- Location
- New York City, NY · New York City
- Department
- Security
- Seniority
- Senior
- Experience
- 5+ years
- Education
- Bachelor
Description
Madison Square Garden Entertainment Corp. (MSG Entertainment) is a leader in live entertainment, delivering unforgettable experiences while forging deep connections with diverse and passionate audiences. The Company’s portfolio includes a collection of world-renowned venues – New York’s Madison Square Garden, Infosys Theater at Madison Square Garden, Radio City Music Hall, and Beacon Theatre; and The Chicago Theatre – that showcase a broad array of sporting events, concerts, family shows, and special events for millions of guests annually. In addition, the Company features the original production, the Christmas Spectacular Starring the Radio City Rockettes, which has been a holiday tradition for more than 90 years. More information is available at www.msgentertainment.com.
Who are we hiring?
The Senior Manager of Information Security will be a key leader in developing and advancing our information security governance, risk, and compliance (GRC) programs and security delivery programs. The Senior Manager of Information Security will be responsible for security compliance, governance frameworks, risk management, and continuous monitoring to ensure MSG maintains a robust security posture aligned with industry best practices and regulatory requirements.
Acting as both a GRC SME and a Technical Program Manager, you will establish security policies, manage project portfolios, track key performance indicators, and drive the hands-on delivery of security controls and risk mitigation projects across the enterprise.
What will you do?
- Act as the primary Program Manager for enterprise-wide security implementations (e.g., IAM rollouts, zero-trust adoption, vulnerability remediation initiatives). Coordinate dependencies across Engineering, IT, Legal, Privacy, and Studio/Business Ops.
- Lead the development, documentation, and enforcement of security policies, standards, and control frameworks. (e.g., NIST, CIS, ISO, MPAA Best Practices).
- Oversee risk assessments, security reviews, and compliance audits to identify gaps and ensure adherence to regulatory requirements, internal standards, and industry best practices.
- Collaborate with legal, privacy, and business stakeholders to interpret regulatory requirements (e.g., GDPR, CCPA, TPN) and ensure their integration into security and operational processes.
- Develop and maintain security baselines, control procedures, and governance artifacts to guide Studio technology teams.
- Oversee vendor risk management by evaluating and continuously monitoring third-party adherence to security standards and requirements.
- Direct the design and implementation of security compliance monitoring tools and dashboards to track posture and maintain audit readiness.
- Provide support to the Incident Response team and contribute to post-incident reviews, emphasizing improvements to controls and the implementation of risk mitigation strategies.
- Serve as a liaison to internal and external auditors, managing evidence collection and audit response processes.
- Develop and deliver security training and awareness programs.
- Participate in business continuity and disaster recovery planning to ensure compliance requirements are met.
- Drive continuous improvement of governance processes and security controls through proactive gap analysis, stakeholder collaboration, and industry benchmarking.
- Prepare executive-level reports and presentations on compliance status, audit results, risk trends, and governance initiatives.
- Perform other duties as needed to accomplish the overall Threat Management mission at MSG.
- Provide exceptional experiences for our guests, partners, and team members, including by adhering to our appearance and presentation guidelines while on-site.
What do you need to succeed?
- 8+ years of related experience
- Bachelor’s degree, or equivalent combination of education and experience
- Undergraduate degree in Computer Science, Engineering, or Management Information Systems
- MS in Cybersecurity preferred
- 5+ years of experience in Information Security with a focus on governance, risk, and compliance (GRC).
- Strong knowledge of regulatory requirements (e.g., SOX, PCI, MPAA Best Practice) and industry frameworks (e.g., NIST, ISO, CIS).
- Experience leading audits and compliance assessments across Cloud environments (AWS, Azure, GCP) and On-Prem systems.
- Demonstrated experience developing and maintaining security policies, standards, and governance documentation.
- Strong understanding of risk management principles and methodologies, with experience performing risk assessments and mitigation planning.
- Familiarity with security technologies and tools (e.g., vulnerability management, identity & access management, endpoint protection), and how they tie into compliance reporting.
- Experience with compliance and governance platforms is a plus (e.g., ServiceNow GRC, Archer).
- Excellent communication and collaboration skills
- Ability to build strong relationships with internal and external stakeholders.
#LI- Onsite
At MSG, we recognize the importance of upskilling employees’ talents and strengths so they can drive their careers forward. We are proud to offer a robust set of tools and resources to help employees understand their interests and purpose, harness their talents and obtain the skills they need to reach the next step in their careers. Growth and longevity for our employees are top priorities here.
We value diversity and are looking for extraordinary employees of all backgrounds! MSG is an Equal Opportunity Employer and provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, sexual and reproductive health choices, national origin, citizenship, age, genetic information, disability, or veteran status. MSG complies with all applicable federal, state, and local laws governing nondiscrimination, including considering requests for reasonable accommodations as required.