Now hiring

Lead - IT Governance @ Godrej Industries

INOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

Job Requirements Provide independent governance and assurance over the NBFC’s technology environment—separate from the IT line—to ensure end‑to‑end compliance with RBI IT Governance, Risk, Controls & Assurance Practices and RBI Outsourcing of IT Services directions, while aligning technology risk management to business objectives and risk appetite. This role reviews, challenges, and validates the effectiveness of IT controls, outsourcing practices (including cloud / SOC), and resilience measures. Key Responsibilities 1. Independent IT Governance Oversight Operate as an independent checker over IT’s policies, standards, and controls; ensure the organization’s IT Governance Framework addresses strategic alignment, risk management, resource/performance management, and BCP/DR as required by RBI’s IT RBI Master Directions, DPDP Act and other applicable regulations 2. RBI Compliance a. Maintain a compliance inventory and gap log, drive remediation with accountable owners in IT/InfoSec b. Establish and oversee (2LoD) adherence to a Board‑approved IT Outsourcing Policy, c. Verify a central inventory of all IT outsourcing arrangements (materiality classification), due diligence, and contractual safeguards (audit & inspection rights, confidentiality & data protection, data residency/sovereignty, regulatory access, subcontracting controls, BCP/DR, exit/termination, SLA/OLA, performance & risk KRIs) d. Ensure compliance with legacy and new agreements with specific compliance windows for renewals/new contracts) e. Oversee cross‑border outsourcing risk assessments and controls; ensure cloud usage aligns with Appendix I (controls, location/sovereignty, monitoring) and SOC outsourcing aligns with Appendix II (governance, log ownership, response SLAs) f. Change, Access & Ops Oversight (Non‑Execution) g. Independently review change management artefacts (risk impact, approvals, testing, rollback, post‑implementation validations) and patch governance timeliness for critical vulnerabilities h. Check effectiveness of privileged access controls, SoD, recertifications, and teleworking controls per the Master Direction i. Validate the adequacy of audit trails/logging and monitoring for systems handling critical/sensitive information j. Review IS/Cyber policies, risk assessments, VA/PT cadence, and incident response/CCMP execution, including regulatory reporting readiness as per the Master Direction k. Track KRI/KCI thresholds for cyber/IT risks; escalate breaches per risk appetite to relevant authorities l. BCP/DR & Resilience Assurance m. Oversee the BCP/DR testing calendar, scenario coverage, achievement of RPO/RTO as stipulated

Work Experience 8–10 years

Skills

it governancerisk managementcompliance oversightcloud outsourcingdata protectionaudit trailschange managementproject governancegovernancetechskillsrisk controlbusiness continuity planningperformance managementstakeholder communicationregulatory reporting

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores