Security Analyst - GRC

Bridgestone Americas · Bengaluru

  • Experience5–7 yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Levelsenior
  • Posted18 Sept 2026

About Bridgestone Americas

Bridgestone Americas is hiring in Bengaluru in automotive mobility. This role looks for around 5+ years of experience.

Skills

  • GRC
  • risk management
  • ISO 27001
  • NIST CSF
  • NIST 800-53
  • CIS Controls
  • PCI DSS
  • GDPR
  • NIS2
  • TISAX
  • security awareness
  • security audits
  • control testing
  • risk assessment
  • Microsoft Excel
  • Microsoft PowerPoint
  • Microsoft Word
  • Microsoft Teams
  • SharePoint

The role

A GRC analyst at an automotive mobility company supports cybersecurity governance through risk management, ISO 27001, and security awareness, shaping controls, assessments, and enterprise compliance. The role also applies ServiceNow and Microsoft Excel to organize evidence, track risk, and report phishing metrics.

Full job description

About Information Security Team

Our mission is to create and maintain a secure foundation for Bridgestone to continue serving society with superior quality and trust in a digital and evolving world. We will Identify, Detect, Protect, Respond and Recover from cyber-attacks, ensuring the Confidentiality, Integrity, Availability and Safety of our team-mates, information, and systems.

Years of experience : 5-7 years

Key Responsibilities

Support Governance, Risk, and Compliance (GRC) programs and initiatives across global regions. 50% Security Awareness support, 50% all other GRC duties as assigned Assist with compliance assessments, evidence collection, control testing, and audit activities supporting frameworks and regulations such as ISO 27001, NIST, PCI DSS, NIS2, TISAX, GDPR, CMMC, and other applicable requirements. Support enterprise risk management activities, including risk identification, assessment, treatment planning, risk register maintenance, and risk reporting. Develop, review, maintain, and organize Information Security policies, standards, procedures, and supporting documentation. Support security awareness and training activities, including awareness campaigns, communications, phishing simulations, metrics collection, and employee engagement initiatives. Prepare reports, dashboards, metrics, and presentations for leadership, auditors, and stakeholders. Specifically phishing metrics and reporting. Monitor regulatory, legal, and industry developments impacting cybersecurity and compliance obligations. Support continuous improvement initiatives related to GRC processes, tools, documentation, and reporting.

Technical Skills

Understanding of Information Security Governance, Risk Management, Compliance, and Security Awareness principles. Familiarity with security frameworks and standards including ISO 27001, NIST CSF, NIST 800-53, CIS Controls, PCI DSS, GDPR, NIS2, TISAX, and similar requirements. Experience supporting audits, assessments, control reviews, and documentation management. Familiarity with risk management methodologies and risk assessment processes. Experience using governance, risk, compliance, issue management, and workflow platforms such as ServiceNow, OneTrust, Archer, Sprinto, or similar tools. Ability to analyze information, develop reports, track metrics, and identify trends. Proficiency with Microsoft Office products including Excel, PowerPoint, Word, Teams, and SharePoint.

Soft Skills

Strong verbal and written communication and interpersonal skills. (in English) Excellent troubleshooting and problem-solving skills Solid business acumen; understands how Information Security supports business objectives. Comfortable dealing with ambiguity and working through change. Works well on a team; supplemented by the ability to work with minimal supervision.

Educations And Qualifications

Bachelor's degree in Cybersecurity, Information Technology, Business, Risk Management, Audit, Compliance, or a related discipline. Relevant certifications preferred, such as Security+, ISO 27001 Lead Implementer/Auditor, CISA, CRISC, CISSP, CISM, CGRC, or similar credentials. Equivalent combination of experience, training, and education may be considered.