Rodeo
Get started

Sony Music Publishing

IT Compliance Specialist

London
Posted about 20 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

At Sony Music Publishing (“SMP”), we believe every voice matters.

We are the #1 global music publisher, advancing the artistry of the world’s greatest songwriters and composers for over 25 years. We keep songwriters at the forefront of everything we do, and design our suite of services to amplify opportunities, build connections, and defend their rights. Our roster benefits from an international team committed to providing support at every career stage. From classic catalogues to contemporary hitmakers, history is always being written. We are a part of the Sony family of global companies. Learn more about SMP here.

Why join Sony Music Group?

Here at Sony Music Group, we are shaping what’s next in a way that creates impact. Forging powerful new ideas at the heart of music, technology, and culture that entertain and move people.

This is your opportunity to be part of a global community, united by individual passion, rising to that challenge every day. Adapting at pace and supporting one another, inspired to influence the future. For the benefit of you, our people; our creators, our business, and wider society too.

Be a part of an organization that is creator first. Committed to fueling excellence and always imagining more, while fostering a supportive culture, one where we elevate each other and act responsibly.

About the Department

Sony Music Publishing's IT team oversees technology, systems, applications, and software services across our global business. We work closely with teams around the world to deliver secure, reliable, and innovative technology solutions that support our employees, songwriters, and partners.

About the Role

We are seeking an IT Compliance Specialist to help ensure our technology systems, processes, and practices comply with internal policies, industry standards, contractual obligations, and regulatory requirements.

This role partners closely with Infrastructure, Security, Service Management, Privacy, Internal Audit, Legal, Finance, and business stakeholders to establish, monitor, and improve IT controls, compliance programmes, risk management activities, and audit readiness.

The successful candidate will help build and maintain a culture of compliance while enabling business objectives through practical governance processes and continuous improvement initiatives.

What You'll Do

Compliance & Governance

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

  • Support the development, implementation, and maintenance of IT compliance programmes, policies, standards, and procedures.
  • Ensure alignment with regulatory and industry frameworks including SOX, ISO 27001, SOC 1/SOC 2, NIST Cybersecurity Framework, CIS Controls, GDPR, and other privacy requirements.
  • Maintain governance documentation, control inventories, and compliance evidence repositories.
  • Monitor regulatory changes and assess their impact on technology operations and services.

Risk Management

  • Conduct compliance and risk assessments across technology systems, processes, vendors, and business practices.
  • Identify control gaps and partner with stakeholders to implement remediation plans.
  • Track compliance-related risks through mitigation and resolution.
  • Maintain risk registers and provide regular reporting to leadership.

Audit Support

  • Coordinate internal and external audits, assessments, and certification activities.
  • Collect, review, and organise audit evidence.
  • Facilitate meetings with auditors and key stakeholders.
  • Track audit findings and corrective actions through to completion.
  • Develop reports and dashboards that demonstrate compliance posture and audit readiness.

Policy & Control Management

  • Review IT processes and controls to ensure effectiveness and compliance.
  • Support control design, testing, documentation, and ongoing monitoring activities.
  • Assist with compliance requirements related to change management, access management, incident management, and business continuity.
  • Ensure documentation remains current and aligned with organisational standards.

Vendor & Third-Party Compliance

  • Participate in vendor risk assessments and due diligence reviews.
  • Evaluate third-party security and compliance documentation.
  • Track vendor compliance obligations and contractual security requirements.
  • Support remediation planning for identified vendor risks.

Training & Awareness

  • Promote compliance awareness across the IT organisation.
  • Assist in developing training materials and educational programmes.
  • Provide guidance to technical teams on compliance obligations and best practices.
  • Support a culture of accountability, governance, and continuous improvement.

Who You Are

Qualifications

  • Bachelor's degree in Information Technology, Information Security, Computer Science, Business Administration, or a related field, or equivalent relevant experience.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Experience

  • 3-5+ years of experience in IT compliance, IT audit, risk management, cybersecurity, governance, or a related field.
  • Experience supporting regulatory, security, or compliance programmes.
  • Experience coordinating audits and managing remediation activities.
  • Familiarity with enterprise IT environments, including infrastructure, cloud services, applications, and service management processes.

Required Knowledge & Skills

  • Strong understanding of IT governance and compliance principles.
  • Knowledge of frameworks and standards such as ISO 27001, NIST, SOC, SOX, and CIS Controls.
  • Understanding of ITIL processes, including Change, Incident, Problem, and Access Management.
  • Strong analytical, problem-solving, and critical-thinking skills.
  • Ability to analyse policies, controls, procedures, and technical configurations.
  • Excellent documentation, reporting, organisational, verbal, and written communication skills.
  • Ability to communicate complex compliance requirements to both technical and non-technical audiences.
  • Ability to manage multiple priorities in a fast-paced environment.

Preferred Qualifications

  • Professional certifications such as CISA, CRISC, CGRC, CISSP, CISM, or ISO 27001 Lead Implementer/Lead Auditor.
  • Experience with ServiceNow, Jira, Microsoft 365 Compliance, GRC platforms, and cloud environments such as AWS, Azure, or GCP.

What We Offer

  • An inclusive, collaborative, and global working environment.
  • Opportunities to learn, grow, and develop your career.
  • Exposure to a broad range of technology, compliance, and risk management activities.
  • Networking opportunities with IT and business professionals across the organisation.
  • A culture that values collaboration, innovation, and continuous improvement.

Equal Opportunities

As an active part of a culturally and socially diverse society, Sony Music Group’s aim is that our workforce is diverse and inclusive. Sony Music Publishing is an equal opportunity employer and supports workforce diversity.

We employ, retain, promote and otherwise treat all employees and job applicants according to their merit, qualifications, competence and talent. We apply this policy without regard to any individual’s sex, race, religion, origin, age, sexual orientation, marital status, medical condition or disability.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

London, England, United Kingdom

Sign up to applySee more jobs like this