Sony→
Intern, Information Security at Sony in New York
InternshipHybridFull-timeNew York$50k–$50k/yr
Skills
information securityrisk assessmentgovernance riskcompliance (grc)regulatory frameworks - iso 27001regulatory frameworks - nistregulatory frameworks - pci dssgrc tools - rsa archercybersecurity best practicesanalytical skills
Job Description
Summary: Sony Corporation of America is the U.S. headquarters of Sony Group Corporation, based in Tokyo, Japan. They are seeking an Information Security Risk and Compliance Intern to join the Information Security Department, responsible for securing Sony’s information assets and enhancing its Information Security program.
Responsibilities:
- Provide day-to-day operational and administrative support to the Governance, Risk, and Compliance (GRC) function within the program
- Support risk assessment of prospective third parties to evaluate their security posture and compliance practices
- Assist in preparing detailed reports on risk findings and security gaps following third-party risk assessment
- Assist in maintaining third-party asset inventory in the GRC tool
- Contribute to the development and improvement of third-party risk management processes
- Participate in the creation and delivery of information security awareness, training, and education program materials
Required Qualifications:
- Current student pursuing a bachelor's degree in Cybersecurity, Computer Science, Information Security, or a related field
- Excellent writing skills with a proven ability to write clear, unambiguous instructions
- Demonstrated strong analytical, problem-solving skills, and attention to detail are essential
- All candidates must be authorized to work in the USA
Preferred Qualifications:
- Working knowledge of regulatory frameworks (ISO 27001, NIST, PCI DSS) beneficial
- Working knowledge of GRC tools such as RSA Archer a plus
- Familiarity with cybersecurity best practices, and ability/interest in creating engaging awareness materials
Required Skills: Information Security, Risk Assessment, Governance Risk, Compliance (GRC), Regulatory Frameworks - ISO 27001, Regulatory Frameworks - NIST, Regulatory Frameworks - PCI DSS, GRC Tools - RSA Archer, Cybersecurity Best Practices, Analytical skills