What are the responsibilities and job description for the Security Compliance Assessor position at COMPANY 3?
POSITION SUMMARY :
Company3 / Method Studios (CO3 / Method) is a global leader in media and entertainment services for film, video and online content. With operations in Los Angeles, New York and around the globe, the company employs over 2,500 of the most talented, highly honored, and recognized artists and industry veterans worldwide.
The Security Compliance Assessor is responsible for ensuring the security and compliance of all information systems, data, and operations within the media and entertainment facility. This role will play a critical part in maintaining a secure and reliable environment that aligns with industry best practices, including the Motion Picture Association (MPA) guidelines and the National Institute of Standards and Technology (NIST) Cybersecurity Framework
MAIN DUTIES :
Governance, Risk & Compliance (GRC) : The Security Compliance Assessor will draft, maintain, and regularly review policies and procedures related to GRC for physical, administrative, and information systems (IS) environments. They will conduct risk assessments and threat modeling to identify and mitigate potential security vulnerabilities, as well as monitor and analyze security incidents and implement appropriate response and remediation plans.
Auditing & Compliance : The Security Compliance Assessor will participate in external audits of CO3 facilities and operations conducted by third-party auditors, conduct regular internal audits of studios to assess compliance with CO3 policies and industry standards, and daft comprehensive audit reports that clearly convey findings to systems owners and executives, including recommendations for corrective actions.
Security Controls : They will establish and maintain internal controls aligned with the NIST Cybersecurity Framework to safeguard sensitive data and systems, and implement and manage security controls, including access control, intrusion detection / prevention systems, and data loss prevention measures.
The Security Compliance Assessor will also be responsible for the following :
Security Awareness & Training :
- Develop and deliver comprehensive security awareness training programs for all employees, covering topics such as phishing, social engineering, and best practices for data handling and protection.
- Track employee training completion and maintain records of training activities.
Incident Response :
Stay Informed :
WHAT YOU BRING :
The ideal candidate will be experienced in the information systems or computer science field, and must have solid experience in developing, implementing, and maintaining GRC frameworks. This includes risk assessments, threat modeling, and policy / procedure development. They must be able to demonstrate a deep understanding of the unique security challenges and regulatory landscape within the media and entertainment sector and be experienced with conducting both internal and external audits, analyzing findings, and producing clear, concise reports with actionable recommendations. Additional desired skills include :
The following skills are considered an asset :
ABOUT THE COMPANY :
Company 3, including its various business units and family of brands, provides a full range of Creative Services for content creators, including conceptual design, pre-vis, look development, ideation and rapid prototyping, 3D animation / CGI, motion graphics / designers, matte painting, compositing, dailies and production services, color grading, post-production finishing, marketing / trailers, live-action production, experiences, and more.
Salary : $29 - $30