Executive Director, InfoSec Governance, Risk, and Compliance
Listed on 2026-06-17
-
IT/Tech
Cybersecurity, Information Security
Executive Director, Info Sec Governance, Risk, and Compliance
Job :
Location: Seattle, Washington;
Glendale, California;
New York, New York;
Orlando, Florida
Business: The Walt Disney Company (Corporate)
Date posted: Jun. 01, 2026
Job SummaryAt Disney, we’re storytellers. We make the impossible, possible. The Walt Disney Company (TWDC) is a world‑class entertainment and technological leader. Walt’s passion was to continuously envision new ways to move audiences around the world—a passion that remains our touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, news, movies and a variety of other businesses.
Uniting each endeavour is a commitment to creating and delivering unforgettable experiences— and we’re constantly looking for new ways to enhance these exciting experiences.
The Enterprise Technology mission is to deliver technology solutions that align to business strategies while enabling enterprise efficiency and promoting cross‑company collaborative innovation. Our group drives competitive advantage by enhancing our consumer experiences, enabling business growth, and advancing operational excellence.
Team Description- Reduce the risk of both accidental and malicious data disclosure.
- Identify, monitor, engage with a complete inventory of information.
- Establish appropriate policies and procedures to be followed.
- Educate user community to minimize risk.
- Drive the evolution of Disney’s Info Sec GRC program from a compliance‑centric model to a dynamic, risk‑intelligence‑led capability that informs enterprise investment and prioritization decisions.
- Define and elevate GRC standards by introducing innovative approaches to risk quantification, compliance automation, and integrated governance.
- Partner with GIS and segment technology leadership to position GRC as a strategic business enabler, translating complex risks into actionable, executive‑ready insights.
- Champion a culture where risk awareness is embedded into daily decision‑making, enabling intuitive and scalable risk‑informed behaviours across the enterprise.
- Lead the design, implementation, and continuous improvement of Disney’s enterprise Info Sec Risk Management Framework.
- Establish and operationalize risk tolerance models, translating business objectives into clear prioritization, investment, and remediation decisions.
- Build and mature a centralized cybersecurity risk register integrating threat intelligence, vulnerabilities, and third‑party risk data.
- Drive risk‑based prioritization across Info Sec functions to ensure measurable risk reduction and alignment to enterprise objectives.
- Deliver clear, credible, and decision‑ready risk reporting to executive leadership and the Board, including financial risk quantification (e.g., FAIR).
- Oversee the full lifecycle of Info Sec policies, standards, and guidelines, ensuring they are risk‑based, actionable, and aligned with business needs.
- Embed governance controls into the technology lifecycle (e.g., Dev Sec Ops , cloud, infrastructure‑as‑code), reducing reliance on manual processes through automation.
- Establish a policy effectiveness framework focused on behavioral change and measurable risk reduction.
- Define and advance governance strategies for emerging technologies, including AI/ML, quantum security, and autonomous systems.
- Lead enterprise maturity assessments (e.g., NIST CSF) to identify gaps and inform strategic investment decisions.
- Provide oversight of global regulatory and contractual compliance programs (e.g., SOX, PCI, GDPR, ISO), ensuring consistency and scalability.
- Build and operationalize a “compliance‑as‑a‑service” model that enables self‑service, automates evidence collection, and minimizes burden on engineering teams.
- Monitor and anticipate changes in the regulatory landscape, proactively positioning Disney to meet evolving requirements.
- Lead, develop, and scale a high‑performing global GRC organization, fostering a culture of accountability, innovation, and continuous improvement.
- Drive organizational excellence…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).