Jobs · Business Development · Washington

Executive Director, InfoSec Governance, Risk, and Compliance

The Walt Disney Company · Seattle, WA · 1 mo ago
On-siteBusiness Development$198k–$265k/yrFull-time

Responsibilities

  • Drive the evolution of Disney’s InfoSec GRC program from a compliance-centric model to a dynamic, risk-intelligence-led capability that informs enterprise investment and prioritization decisions
  • Define and elevate GRC standards by introducing innovative approaches to risk quantification, compliance automation, and integrated governance
  • Partner with GIS and segment technology leadership to position GRC as a strategic business enabler, translating complex risks into actionable, executive-ready insights
  • Champion a culture where risk awareness is embedded into daily decision-making, enabling intuitive and scalable risk-informed behaviors across the enterprise
  • Risk Management Leadership: - Lead the design, implementation, and continuous improvement of Disney’s enterprise InfoSec Risk Management Framework - Establish and operationalize risk tolerance models, translating business objectives into clear prioritization, investment, and remediation decisions - Build and mature a centralized cybersecurity risk register integrating threat intelligence, vulnerabilities, and third-party risk data - Drive risk-based prioritization across InfoSec functions to ensure measurable risk reduction and alignment to enterprise objectives - Deliver clear, credible, and decision-ready risk reporting to executive leadership and the Board, including financial risk quantification (e.g., FAIR)
  • Governance Program Leadership: - Oversee the full lifecycle of InfoSec policies, standards, and guidelines, ensuring they are risk-based, actionable, and aligned with business needs - Embed governance controls into the technology lifecycle (e.g., DevSecOps, cloud, infrastructure-as-code), reducing reliance on manual processes through automation - Establish a policy effectiveness framework focused on behavioral change and measurable risk reduction - Define and advance governance strategies for emerging technologies, including AI/ML, quantum security, and autonomous systems - Lead enterprise maturity assessments (e.g., NIST CSF) to identify gaps and inform strategic investment decisions
  • Compliance Program Leadership: - Provide oversight of global regulatory and contractual compliance programs (e.g., SOX, PCI, GDPR, ISO), ensuring consistency and scalability - Build and operationalize a “compliance-as-a-service” model that enables self-service, automates evidence collection, and minimizes burden on engineering teams - Monitor and anticipate changes in the regulatory landscape, proactively positioning Disney to meet evolving requirements
  • Organizational Leadership: - Lead, develop, and scale a high-performing global GRC organization, fostering a culture of accountability, innovation, and continuous improvement - Drive organizational excellence through strong leadership, talent development, and a focus on delivering scalable, forward-looking solutions

Requirements

  • You will have 12+ years of progressive experience in cybersecurity, technology risk, or compliance, including 3+ years leading enterprise-scale GRC functions
  • You will bring structured problem-solving, audit rigor, and enterprise advisory experience
  • You will have industry experience within large, complex organizations, with the ability to operate effectively in highly matrixed environments
  • You will have a proven track record of transforming GRC programs into risk-driven operating models that influence enterprise decision-making
  • You will have deep expertise across risk management, governance, and compliance, including frameworks, policy lifecycle, automation, audit, and controls assurance
  • You will have strong working knowledge of industry frameworks and regulations, including NIST CSF, NIST 800-53, ISO 27001, PCI DSS 4.0, SOX ITGC, and GDPR
  • You will have demonstrated executive presence and exceptional influence skills, with the ability to operate as a trusted advisor to senior leadership and translate complex technical risk into clear business insights
  • You will have experience applying financial risk quantification methodologies (e.g., FAIR) to support investment and prioritization decisions
  • You will have a strong customer-focused mindset, ensuring GRC solutions enable the business and enhance—not hinder—user and product experiences
  • You will have experience leading in highly matrixed, global environments, driving alignment across engineering, security, and business stakeholders

Qualifications

  • You will have a bachelor’s degree in computer science, information security, or a related field—or equivalent practical experience
  • You may have advanced degrees or relevant certifications (e.g., CISSP, CISM, CRISC)

Benefits

  • The hiring range for this position varies based on location.

Pay

  • The base pay range for this position in Orlando, FL is $197,500 to $265,000 per year
  • The base pay range for this position in Glendale, CA is $207,400 to $278,200 per year
  • The base pay range for this position in Seattle, WA is $217,300 to $291,500 per year
  • The base pay range for this position in New York, NY is $217,300 to $291,500 per year

Schedule

  • The schedule for this position varies based on location.

Similar jobs

Director, Information Governance

Otsuka Pharmaceutical Companies (U.S.)Princeton, NJ· 1 mo ago
Information Technology$186k/yrapply on vhr-otsuka.wd1.myworkdayjobs.com

Head of Infosec

ZiplineSouth San Francisco, CA· 2 days ago
Information Technologyapply on zipline.com