Executive Director, Info Security
Job Summary:
Department Description
At Disney, we’re storytellers. We make the impossible, possible. The Walt Disney Company is a world-class entertainment and technological leader. Walt’s passion was to continuously envision new ways to move audiences around the world - a passion that remains our touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, TV, movies and a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences - and we’re constantly looking for new ways to enhance these exciting experiences.
The Enterprise Technology & Data mission is to deliver technology solutions that align to business strategies while enabling enterprise efficiency and promoting cross-company collaborative innovation. Our group drives competitive advantage by enhancing our consumer experiences, enabling business growth, and advancing operational excellence. Global Information Security (GIS) provides services to protect the value and use of Disney’s information through collaboration, empowerment, and education across The Walt Disney Company.
Team Description:
At Disney, innovation and imagination fuel everything we do. The InfoSec Governance, Risk & Compliance (GRC) team is not just a guardian of standards - we are leaders who drive the evolution of information security. As a strategic powerhouse in the GIS organization, our mission transcends compliance, setting new benchmarks for risk intelligence, automation, and integrated governance. We aim to redefine what “great” looks like, pioneering visionary approaches that shape how Disney (and the industry) understands and manages security risk.
The GRC team is the pulse of Disney’s enterprise technology ecosystem. We don’t just follow regulatory mandates; we leap ahead, leveraging data-driven insights, advanced risk quantification, and automated control frameworks to empower business leaders and technologists. Our collaborative culture ensures that every corner of GIS speaks a unified risk language, propelling risk-aware thinking to the forefront of daily business decisions and fueling cross-company innovation.
By joining this team, you become a change agent, transforming GRC from a “checkbox” function to a dynamic, strategic enabler. You will lead and inspire a diverse, high-performing group that anticipates emerging risk domains, shapes industry-leading policy design, and drives measurable, business-aligned security outcomes. If your passion is to advance, not just meet, industry standards, and to make a lasting impact on a legendary brand’s global footprint, the InfoSec GRC team at Disney is your stage.
Responsibilities of Role (List in order of priority, first few bullets should be the most important):
- Transform GRC at Disney
- Drive continous evolution of Disney’s InfoSec GRC program, replacing compliance-centric, checkbox-driven operations with a dynamic, risk-intelligence-led model that directly informs how Disney prioritizes investment, staffing, and remediation.
- Define what “great” looks like, not by referencing existing standards but by advancing them. Develop novel approaches to risk quantification, compliance automation, and governance integration.
- Partner with GIS Leadership and Segment CTO teams to ensure the GRC program functions as a strategic business enabler, translating complex risk landscapes into executive- and board-ready insights that drive confident decision-making.
- Champion a culture shift across all of GIS and the broader enterprise: risk awareness is everyone’s job, and GRC’s role is to make risk-informed thinking intuitive, not burdensome.
- Risk Management Leadership
- Oversee the development and ongoing operations of Disney’s comprehensive InfoSec Risk Management program, including the establishment, implementation, and continuous improvement of the enterprise Risk Management Framework.
- Establish and operationalize risk tolerance frameworks in partnership with executive leadership, defining clear thresholds that translate business appetite into actionable security investment and prioritization decisions.
- Build and mature a cybersecurity risk register that serves as the authoritative source of truth for Disney’s threat and control posture, dynamically integrated with threat intelligence, vulnerability management, and third-party risk inputs.
- Drive risk-based prioritization across all InfoSec operational functions (engineering, red team, SOC, cloud security, etc.) - ensuring that every team’s roadmap is anchored in defensible risk reduction rationale, not reactive urgency.
- Develop executive and board-level risk reporting that is clear, credible, and decision-ready; ensure Disney’s risk narrative is consistent from the CISO to the Audit Committee.
- Lead efforts to quantify InfoSec risk in financial terms (FAIR or equivalent), enabling direct comparison of security investment across Disney’s ubiquitous businesses and against measurable risk reduction outcomes.
- Lead a third-party and supply chain risk intelligence capability that goes beyond questionnaire-based assessments by integrating continuous external attack surface monitoring, threat intelligence on vendor compromise activity, and contractual control requirements into a unified third-party risk posture.
- Governance Program Leadership
- Oversee the development, maintenance, and lifecycle management of enterprise-wide Information Security policies, standards, and guidelines, ensuring they are risk-based, clear, and aligned to business realities (not just regulatory checklists).
- Drive automated policy enforcement and integration of governance requirements into the technology design lifecycle (DevSecOps, cloud provisioning, infrastructure-as-code, etc.), reducing reliance on manual control operations and attestation.
- Lead the development of a policy effectiveness measurement framework that moves beyond “is the policy published and attested to?” toward “is the policy actually changing behavior and reducing risk?” (tracked via control telemetry, exception rates, and risk outcome data).
- Pioneer a forward-looking policy architecture that anticipates emerging technology risk domains (AI/ML model governance, quantum-safe cryptography transition, agentic automation).
