Responsibilities
- Act as the primary Program Manager for enterprise-wide security implementations (e.g., IAM rollouts, zero-trust adoption, vulnerability remediation initiatives). Coordinate dependencies across Engineering, IT, Legal, Privacy, and Studio/Business Ops.
- Lead the development, documentation, and enforcement of security policies, standards, and control frameworks. (e.g., NIST, CIS, ISO, MPAA Best Practices).
- Oversee risk assessments, security reviews, and compliance audits to identify gaps and ensure adherence to regulatory requirements, internal standards, and industry best practices.
- Collaborate with legal, privacy, and business stakeholders to interpret regulatory requirements (e.g., GDPR, CCPA, TPN) and ensure their integration into security and operational processes.
- Develop and maintain security baselines, control procedures, and governance artifacts to guide Studio technology teams.
- Oversee vendor risk management by evaluating and continuously monitoring third-party adherence to security standards and requirements.
- Direct the design and implementation of security compliance monitoring tools and dashboards to track posture and maintain audit readiness.
- Provide support to the Incident Response team and contribute to post-incident reviews, emphasizing improvements to controls and the implementation of risk mitigation strategies.
- Serve as a liaison to internal and external auditors, managing evidence collection and audit response processes.
- Develop and deliver security training and awareness programs.
- Participate in business continuity and disaster recovery planning to ensure compliance requirements are met.
- Drive continuous improvement of governance processes and security controls through proactive gap analysis, stakeholder collaboration, and industry benchmarking.
- Prepare executive-level reports and presentations on compliance status, audit results, risk trends, and governance initiatives.
- Perform other duties as needed to accomplish the overall Threat Management mission at MSG.
- Provide exceptional experiences for our guests, partners, and team members, including by adhering to our appearance and presentation guidelines while on-site.
Requirements
- 8+ years of related experience
- Bachelor’s degree, or equivalent combination of education and experience
- Undergraduate degree in Computer Science, Engineering, or Management Information Systems
- 5+ years of experience in Information Security with a focus on governance, risk, and compliance (GRC)
- Strong knowledge of regulatory requirements (e.g., SOX, PCI, MPAA Best Practice) and industry frameworks (e.g., NIST, ISO, CIS)
- Experience leading audits and compliance assessments across Cloud environments (AWS, Azure, GCP) and On-Prem systems
- Demonstrated experience developing and maintaining security policies, standards, and governance documentation
- Strong understanding of risk management principles and methodologies, with experience performing risk assessments and mitigation planning
- Familiarity with security technologies and tools (e.g., vulnerability management, identity & access management, endpoint protection), and how they tie into compliance reporting
- Excellent communication and collaboration skills
- Ability to build strong relationships with internal and external stakeholders
Nice to Have
- MS in Cybersecurity preferred
- Experience with compliance and governance platforms is a plus (e.g., ServiceNow GRC, Archer)
Work Arrangement
On-site — New York
Additional Information
- Provide exceptional experiences for our guests, partners, and team members, including by adhering to our appearance and presentation guidelines while on-site.