Executive Director, InfoSec Governance, Risk, and Compliance
The Walt Disney Company · Seattle, WA · 1 mo ago
On-siteBusiness Development$198k–$265k/yrFull-time
Responsibilities
- Drive the evolution of Disney’s InfoSec GRC program from a compliance-centric model to a dynamic, risk-intelligence-led capability that informs enterprise investment and prioritization decisions
- Define and elevate GRC standards by introducing innovative approaches to risk quantification, compliance automation, and integrated governance
- Partner with GIS and segment technology leadership to position GRC as a strategic business enabler, translating complex risks into actionable, executive-ready insights
- Champion a culture where risk awareness is embedded into daily decision-making, enabling intuitive and scalable risk-informed behaviors across the enterprise
- Risk Management Leadership: - Lead the design, implementation, and continuous improvement of Disney’s enterprise InfoSec Risk Management Framework - Establish and operationalize risk tolerance models, translating business objectives into clear prioritization, investment, and remediation decisions - Build and mature a centralized cybersecurity risk register integrating threat intelligence, vulnerabilities, and third-party risk data - Drive risk-based prioritization across InfoSec functions to ensure measurable risk reduction and alignment to enterprise objectives - Deliver clear, credible, and decision-ready risk reporting to executive leadership and the Board, including financial risk quantification (e.g., FAIR)
- Governance Program Leadership: - Oversee the full lifecycle of InfoSec policies, standards, and guidelines, ensuring they are risk-based, actionable, and aligned with business needs - Embed governance controls into the technology lifecycle (e.g., DevSecOps, cloud, infrastructure-as-code), reducing reliance on manual processes through automation - Establish a policy effectiveness framework focused on behavioral change and measurable risk reduction - Define and advance governance strategies for emerging technologies, including AI/ML, quantum security, and autonomous systems - Lead enterprise maturity assessments (e.g., NIST CSF) to identify gaps and inform strategic investment decisions
- Compliance Program Leadership: - Provide oversight of global regulatory and contractual compliance programs (e.g., SOX, PCI, GDPR, ISO), ensuring consistency and scalability - Build and operationalize a “compliance-as-a-service” model that enables self-service, automates evidence collection, and minimizes burden on engineering teams - Monitor and anticipate changes in the regulatory landscape, proactively positioning Disney to meet evolving requirements
- Organizational Leadership: - Lead, develop, and scale a high-performing global GRC organization, fostering a culture of accountability, innovation, and continuous improvement - Drive organizational excellence through strong leadership, talent development, and a focus on delivering scalable, forward-looking solutions
Requirements
- You will have 12+ years of progressive experience in cybersecurity, technology risk, or compliance, including 3+ years leading enterprise-scale GRC functions
- You will bring structured problem-solving, audit rigor, and enterprise advisory experience
- You will have industry experience within large, complex organizations, with the ability to operate effectively in highly matrixed environments
- You will have a proven track record of transforming GRC programs into risk-driven operating models that influence enterprise decision-making
- You will have deep expertise across risk management, governance, and compliance, including frameworks, policy lifecycle, automation, audit, and controls assurance
- You will have strong working knowledge of industry frameworks and regulations, including NIST CSF, NIST 800-53, ISO 27001, PCI DSS 4.0, SOX ITGC, and GDPR
- You will have demonstrated executive presence and exceptional influence skills, with the ability to operate as a trusted advisor to senior leadership and translate complex technical risk into clear business insights
- You will have experience applying financial risk quantification methodologies (e.g., FAIR) to support investment and prioritization decisions
- You will have a strong customer-focused mindset, ensuring GRC solutions enable the business and enhance—not hinder—user and product experiences
- You will have experience leading in highly matrixed, global environments, driving alignment across engineering, security, and business stakeholders
Qualifications
- You will have a bachelor’s degree in computer science, information security, or a related field—or equivalent practical experience
- You may have advanced degrees or relevant certifications (e.g., CISSP, CISM, CRISC)
Benefits
- The hiring range for this position varies based on location.
Pay
- The base pay range for this position in Orlando, FL is $197,500 to $265,000 per year
- The base pay range for this position in Glendale, CA is $207,400 to $278,200 per year
- The base pay range for this position in Seattle, WA is $217,300 to $291,500 per year
- The base pay range for this position in New York, NY is $217,300 to $291,500 per year
Schedule
- The schedule for this position varies based on location.