- Oversee annual NIST CSF assessments and provide rigorous, actionable reporting to the CISO and senior leadership on program maturity and investment gaps.
- In partnership with ISO teams, lead the Governance team in providing consultation to segments and business units, ensuring security requirements are understood, contextualized, and achievable - not perceived as obstacles.
- Compliance Program Leadership
- Provide oversight across all regulatory, contractual, and policy compliance programs, including SOX 404, PCI DSS, K-ISMS, GDPR, COPPA, ISO 27001, and more.
- Build compliance-as-a-service capabilities for technology teams: engineers and product owners access a self-service portal to understand what compliance requirements apply to their system, what controls are already satisfied by platform-level implementations they inherit, what evidence is auto-collected on their behalf, and what residual actions remain — compliance burden on tech teams is measured and systematically driven toward zero.
- Proactively monitor the regulatory horizon: identify emerging requirements before they become mandates, and position Disney to comply with confidence rather than scrambling.
- Organizational Leadership
- Lead, develop, and inspire a high-performing organization of ~40+ professionals across Governance, Compliance, and Risk Management.
- Model and demand intellectual rigor, ownership, and a continuous improvement mindset - leading a team that challenges assumptions, identifies root causes, and delivers scalable and dynamic solutions.
Must Haves (Years of Experience, languages, programs, tools, etc.):
- Experience & Expertise
- 12+ years of progressive experience in cybersecurity, technology risk, or technology compliance, with a minimum of 3 years in leadership roles overseeing GRC functions at enterprise scale.
- Demonstrated track record of building and transforming GRC programs, moving organizations to risk-driven operating models.
- Deep expertise across the full GRC spectrum: risk management (frameworks, quantification, reporting), governance (policy lifecycle, automated enforcement, metrics), and compliance (regulatory audit management, controls assurance, overall audit alignment).
- Extensive knowledge of information security risk, governance, and control frameworks: NIST CSF, NIST 800-53, ISO/IEC 27001, PCI DSS 4.0, SOX ITGC, GDPR.
- Proven executive presence: ability to command a room, build trust with senior leadership, and translate highly technical risk concepts into clear business language.
- Strong experience in risk quantification methodologies (FAIR or equivalent) and experience driving financial-terms risk reporting for executive audiences.
- Technical Knowledge
- Expert-level understanding of security audit methodologies, controls testing, and assurance processes across both IT general controls (ITGCs) and automated application controls.
- Hands-on familiarity with implementing and operating GRC tooling and platforms (Archer, SailPoint, ServiceNow GRC, or equivalent).
- Solid understanding of cloud security architecture and the compliance implications of cloud-native environments (IaaS, PaaS, SaaS) across major providers (AWS, Azure, GCP).
- Familiarity with DevSecOps practices and the integration of security governance and compliance controls into software development and infrastructure deployment pipelines.
Nice To Haves (see above):
- Experience in the Media & Entertainment, Sports, Hospitality, and/or Retail industries.
- An understanding of the unique regulatory, content protection, and consumer-facing risks and compliance requirements of a global entertainment brand.
- Big 4 accounting firm experience (audit or advisory) with direct exposure to Fortune 100 technology and security compliance programs.
- CPA certification (active or expired).
- Experience operating in a large, complex, matrixed enterprise with multiple business segments, regulatory regimes, and stakeholder groups.
Education:
- Bachelor’s degree in Computer Science, Information Systems, Software, Electrical or Electronics Engineering, or comparable field of study, and/or equivalent work experience.
- One or more of the following certifications required: CISSP, CISM, CISA, CRISC.
The hiring range for this position in Orlando, FL is $197,500 to $265,000 per year and in Glendale,CA is $207,400 to $278,200 per year. The hiring range for this position in Seattle, WA is $217,300 to $291,500 per year and in New York, NY is $217,300 to $291,500 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate’s geographic region, job-related knowledge, skills, and experience among other factors. A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.
About The Walt Disney Company (Corporate):
At Disney Corporate you can see how the businesses behind the Company’s powerful brands come together to create the most innovative, far-reaching and admired entertainment company in the world. As a member of a corporate team, you’ll work with world-class leaders driving the strategies that keep The Walt Disney Company at the leading edge of entertainment. See and be seen by other innovative thinkers as you enable the greatest storytellers in the world to create memories for millions of families around the globe.
About The Walt Disney Company:
The Walt Disney Company, together with its subsidiaries and affiliates, is a leading diversified international family entertainment and media enterprise that includes three core business segments: Disney Entertainment, ESPN, and Disney Experiences. From humble beginnings as a cartoon studio in the 1920s to its preeminent name in the entertainment industry today, Disney proudly continues its legacy of creating world-class stories and experiences for every member of the family. Disney’s stories, characters and experiences reach consumers and guests from every corner of the globe. With operations in more than 40 countries, our employees and cast members work together to create entertainment experiences that are both universally and locally cherished.
This position is with Disney Worldwide Services, Inc., which is part of a business we call The Walt Disney Company (Corporate).
