Lead, Information Security Governance, Risk & Compliance
Culver, CA - USA
Job Summary
This role provides leadership and expertise in building scaling and continuously improving enterprise Governance Risk and Compliance (GRC) programs for Sony Pictures Entertainment and its affiliates. The position is responsible for managing end-to-end cybersecurity and compliance initiatives including PCI DSS ISO 27001 privacy/security controls and related security governance frameworks.
The role also supports strategic Sony Group information security governance initiatives including ISMS performance management policy and standards development and Sony Group Critical Asset Program.
The role partners closely with technical and business stakeholders to lead and coordinate assessments drive remediation activities report on program health and risk posture and improve operational maturity across the organization. A key focus is modernizing and automating control assessment activities through workflow automation AI-assisted evidence collection continuous control monitoring and data-driven reporting to improve efficiency and scalability with limited resources.
This individual will also help lead the development modernization governance and rollout of global information security policies standards and procedures ensuring alignment with Sony Group business operations evolving technologies and regulatory requirements.
Success in this role requires strong relationship-building skills and the ability to influence teams across Information Technology Legal People & Operations (P&O) Privacy Production Security and corporate functions. Experience working in fast-paced creative or lightly regulated industries such as entertainment media gaming or streaming is highly desirable where collaboration and influence are critical to driving security and risk reduction outcomes.
Responsibilities
- Lead and manage enterprise cybersecurity compliance programs including PCI DSS ISO 27001 privacy/security initiatives and internal control frameworks.
- Lead and coordinate end-to-end compliance assessments including scoping evidence collection control testing remediation tracking and reporting.
- Partner with control owners and technical teams to assess control effectiveness and drive remediation activities.
- Develop dashboards metrics and executive reporting to communicate compliance status risk trends and program maturity.
- Identify opportunities to automate control assessments evidence collection reporting and governance workflows using AI and automation technologies.
- Support continuous control monitoring and process improvements to increase operational efficiency and scalability.
- Develop maintain and modernize global information security policies standards and procedures.
- Drive policy governance activities including stakeholder alignment periodic reviews approvals exception management and rollout communications.
- Collaborate with Information Technology Privacy Legal P&O Production Security and corporate functions to align security controls and policies with organizational objectives.
- Support Sony Group information security governance initiatives including ISMS performance reporting Sony Group Critical Asset Program activities and policy and standards development.
- Serve as a trusted advisor and relationship builder across technical and non-technical stakeholders.
- Monitor evolving cybersecurity privacy and compliance requirements and recommend program improvements.
Qualifications / Preferred Skills
- 57 years of experience in cybersecurity GRC compliance risk management audit or security program management.
- Hands-on experience with frameworks such as PCI DSS ISO 27001 SOC 2 NIST CSF or related security/privacy standards.
- Experience leading compliance assessments remediation management and control validation activities.
- Experience developing and operationalizing security policies standards and governance processes.
- Familiarity with GRC and workflow platforms such as ServiceNow AuditBoard/Optro Smartsheet or similar tools.
- Experience driving automation initiatives related to compliance operations evidence collection reporting or continuous monitoring.
- Familiarity with AI-enabled workflows and automation technologies to improve operational scale and efficiency.
- Strong communication stakeholder management and relationship-building skills.
- Ability to operate effectively in fast-paced evolving environments with competing priorities.
- Experience in entertainment media gaming or streaming environments is highly desirable.
- Relevant certifications preferred (CISA CISM CRISC CISSP ISO 27001 PCI ISA
Sony Pictures Entertainment is an equal opportunity employer. We evaluate qualified applicants without regard to race color religion sex national origin disability veteran status age sexual orientation gender identity or other protected characteristics.
SPE will consider qualified applicants with arrest or conviction records in accordance with applicable law.
Sony Pictures does not allow audio recording video recording or use of AI note-taking tools during interviews. Please be aware these tools may be enabled as a default and can be difficult to disable once the interview has started so we recommend you check your device and disable these tools prior to the start of your interview. If recording or the use of the tools occurs during the interview and cannot be promptly turned off or disabled the interviewer may end the interview.
To request an accommodation for purposes of participating in the hiring process you may contact us at
About Company
The toga lady holds her torch high for film audiences everywhere by representing Columbia Pictures, the studio through which Sony Pictures Entertainment produces its big budget movies. The studio was founded in 1924, and in 1982 it was purchased by Coca-Cola. Sony purchased ...