Turn this role into an interview — a resume and cover letter built around what this employer wants.
Sony Pictures Entertainment, Inc. is seeking a senior GRC leader to build and scale enterprise governance, risk, and compliance programs across its affiliates.
You will drive PCI DSS, ISO 27001, privacy controls, and security governance frameworks while aligning with Sony Group initiatives. You’ll partner with IT, Legal, Privacy, P&O, and Production Security to automate control assessments and report on risk posture.
This role provides leadership and expertise in building, scaling, and continuously improving enterprise Governance, Risk, and Compliance (GRC) programs for Sony Pictures Entertainment and its affiliates. The position is responsible for managing end-to-end cybersecurity and compliance initiatives including PCI DSS, ISO 27001, privacy/security controls, and related security governance frameworks.
The role also supports strategic Sony Group information security governance initiatives, including ISMS performance management, policy and standards development, and Sony Group Critical Asset Program.
The role partners closely with technical and business stakeholders to lead and coordinate assessments, drive remediation activities, report on program health and risk posture, and improve operational maturity across the organization. A key focus is modernizing and automating control assessment activities through workflow automation, AI-assisted evidence collection, continuous control monitoring, and data-driven reporting to improve efficiency and scalability with limited resources.
This individual will also help lead the development, modernization, governance, and rollout of global information security policies, standards, and procedures, ensuring alignment with Sony Group, business operations, evolving technologies, and regulatory requirements.
Success in this role requires strong relationship-building skills and the ability to influence teams across Information Technology, Legal, People & Operations (P&O), Privacy, Production Security, and corporate functions. Experience working in fast-paced, creative, or lightly regulated industries such as entertainment, media, gaming, or streaming is highly desirable, where collaboration and influence are critical to driving security and risk reduction outcomes.