC
Senior Manager - IT GRC

PNB Housing • Dadri

On-site
INR 1,200,000 - 1,800,000
Deputy General Manager-GRC
Deputy General Manager-GRC

SupportFinity™ • Ahmedabad District

On-site
INR 1,200,000 - 2,000,000
Information Technology Security Specialist
Information Technology Security Specialist

Senvion India • Mumbai

On-site
INR 2,500,000 - 4,200,000
Sr Lead - IT Risk & GRC
Sr Lead - IT Risk & GRC

Star Union Dai-ichi Life Insurance Company Limited • Navi Mumbai

On-site
INR 1,500,000 - 2,500,000
Senior Security GRC & ISO 27001 Manager
Senior Security GRC & ISO 27001 Manager

UST • Thiruvananthapuram

On-site
INR 1,500,000 - 2,100,000
Assistant Vice President – Information Security
Assistant Vice President – Information Security

IndiaFirst Life • Mumbai

On-site
INR 1,000,000 - 1,500,000
Security, Risk & Compliance Lead
Security, Risk & Compliance Lead

RedDoorz • Dadri

On-site
INR 2,400,000 - 4,800,000
Information Security Manager
Information Security Manager

Dmi Finance • Dadri, Delhi

On-site
INR 1,200,000 - 1,800,000