Senior Security & Compliance Analyst

Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in cybersecurity, risk management, or compliance roles.
  • Experience supporting cybersecurity audits or compliance certifications.
  • Familiarity with standards like TISAX, ISO 27001, and SOC 2.
  • Understanding of risk assessment methodologies related to cybersecurity.
  • Knowledge of Microsoft security tools and cloud security concepts.
  • Strong analytical skills with the capability to manage multiple projects effectively.
  • Excellent communication skills for interaction with technical and non-technical stakeholders.

Responsibilities

  • Coordinate TISAX assessments and ongoing compliance monitoring.
  • Serve as the regional coordinator for cybersecurity compliance initiatives.
  • Support the implementation of corporate cybersecurity policies and standards.
  • Act as a liaison between regional teams and the corporate cybersecurity team in Japan.
  • Assist in interpreting and implementing cybersecurity requirements for business units.
  • Conduct risk assessments and track compliance gaps to management.
  • Support internal/external audits, ensuring adherence to security guidelines.

Benefits

  • Collaborative work environment with a focus on professional development.
  • Opportunity to engage with a global cybersecurity team in a multi-site organization.
  • Involvement in comprehensive cybersecurity initiatives and various compliance activities.
  • Experience in cutting-edge security technologies and frameworks like TISAX and ISO 27001.
  • Flexibility to work on diverse projects that have significant organizational impact.
Full Job Description
Job Title: Senior Security & Compliance Analyst

Company: AISIN World Corp. of America

Department: DX Infrastructure and Security

Location: Northville, MI or Seymour, IN

Position Responsibilities

The incumbent is expected to perform the following functions that the company has determined are essential to this position:
  • Coordinate and support TISAX assessment, certification, and recertification activities, including control reviews, evidence collection, remediation tracking, and ongoing compliance monitoring. Support SOC audits and related compliance activities as required.
  • Serve as the regional coordinator for cybersecurity compliance initiatives and assessments.
  • Support the implementation, adoption, and sustainment of cybersecurity policies, standards, guidelines, and initiatives deployed by the corporate security organization in Japan.
  • Work closely with affiliated companies to ensure alignment with corporate cybersecurity requirements and governance expectations.
  • Act as a liaison between the regional organizations and the corporate cybersecurity team in Japan regarding security policies, compliance requirements, and security initiatives.
  • Assist business units and IT teams in interpreting and implementing cybersecurity requirements and standards.
  • Support internal and external cybersecurity audits, assessments, surveys, and regulatory compliance activities.
  • Maintain and improve cybersecurity governance documentation, procedures, standards, and control frameworks.
  • Conduct cybersecurity risk assessments and assist in the development of risk mitigation plans.
  • Track, document, and report cybersecurity risks, compliance gaps, and remediation activities to management.
  • Support security awareness and compliance training activities across the region.
  • Monitor industry trends, regulatory requirements, and cybersecurity best practices and provide recommendations for continuous improvement.
  • Collaborate with infrastructure, application, and business teams to ensure security controls are effectively implemented.
  • Assist with the implementation and administration of corporate cybersecurity tools and technologies.
  • Support security operations, vulnerability management, and incident response activities as required.
  • Assist with Microsoft security technologies including Intune, Conditional Access, Multi-Factor Authentication (MFA), Microsoft Defender, and Exchange Online Protection.
  • Support investigations of security events and assist with remediation activities when required.
  • Prepare reports, metrics, and documentation related to cybersecurity compliance, TISAX readiness, and security program effectiveness.
  • Other tasks and duties as assigned.


Required Skills and Abilities

Essential Skills and Experience:
  • 5+ years of experience in cybersecurity, information security governance, risk management, compliance, or security operations.
  • Experience supporting cybersecurity compliance programs, audits, or certification activities.
  • Familiarity with cybersecurity frameworks and standards such as TISAX, ISO 27001, SOC 2, NIST CSF, and related control frameworks.
  • Understanding of cybersecurity risk assessment methodologies and governance processes.
  • Working knowledge of Microsoft security technologies and cloud security concepts.
  • Understanding of network, endpoint, and identity security principles.
  • Strong analytical and problem-solving skills.
  • Strong organizational skills with the ability to manage multiple compliance and security initiatives simultaneously.
  • Strong written and verbal communication skills.
  • Ability to work effectively with global teams and non-technical business stakeholders.
  • Ability to work independently with limited supervision.


Beneficial Skills and Experience
  • Experience supporting TISAX certification or recertification activities.
  • Experience working within global or multi-site organizations.
  • Experience with Trend Micro Apex One, Microsoft Intune, and Entra ID.
  • Experience supporting ISO 27001 or SOC audits or information security management systems.
  • Knowledge of automotive manufacturing industry requirements.
  • Experience coordinating cybersecurity initiatives across multiple subsidiaries or affiliated companies.
  • Demonstrated commitment to continuous learning and professional development.


Education/Training/Certifications
  • Bachelor's degree in IT, Cybersecurity, Information Systems, or related field, or equivalent experience.
  • One or more cybersecurity-related certifications preferred:
    • Security+
    • SC-200
    • SC-300
    • CISSP
    • CISM
    • ISO 27001 Lead Implementer / Lead Auditor
    • TISAX-related training or certification (preferred)


Travel Requirements
  • Approximately 30 %.
  • Must be willing and available to travel to such locations and with such frequency as is necessary and desirable to meet business needs.


Work Environment Requirements

With reasonable accommodation:
  • Must be able to operate a personal computer, telephone, and other office equipment.
  • Must perform job duties onsite, when necessary, except those duties that are customarily or by their nature performed offsite (for example, offsite customer visits).
  • Must be able to work effectively in a fast-paced environment.
  • Must be able to work on multiple assignments at once, and complete assignments within deadline and budget (if applicable) with satisfactory quality.
  • Must be able to operate as an effective team member.
  • Must be committed to a high standard of safety and be willing and able to comply with all safety laws and all company safety policies.


Attendance/Work Hour Requirements
  • Must maintain an acceptable attendance record.
  • Must be willing and available to work weekends and holidays as necessary and desirable to meet business needs.

Similar Jobs

More Jobs at AISIN North Carolina Corporation

More Information Technology Jobs

Find similar Senior Security & Compliance Analyst jobs: