Governance Risk And Compliance Jobs in California
Governance Risk And Compliance jobs in California represent one of the most active markets in the country, concentrated in financial services, technology, healthcare, and defense contracting across a seniority range from analyst and associate through chief compliance officer. San Francisco, Los Angeles, and San Diego are the primary hiring hubs, where major employers such as Wells Fargo, Kaiser Permanente, and Qualcomm maintain substantial compliance and risk functions. The most in-demand specialties include enterprise risk management, regulatory compliance for fintech and biotech, and cybersecurity governance. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 15+ Governance Risk And Compliance jobs











This role provides leadership and expertise in building, scaling, and continuously improving enterprise Governance, Risk, and Compliance (GRC) programs for Sony Pictures Entertainment and its affiliates. The position is responsible for managing end-to-end cybersecurity and compliance initiatives including PCI DSS, ISO 27001, privacy/security controls, and related security governance frameworks.
The role also supports strategic Sony Group information security governance initiatives, including ISMS performance management, policy and standards development, and Sony Group Critical Asset Program.
The role partners closely with technical and business stakeholders to lead and coordinate assessments, drive remediation activities, report on program health and risk posture, and improve operational maturity across the organization. A key focus is modernizing and automating control assessment activities through workflow automation, AI-assisted evidence collection, continuous control monitoring, and data-driven reporting to improve efficiency and scalability with limited resources.
This individual will also help lead the development, modernization, governance, and rollout of global information security policies, standards, and procedures, ensuring alignment with Sony Group, business operations, evolving technologies, and regulatory requirements.
Success in this role requires strong relationship-building skills and the ability to influence teams across Information Technology, Legal, People & Operations (P&O), Privacy, Production Security, and corporate functions. Experience working in fast-paced, creative, or lightly regulated industries such as entertainment, media, gaming, or streaming is highly desirable, where collaboration and influence are critical to driving security and risk reduction outcomes.
Responsibilities
- Lead and manage enterprise cybersecurity compliance programs including PCI DSS, ISO 27001, privacy/security initiatives, and internal control frameworks.
- Lead and coordinate end-to-end compliance assessments including scoping, evidence collection, control testing, remediation tracking, and reporting.
- Partner with control owners and technical teams to assess control effectiveness and drive remediation activities.
- Develop dashboards, metrics, and executive reporting to communicate compliance status, risk trends, and program maturity.
- Identify opportunities to automate control assessments, evidence collection, reporting, and governance workflows using AI and automation technologies.
- Support continuous control monitoring and process improvements to increase operational efficiency and scalability.
- Develop, maintain, and modernize global information security policies, standards, and procedures.
- Drive policy governance activities, including stakeholder alignment, periodic reviews, approvals, exception management, and rollout communications.
- Collaborate with Information Technology, Privacy, Legal, P&O, Production Security, and corporate functions to align security controls and policies with organizational objectives.
- Support Sony Group information security governance initiatives, including ISMS performance reporting, Sony Group Critical Asset Program activities, and policy and standards development.
- Serve as a trusted advisor and relationship builder across technical and non-technical stakeholders.
- Monitor evolving cybersecurity, privacy, and compliance requirements and recommend program improvements.
Qualifications / Preferred Skills
- 5–7+ years of experience in cybersecurity GRC, compliance, risk management, audit, or security program management.
- Hands-on experience with frameworks such as PCI DSS, ISO 27001, SOC 2, NIST CSF, or related security/privacy standards.
- Experience leading compliance assessments, remediation management, and control validation activities.
- Experience developing and operationalizing security policies, standards, and governance processes.
- Familiarity with GRC and workflow platforms such as ServiceNow, AuditBoard/Optro, Smartsheet, or similar tools.
- Experience driving automation initiatives related to compliance operations, evidence collection, reporting, or continuous monitoring.
- Familiarity with AI-enabled workflows and automation technologies to improve operational scale and efficiency.
- Strong communication, stakeholder management, and relationship-building skills.
- Ability to operate effectively in fast-paced, evolving environments with competing priorities.
- Experience in entertainment, media, gaming, or streaming environments is highly desirable.
- Relevant certifications preferred (CISA, CISM, CRISC, CISSP, ISO 27001, PCI ISA,
The anticipated base salary for this position is $142,400-$178,000. This role may also qualify for annual incentive and/or comprehensive benefits. The actual base salary offered will depend on a variety of factors, including without limitation, the qualifications of the individual applicant for the position, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location of the position.
Sony Pictures Entertainment is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, national origin, disability, veteran status, age, sexual orientation, gender identity, or other protected characteristics.
SPE will consider qualified applicants with arrest or conviction records in accordance with applicable law.
To request an accommodation for purposes of participating in the hiring process, you may contact us at SPE_Accommodation_Assistance@spe.sony.com.
See All 15 Governance Risk And Compliance Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find JobsGovernance Risk And Compliance Jobs by City in California
Where California roles are concentrated, by current openings.
Governance Risk And Compliance Job Market in California
A snapshot from current California openings, updated as new roles post.
Who's Hiring



Top Industries Hiring
- Technology & Software
- Healthcare & Medical Services
- Biotechnology & Pharmaceuticals
What California Employers Look For
The qualifications that appear most often in governance risk and compliance jobs across California.
- Bachelor's degree in business, finance, law, or a related field required
- Certified Compliance and Ethics Professional or CISA certification strongly preferred
- Three or more years of experience in risk, audit, or regulatory compliance functions
- Working knowledge of California-specific regulations including CCPA and DFPI requirements
- Demonstrated experience conducting risk assessments, audits, or internal control reviews
- Familiarity with frameworks such as COSO, ISO 31000, or NIST for governance programs
Governance Risk And Compliance Jobs in California: Frequently Asked Questions
How do you become a governance risk and compliance in California?
Most governance risk and compliance roles in California require at minimum a bachelor's degree in business administration, finance, accounting, law, or a related field. From there, employers consistently favor candidates who hold recognized credentials such as the Certified Compliance and Ethics Professional designation, the Certified Internal Auditor certification, or ISACA's CISA or CRISC for technology-focused roles. California's large regulated industries, including banking supervised by the Department of Financial Protection and Innovation and healthcare oversight under DHCS, create strong demand for professionals who understand state-specific regulatory frameworks alongside federal requirements.
Which companies hire governance risk and compliances in California?
Employers hiring governance risk and compliances in California right now include Whatnot, NA, and ivo, based on current listings on Migrate Mate as of September 2026. California's dense concentration of publicly traded technology companies, major banks, and large health systems means governance risk and compliance hiring tends to be broad and consistent throughout the year.
Which California cities have the most governance risk and compliance jobs?
San Francisco, Palo Alto, and Oakland have the most governance risk and compliance openings in California. San Francisco leads due to its concentration of financial services firms, fintech startups, and technology companies with extensive regulatory obligations, while Los Angeles draws volume from entertainment, healthcare, and aerospace, and San Diego's strength in biotech and defense contracting sustains steady demand for compliance professionals in those sectors.
Are there remote governance risk and compliance jobs in California?
Yes, and more than most fields. About 69% of governance risk and compliance openings tied to California are remote or hybrid as of September 2026, reflecting that much of the work involves policy review, documentation, risk assessments, and regulatory analysis that can be done without a fixed office. Policy development, third-party risk management, and compliance monitoring roles tend to be the most consistently available in remote or hybrid formats.
How can I get hired as a governance risk and compliance in California with little or no experience?
The most realistic entry path is moving from an adjacent role in internal audit, legal operations, finance, or IT security into a compliance analyst or junior risk associate position. Large California employers including major Bay Area technology companies, Kaiser Permanente, and the larger regional banks regularly post associate compliance and risk analyst roles that are structured for candidates with a relevant degree but limited direct experience. Earning an entry-level credential such as the CAMS for financial crime or the CompTIA Security Plus for cybersecurity governance noticeably strengthens applications, as does any internship or co-op experience with a California-regulated industry.
Where can I find and apply to governance risk and compliance jobs in California?
You can find and apply to governance risk and compliance jobs in California on Migrate Mate, which lists current California openings across industries and seniority levels. Find the roles that fit your background and apply directly.
See All 15 Governance Risk And Compliance Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find Jobs