Lead, Information Security - Governance, Risk & Compliance

Sony Pictures Entertainment, Inc

Culver City (CA)

On-site

USD 130,000 - 170,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Sony Pictures Entertainment, Inc. is seeking a senior GRC leader to build and scale enterprise governance, risk, and compliance programs across its affiliates.

You will drive PCI DSS, ISO 27001, privacy controls, and security governance frameworks while aligning with Sony Group initiatives. You’ll partner with IT, Legal, Privacy, P&O, and Production Security to automate control assessments and report on risk posture.

Qualifications

  • 5–7+ years in cybersecurity GRC, compliance, risk management, audit, or security program management.
  • Hands‑on with PCI DSS, ISO 27001, SOC 2, NIST CSF.
  • Experience leading compliance assessments, remediation management, and control validation.
  • Experience developing and operationalizing security policies, standards, and governance processes.
  • Familiarity with GRC/workflow platforms (ServiceNow, AuditBoard/Optro, Smartsheet).
  • Experience driving automation in compliance operations, evidence collection, reporting, or monitoring.
  • Familiarity with AI‑enabled workflows to improve scalability.
  • Strong communication and stakeholder management skills.
  • Experience in entertainment/media/gaming/streaming environments is desirable.
  • Certifications preferred (CISA, CISM, CRISC, CISSP, ISO 27001, PCI ISA).

Responsibilities

  • Lead enterprise cybersecurity compliance programs including PCI DSS, ISO 27001, and privacy initiatives.
  • Coordinate end‑to‑end assessments: scoping, evidence collection, testing, remediation tracking, reporting.
  • Partner with control owners to assess effectiveness and drive remediation.
  • Develop dashboards and executive reporting on compliance status and risk trends.
  • Identify opportunities to automate control assessments and governance workflows.
  • Support continuous control monitoring and process improvements for efficiency.
  • Develop and modernize global information security policies and procedures.
  • Drive policy governance, approvals, and rollout communications.
  • Collaborate with IT, Privacy, Legal, P&O, Production Security, and corporate functions.
  • Support Sony Group governance initiatives and ISMS activities.
  • Act as trusted advisor across technical and non‑technical stakeholders.
  • Monitor evolving regulatory requirements and recommend program improvements.

Skills

GRC experience
Policy development
Stakeholder management
Automation in security
AI-enabled workflows
Security frameworks
ISO 27001

Education

CISA
CISM
CRISC
CISSP

Tools

ServiceNow
AuditBoard/Optro
Smartsheet

Job description

This role provides leadership and expertise in building, scaling, and continuously improving enterprise Governance, Risk, and Compliance (GRC) programs for Sony Pictures Entertainment and its affiliates. The position is responsible for managing end-to-end cybersecurity and compliance initiatives including PCI DSS, ISO 27001, privacy/security controls, and related security governance frameworks.

The role also supports strategic Sony Group information security governance initiatives, including ISMS performance management, policy and standards development, and Sony Group Critical Asset Program.

The role partners closely with technical and business stakeholders to lead and coordinate assessments, drive remediation activities, report on program health and risk posture, and improve operational maturity across the organization. A key focus is modernizing and automating control assessment activities through workflow automation, AI-assisted evidence collection, continuous control monitoring, and data-driven reporting to improve efficiency and scalability with limited resources.

This individual will also help lead the development, modernization, governance, and rollout of global information security policies, standards, and procedures, ensuring alignment with Sony Group, business operations, evolving technologies, and regulatory requirements.

Success in this role requires strong relationship-building skills and the ability to influence teams across Information Technology, Legal, People & Operations (P&O), Privacy, Production Security, and corporate functions. Experience working in fast-paced, creative, or lightly regulated industries such as entertainment, media, gaming, or streaming is highly desirable, where collaboration and influence are critical to driving security and risk reduction outcomes.

