About Information Security Team
Our mission is to create and maintain a secure foundation for Bridgestone to continue serving society with superior quality and trust in a digital and evolving world. We will Identify, Detect, Protect, Respond and Recover from cyber-attacks, ensuring the Confidentiality, Integrity, Availability and Safety of our team-mates, information, and systems.
Years of experience :  5-7 years
Key Responsibilities :
* Support Governance, Risk, and Compliance (GRC) programs and initiatives across global regions.
* 50% Security Awareness support, 50% all other GRC duties as assigned
* Assist with compliance assessments, evidence collection, control testing, and audit activities supporting frameworks and regulations such as ISO 27001, NIST, PCI DSS, NIS2, TISAX, GDPR, CMMC, and other applicable requirements.
* Support enterprise risk management activities, including risk identification, assessment, treatment planning, risk register maintenance, and risk reporting.
* Develop, review, maintain, and organize Information Security policies, standards, procedures, and supporting documentation.
* Support security awareness and training activities, including awareness campaigns, communications, phishing simulations, metrics collection, and employee engagement initiatives.
* Prepare reports, dashboards, metrics, and presentations for leadership, auditors, and stakeholders. Specifically phishing metrics and reporting.
* Monitor regulatory, legal, and industry developments impacting cybersecurity and compliance obligations.
* Support continuous improvement initiatives related to GRC processes, tools, documentation, and reporting.
Technical Skills :
* Understanding of Information Security Governance, Risk Management, Compliance, and Security Awareness principles.
* Familiarity with security frameworks and standards including ISO 27001, NIST CSF, NIST 800-53, CIS Controls, PCI DSS, GDPR, NIS2, TISAX, and similar requirements.
* Experience supporting audits, assessments, control reviews, and documentation management.
* Familiarity with risk management methodologies and risk assessment processes.
* Experience using governance, risk, compliance, issue management, and workflow platforms such as ServiceNow, OneTrust, Archer, Sprinto, or similar tools.
* Ability to analyze information, develop reports, track metrics, and identify trends.
* Proficiency with Microsoft Office products including Excel, PowerPoint, Word, Teams, and SharePoint.
Soft Skills :
* Strong verbal and written communication and interpersonal skills. (in English)
* Excellent troubleshooting and problem-solving skills
* Solid business acumen; understands how Information Security supports business objectives.
* Comfortable dealing with ambiguity and working through change.
* Works well on a team; supplemented by the ability to work with minimal supervision.
Educations and Qualifications :
* Bachelor's degree in Cybersecurity, Information Technology, Business, Risk Management, Audit, Compliance, or a related discipline.
* Relevant certifications preferred, such as Security+, ISO 27001 Lead Implementer/Auditor, CISA, CRISC, CISSP, CISM, CGRC, or similar credentials.
* Equivalent combination of experience, training, and education may be considered.