The Compliance Analyst will monitor and manage compliance issues while ensuring internal systems meet TISAX and VDA ISA security standards. They will also design audit processes, coordinate reporting channels, and provide technical support for information security controls.
The Compliance Analyst will be responsible for monitoring, managing and closing existing compliance issues while also ensuring that internal systems are compliant with TISAX VDA Information Security Assessment (ISA) security standard. Compliance Analyst’s responsibilities include the identification, evaluation, and interpretation of regulatory, statutory and member security requirements, control deficiencies and information security risks.
Essential Duties & Responsibilities:
Design, coordinate and execute audit process e.g., TISAX or ISO, monitoring and procedures to assess and measure company information security risks and compliance with its security policies and procedures.
Monitor advancements in Trusted Information Security Assessment Exchange (TISAX) requirements, including VDA ISA Catalog, and the ENX audit and exchange mechanism (ENX Portal) .
Develop, recommend, and establish controls and processes as necessary to protect Tenneco information assets against unauthorized or accidental modification, destruction, or disclosure.
Create and coordinate proper reporting channels for compliance issues. Develop and support compliance communications with Tenneco’s Business Units. Coordinate required compliance training for employees.
Provide consulting and technical support services to owners, custodians, and users in defining and deploying cost-effective security controls and protections.
Document, maintain, and obtain ongoing support for all aspects of the Information Security Management System (ISMS) program.
Monitor the effectiveness of strategies, activities, measures, and controls designed to protect the Tenneco information assets.
Serve as Tenneco internal and external point of contact for information security matters regarding information security topics.
Participate in the Information Security policies lifecycle process, necessary to ensure the security of information and information resources against unauthorized or accidental modification, destruction, or disclosure.
Coordinate the review of the data security requirements, specifications of the third-party risk assessment (TPRM).
Requirements:
Desirable 2 + years of relevant Information Security experience in any organization with background covering design, risk, compliance, governance, data protection, Identity and assess management, Network security, application security and/or cloud.
Knowledge of TISAX, ISO 27001, NIS 2.
Audit approach.
Excellent communication, organization time management and problem-solving skills.
Exceptional track record of building relationships with stakeholders.
Strong multi-tasking skills with the ability to manage multiple projects.
Ability to function as a Team Player and maintain a good working relationship, yet think and act independently with professionalism, discretion and confidentiality.
Excellent communication, organization time management and problem-solving skills.
Bachelor’s degree in Computer Science, Information Security and Risk Management, or Information Systems.
CISSP, CISM or ITIL certifications are preferred.
Willingness to business travels (up to 20%).
What do we offer:
Fully remote work schedule
13th salary (paid in 3 installments)
Additional 5 paid leave days per year (calculated proportionally to the period worked)
Monthly budget to spend on Flexible Benefits Platform
Well-being bonus (1-time bonus after probation period)
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”