Responsibilities
  • Lead and manage enterprise cybersecurity compliance programs including PCI DSS, ISO 27001, privacy/security initiatives, and internal control frameworks.
  • Lead and coordinate end-to-end compliance assessments including scoping, evidence collection, control testing, remediation tracking, and reporting.
  • Partner with control owners and technical teams to assess control effectiveness and drive remediation activities.
  • Develop dashboards, metrics, and executive reporting to communicate compliance status, risk trends, and program maturity.
  • Identify opportunities to automate control assessments, evidence collection, reporting, and governance workflows using AI and automation technologies.
  • Support continuous control monitoring and process improvements to increase operational efficiency and scalability.
  • Develop, maintain, and modernize global information security policies, standards, and procedures.
  • Drive policy governance activities, including stakeholder alignment, periodic reviews, approvals, exception management, and rollout communications.
  • Collaborate with Information Technology, Privacy, Legal, P&O, Production Security, and corporate functions to align security controls and policies with organizational objectives.
  • Support Sony Group information security governance initiatives, including ISMS performance reporting, Sony Group Critical Asset Program activities, and policy and standards development.
  • Serve as a trusted advisor and relationship builder across technical and non-technical stakeholders.
  • Monitor evolving cybersecurity, privacy, and compliance requirements and recommend program improvements.
Qualifications / Preferred Skills
  • 5–7+ years of experience in cybersecurity GRC, compliance, risk management, audit, or security program management.
  • Hands‑on experience with frameworks such as PCI DSS, ISO 27001, SOC 2, NIST CSF, or related security/privacy standards.
  • Experience leading compliance assessments, remediation management, and control validation activities.
  • Experience developing and operationalizing security policies, standards, and governance processes.
  • Familiarity with GRC and workflow platforms such as ServiceNow, AuditBoard/Optro, Smartsheet, or similar tools.
  • Experience driving automation initiatives related to compliance operations, evidence collection, reporting, or continuous monitoring.
  • Familiarity with AI‑enabled workflows and automation technologies to improve operational scale and efficiency.
  • Strong communication, stakeholder management, and relationship‑building skills.
  • Ability to operate effectively in fast‑paced, evolving environments with competing priorities.
  • Experience in entertainment, media, gaming, or streaming environments is highly desirable.
  • Relevant certifications preferred (CISA, CISM, CRISC, CISSP, ISO 27001, PCI ISA,
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead, Information Security - Governance, Risk & Compliance
Lead, Information Security - Governance, Risk & Compliance

Sony Pictures Entertainment • Culver City (CA), Northern (KY)

Hybrid
USD 142,000 - 178,000
Lead, Information Security - Governance, Risk & Compliance
Lead, Information Security - Governance, Risk & Compliance

Sonypictures • Culver City (CA), Northern (KY)

Hybrid
USD 142,000 - 178,000
Annual incentive
Comprehensive benefits
Senior GRC & Information Security Leader
Senior GRC & Information Security Leader

Sonypictures • Culver City (CA), Northern (KY)

Hybrid
USD 142,000 - 178,000
Annual incentive
Comprehensive benefits
Senior GRC & Information Security Leader
Senior GRC & Information Security Leader

Sony Pictures Entertainment • Culver City (CA), Northern (KY)

Hybrid
USD 142,000 - 178,000
Senior GRC Leader — Security, Compliance & Automation
Senior GRC Leader — Security, Compliance & Automation

Sony Pictures Entertainment, Inc • Culver City (CA)

On-site
USD 130,000 - 170,000
Sr. Security Governance, Risk & Compliance Specialist
Sr. Security Governance, Risk & Compliance Specialist

clarioclinical • United States

On-site
USD 120,000 - 180,000
Information Security Manager
Information Security Manager

Kinsley Power Systems • Nashville (TN)

On-site
USD 100,000 - 130,000
Senior Manager, IT Finance Compliance (IT SOX)
Senior Manager, IT Finance Compliance (IT SOX)

Sony Pictures Entertainment • Culver City (CA)

On-site
USD 145,000 - 175,000
Senior Manager, IT Finance Compliance (IT SOX)
Senior Manager, IT Finance Compliance (IT SOX)

Sony Pictures Entertainment, Inc • Culver City (CA)

On-site
USD 145,000 - 175,000
Annual incentive
Comprehensive benefits
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,000 - 220,000
Annual incentive bonus