Technology & InfoSec

Sony Corporation
United States
10 days ago
Apply on spe.wd1.myworkdayjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$142,400.0 - $178,000.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Cyber Security PCI Data Security Standards Smartsheet Information Security Management System Information Technology Performance Monitor Servicenow

Job description

This role provides leadership and expertise in building, scaling, and continuously improving enterprise Governance, Risk, and Compliance (GRC) programs for Sony Pictures Entertainment and its affiliates. The position is responsible for managing end-to-end cybersecurity and compliance initiatives including PCI DSS, ISO 27001, privacy/security controls, and related security governance frameworks.

The role also supports strategic Sony Group information security governance initiatives, including ISMS performance management, policy and standards development, and Sony Group Critical Asset Program.

The role partners closely with technical and business stakeholders to lead and coordinate assessments, drive remediation activities, report on program health and risk posture, and improve operational maturity across the organization. A key focus is modernizing and automating control assessment activities through workflow automation, AI-assisted evidence collection, continuous control monitoring, and data-driven reporting to improve efficiency and scalability with limited resources.

This individual will also help lead the development, modernization, governance, and rollout of global information security policies, standards, and procedures, ensuring alignment with Sony Group, business operations, evolving technologies, and regulatory requirements., * Lead and manage enterprise cybersecurity compliance programs including PCI DSS, ISO 27001, privacy/security initiatives, and internal control frameworks.

  • Lead and coordinate end-to-end compliance assessments including scoping, evidence collection, control testing, remediation tracking, and reporting.
  • Partner with control owners and technical teams to assess control effectiveness and drive remediation activities.
  • Develop dashboards, metrics, and executive reporting to communicate compliance status, risk trends, and program maturity.
  • Identify opportunities to automate control assessments, evidence collection, reporting, and governance workflows using AI and automation technologies.
  • Support continuous control monitoring and process improvements to increase operational efficiency and scalability.
  • Develop, maintain, and modernize global information security policies, standards, and procedures.
  • Drive policy governance activities, including stakeholder alignment, periodic reviews, approvals, exception management, and rollout communications.
  • Collaborate with Information Technology, Privacy, Legal, P&O, Production Security, and corporate functions to align security controls and policies with organizational objectives.
  • Support Sony Group information security governance initiatives, including ISMS performance reporting, Sony Group Critical Asset Program activities, and policy and standards development.
  • Serve as a trusted advisor and relationship builder across technical and non-technical stakeholders.
  • Monitor evolving cybersecurity, privacy, and compliance requirements and recommend program improvements.

Requirements

Success in this role requires strong relationship-building skills and the ability to influence teams across Information Technology, Legal, People & Operations (P&O), Privacy, Production Security, and corporate functions. Experience working in fast-paced, creative, or lightly regulated industries such as entertainment, media, gaming, or streaming is highly desirable, where collaboration and influence are critical to driving security and risk reduction outcomes., * 5-7+ years of experience in cybersecurity GRC, compliance, risk management, audit, or security program management.

  • Hands-on experience with frameworks such as PCI DSS, ISO 27001, SOC 2, NIST CSF, or related security/privacy standards.
  • Experience leading compliance assessments, remediation management, and control validation activities.
  • Experience developing and operationalizing security policies, standards, and governance processes.
  • Familiarity with GRC and workflow platforms such as ServiceNow, AuditBoard/Optro, Smartsheet, or similar tools.
  • Experience driving automation initiatives related to compliance operations, evidence collection, reporting, or continuous monitoring.
  • Familiarity with AI-enabled workflows and automation technologies to improve operational scale and efficiency.
  • Strong communication, stakeholder management, and relationship-building skills.
  • Ability to operate effectively in fast-paced, evolving environments with competing priorities.
  • Experience in entertainment, media, gaming, or streaming environments is highly desirable.
  • Relevant certifications preferred (CISA, CISM, CRISC, CISSP, ISO 27001, PCI ISA, The anticipated base salary for this position is $142,400-$178,000. This role may also qualify for annual incentive and/or comprehensive benefits. The actual base salary offered will depend on a variety of factors, including without limitation, the qualifications of the individual applicant for the position, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location of the position.

Benefits & conditions

Be a part of a diverse, inclusive and collaborative culture that focuses on professional development, high performance and growth by leveraging structured programs that include OKRs (stretch for amazing) and modern development planning tools (e.g. competency model). Check out the top traits we’re looking for and see if you have the right mix.

  • trusted partner
  • innovative problem solver
  • strategic thinker
  • change agent
  • effective communicator
  • learner and developer

About the company

At the heart of our creative entertainment company lies a deep commitment to technology, driving innovation across film, television, interactive media, and more. An agile, fast-paced environment empowers team members to solve complex, business-critical challenges while embracing cutting-edge tools, technical excellence, and imaginative thinking.

From our innovative technology-driven production studios to our dynamic Information Technology and Information Security teams to the people who support our creative talent and protect our content, help us forge the future of entertainment at Sony Pictures - where creativity meets technology to inspire audiences worldwide!, The constant evolution of technology and its role in shaping the entertainment industry is what excites me most. Working at Sony Pictures Entertainment has amplified this passion, exposing me to a world of innovation where I get to collaborate with incredibly diverse teams from around the globe. This unique opportunity to contribute to a global enterprise, including my relocation from Brazil to Miami, has given me a new appreciation for how technology connects us all. I am very proud to be part of a company that values inclusivity and pushes the boundaries of what’s possible. Cristiane Kadooka Executive Director, Regional IT - Latin America

I love working at SPE because of the incredible people-collaborative, welcoming, and genuinely passionate about what they do. As part of the IT team, I get to work on exciting new projects and explore advanced technologies that are shaping the future of our industry and business. Every day brings new opportunities to learn, grow, and make a meaningful impact. It’s a dynamic environment that supports your career development and makes you feel proud to be here. Alex Kim Executive Director, Corporate IT - Culver City

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on spe.wd1.myworkdayjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all