Innovate in Bengaluru
This position is based at our on-site office in Bengaluru. Lowe's offers an ultramodern work environment, complete with cutting-edge technology, collaborative workspaces, an on-site gym and clinic, and other perks to enhance your work experience.
About Lowe’s
Lowe's Companies, Inc. (NYSE: LOW) is a FORTUNE® 100 home improvement company serving approximately 16 million customer transactions a week, with total fiscal year 2024 sales of more than $83 billion. Lowe's employs approximately 300,000 associates and operates over 1,700 home improvement stores, 530 branches and 130 distribution centers. Based in Mooresville, N.C., Lowe's supports the communities it serves through programs focused on creating safe, affordable housing, improving community spaces, helping to develop the next generation of skilled trade experts and providing disaster relief to communities in need. For more information, visit Lowes.com.
At Lowe's India, we are the enablers who help create an engaging customer experience for our $90+ billion home improvement business at Lowe's. Our 4000+ associates work across technology, analytics, business operations, finance & accounting, product management, and shared services. We leverage new technologies and find innovative methods to ensure that Lowe's has a competitive edge in the market. To know more about Lowe's India, visit Lowes.co.in
Job Summary
The Governance Analyst supports the lifecycle management of Information Security and Technology policies, standards, procedures, guidelines, and related governance artifacts. The role works closely with document owners, subject matter experts, Risk, Compliance, Audit, Legal, Technology, and other stakeholders to help ensure governance documents remain current, consistent, traceable, and appropriately maintained.
The Analyst will support routine governance activities independently while escalating complex policy, risk, regulatory, or technical matters as appropriate.
Key Responsibilities
Support the end-to-end lifecycle of policies, standards, procedures, and guidelines, including drafting, review, renewal, approval, publication, and retirement.
Coordinate periodic document reviews and change requests, including stakeholder engagement, feedback tracking, follow-ups, approvals, and finalization.
Review governance documents for clarity, consistency, completeness, duplication, conflicting requirements, ownership, and alignment with related policies, standards, and controls.
Work with subject matter experts to understand business, security, audit, regulatory, or risk-driven changes and incorporate agreed updates into governance documents.
Support requirement-to-control and framework mappings and help identify potential gaps or inconsistencies in governance coverage.
Maintain governance records and lifecycle information, including document ownership, versions, review dates, change history, approvals, action items, and supporting evidence.
Use GRC (governance, risk, compliance) and document management platforms such as LogicGate, ServiceNow GRC, Archer, SharePoint, Confluence, or similar tools to support governance workflows and maintain audit-ready records.
Monitor review schedules, outstanding actions, approvals, and change requests; proactively follow-up and escalate delays or dependencies where needed.
Prepare governance trackers, dashboards, metrics, meeting notes, change summaries, and status updates for stakeholders and leadership.
Identify opportunities to improve governance processes, templates, workflows, reporting, and automation.
Support governance, audit, risk, and compliance activities by providing policy documentation, traceability, and related evidence as required.
Required Qualifications
Bachelor’s degree in technology or relevant field is preferred; or an equivalent combination of education, professional certifications, training, and relevant work experience will also be considered.
2-5 years of relevant experience in Information Security Governance, Policy Management, GRC, Risk, Compliance, Audit, Cybersecurity, Data Governance, or related areas.
Understanding of policies, standards, procedures, controls, risks, and governance lifecycle concepts.
Strong written and verbal communication skills.
Strong analytical, organizational, and documentation skills with attention to detail.
Ability to manage multiple priorities and coordinate effectively with technical and non-technical stakeholders.
Proficiency with Microsoft Word, Excel, PowerPoint, and related productivity tools.
Preferred Qualifications
Experience supporting policy or standards lifecycle management.
Familiarity with security frameworks such as NIST CSF, ISO 27001, COBIT, CIS Controls, or similar frameworks.
General awareness of regulatory and compliance requirements such as SOX, PCI DSS, or privacy requirements.
Experience with GRC platforms such as LogicGate, Archer, ServiceNow GRC, or similar tools.
Experience with SharePoint, Confluence, Power BI, or other document management and reporting tools.
Exposure to control mapping, gap analysis, audit support, or compliance documentation.
Relevant certifications such as Security+, ISO 27001 LA/LE, CISA, CISM, CRISC, or CGRC are beneficial but not mandatory.
Key Competencies
Policy and Standards Management
Analytical Thinking
Stakeholder Coordination
Governance Operations
Written Communication
Risk and Control Awareness
Planning and Prioritization
Attention to Detail
Continuous Improvement
Lowe's is an equal opportunity employer and administers all personnel practices without regard to race, color, religious creed, sex, gender, age, ancestry, national origin, mental or physical disability or medical condition, sexual orientation, gender identity or expression, marital status, military or veteran status, genetic information, or any other category protected under federal, state, or local law.