Job Title: Senior Security & Compliance Analyst
Company: AISIN World Corp. of America
Department: DX Infrastructure and Security
Location: Northville, MI or Seymour, IN
Position ResponsibilitiesThe incumbent is expected to perform the following functions that the company has determined are essential to this position:
- Coordinate and support TISAX assessment, certification, and recertification activities, including control reviews, evidence collection, remediation tracking, and ongoing compliance monitoring. Support SOC audits and related compliance activities as required.
- Serve as the regional coordinator for cybersecurity compliance initiatives and assessments.
- Support the implementation, adoption, and sustainment of cybersecurity policies, standards, guidelines, and initiatives deployed by the corporate security organization in Japan.
- Work closely with affiliated companies to ensure alignment with corporate cybersecurity requirements and governance expectations.
- Act as a liaison between the regional organizations and the corporate cybersecurity team in Japan regarding security policies, compliance requirements, and security initiatives.
- Assist business units and IT teams in interpreting and implementing cybersecurity requirements and standards.
- Support internal and external cybersecurity audits, assessments, surveys, and regulatory compliance activities.
- Maintain and improve cybersecurity governance documentation, procedures, standards, and control frameworks.
- Conduct cybersecurity risk assessments and assist in the development of risk mitigation plans.
- Track, document, and report cybersecurity risks, compliance gaps, and remediation activities to management.
- Support security awareness and compliance training activities across the region.
- Monitor industry trends, regulatory requirements, and cybersecurity best practices and provide recommendations for continuous improvement.
- Collaborate with infrastructure, application, and business teams to ensure security controls are effectively implemented.
- Assist with the implementation and administration of corporate cybersecurity tools and technologies.
- Support security operations, vulnerability management, and incident response activities as required.
- Assist with Microsoft security technologies including Intune, Conditional Access, Multi-Factor Authentication (MFA), Microsoft Defender, and Exchange Online Protection.
- Support investigations of security events and assist with remediation activities when required.
- Prepare reports, metrics, and documentation related to cybersecurity compliance, TISAX readiness, and security program effectiveness.
- Other tasks and duties as assigned.
Required Skills and AbilitiesEssential Skills and Experience:
- 5+ years of experience in cybersecurity, information security governance, risk management, compliance, or security operations.
- Experience supporting cybersecurity compliance programs, audits, or certification activities.
- Familiarity with cybersecurity frameworks and standards such as TISAX, ISO 27001, SOC 2, NIST CSF, and related control frameworks.
- Understanding of cybersecurity risk assessment methodologies and governance processes.
- Working knowledge of Microsoft security technologies and cloud security concepts.
- Understanding of network, endpoint, and identity security principles.
- Strong analytical and problem-solving skills.
- Strong organizational skills with the ability to manage multiple compliance and security initiatives simultaneously.
- Strong written and verbal communication skills.
- Ability to work effectively with global teams and non-technical business stakeholders.
- Ability to work independently with limited supervision.
Beneficial Skills and Experience- Experience supporting TISAX certification or recertification activities.
- Experience working within global or multi-site organizations.
- Experience with Trend Micro Apex One, Microsoft Intune, and Entra ID.
- Experience supporting ISO 27001 or SOC audits or information security management systems.
- Knowledge of automotive manufacturing industry requirements.
- Experience coordinating cybersecurity initiatives across multiple subsidiaries or affiliated companies.
- Demonstrated commitment to continuous learning and professional development.
Education/Training/Certifications- Bachelor's degree in IT, Cybersecurity, Information Systems, or related field, or equivalent experience.
- One or more cybersecurity-related certifications preferred:
- Security+
- SC-200
- SC-300
- CISSP
- CISM
- ISO 27001 Lead Implementer / Lead Auditor
- TISAX-related training or certification (preferred)
Travel Requirements- Approximately 30 %.
- Must be willing and available to travel to such locations and with such frequency as is necessary and desirable to meet business needs.
Work Environment RequirementsWith reasonable accommodation:
- Must be able to operate a personal computer, telephone, and other office equipment.
- Must perform job duties onsite, when necessary, except those duties that are customarily or by their nature performed offsite (for example, offsite customer visits).
- Must be able to work effectively in a fast-paced environment.
- Must be able to work on multiple assignments at once, and complete assignments within deadline and budget (if applicable) with satisfactory quality.
- Must be able to operate as an effective team member.
- Must be committed to a high standard of safety and be willing and able to comply with all safety laws and all company safety policies.
Attendance/Work Hour Requirements- Must maintain an acceptable attendance record.
- Must be willing and available to work weekends and holidays as necessary and desirable to meet business needs.