Disney Worldwide Services, Inc. is an equal opportunity employer. Applicants will receive consideration for employment without regard to race, religion, color, sex, sexual orientation, gender, gender identity, gender expression, national origin, ancestry, age, marital status, military or veteran status, medical condition, genetic information or disability, or any other basis prohibited by federal, state or local law. Disney champions a business environment where ideas and decisions from all people help us grow, innovate, create the best stories and be relevant in a constantly evolving world.
DISABILITY ACCOMMODATION FOR EMPLOYMENT APPLICATIONS
The Walt Disney Company and its Affiliated Companies are Equal Employment Opportunity employers and welcome all job seekers including individuals with disabilities and veterans with disabilities. If you have a disability and believe you need a reasonable accommodation in order to search for a job opening or apply for a position, visit the Disney candidate disability accommodations FAQs. We will only respond to those requests that are related to the accessibility of the online application system due to a disability.
Having technical issues? View the FAQs for help.
Hiring Process
-
Where Does Your Story Begin?
Explore Disney Careers and the Life at Disney blog to learn about all the amazing opportunities waiting to be discovered at The Walt Disney Company.
-
Be Part of the Story
There are many different brands and businesses to explore. Once you've found the opportunity that is right for you, take the next step by completing your application.
-
The Next Chapter
Once you've applied, you will receive an email allowing you to access your candidate dashboard. Create your login and make sure to check your dashboard often to see your application progress.
Explore this Location Seattle, WA
With a thriving food-and-drink scene, eclectic neighborhoods and a stunning coastal setting, Seattle is a dynamic urban enclave nestled in the Pacific Northwest. The city is bounded by Lake Washington in the east and Puget Sound to the west, an ideal location for water recreation and sight-seeing cruises.
Related Jobs
- Senior VMO Operations Specialist (Project Hire) The Walt Disney Company (Corporate) 10142042 Burbank, California / Orlando, Florida Apply
- Senior Software Engineer The Walt Disney Company (Corporate) 10134272 Burbank, California / Santa Monica, California / Seattle, Washington / Orlando, Florida Apply
- Security Engineer - Security Architecture and Engineering The Walt Disney Company (Corporate) 10137015 Burbank, California / Orlando, Florida / Seattle, Washington Apply
OUR CULTURE
Related Content
-
Diversity, Equity, and Inclusion To Be Young, Gifted, and Black: Wisdom and Stories from Emerging Black Leaders at Disney -
Career Development Employee Stories A Day in the Life of Anthony, a Disney Recreation Coordinator -
Employee Stories Will, Disney Cruise Line HR manager and Navy veteran, supports crew and discovers his own Disney magic -
Career Opportunities Employee Stories Nontraditional Career Paths Lead to Technology & Digital Opportunities at Disney Parks -
Career Opportunities Employee Stories Taking a Chance and Finding a Dream Job: Meet Kati, Ride & Show Technician -
Career Opportunities Employee Stories Disney Cruise Line cast delivers magic in The Bahamas -
Hiring Process Employee Stories Unlock the Magic: Your Guide to Disney College Program Character Performer Auditions -
Diversity, Equity, and Inclusion Employee Stories Celebrate Black History Month: How Their Stories Inspire Others to Dream -
Career Opportunities Disney Cruise Line manager of HR shares new opportunities in The Bahamas -
Career Development Employee Stories Disney Chefs Share Their Advice for Aspiring Culinary Talent -
Career Opportunities Students & Recent Graduates Dreams Take Flight with UK Early Careers -
Career Development Diversity, Equity, and Inclusion Employee Stories Q&A with Domi Flores-Wong: A Nontraditional Career Path into Technology at Disney -
Employee Stories Students & Recent Graduates Meet 3 Japanese Trainees Starting Their Career With Disney -
Diversity, Equity, and Inclusion Culture & Values Employee Stories Meet Artemis: EMEA Talent Acquisition Intern -
Benefits Culture & Values Disney named Top Adoption-Friendly Workplace -
Career Opportunities Diversity, Equity, and Inclusion National Geographic Announces Third Year of Field Ready Program -
Employee Stories Students & Recent Graduates Ireland Intern Spotlight: Meet Ellen and Karla! -
Diversity, Equity, and Inclusion Employee Stories Celebrate Black History Month: Why the Work We Do Matters -
Career Development Diversity, Equity, and Inclusion Employee Stories Bringing Passion Through Storytelling: Meet Staff Writer, Zaire! -
Career Development Employee Stories Work & Innovation From Concept to Console: Meet Winslow, Producer III, Disney Games -
Career Development Diversity, Equity, and Inclusion Four Women in Leadership Growing Their Careers in Japan -
Employee Stories Creating a Culture of Safety: Meet Krista -
Career Development Employee Stories Creating Home-Away-From-Home Magic as a Houseman at Disneyland Resort -
Employee Stories Behind the Magic with Jenn, Disney Vacation Club Project Manager -
Employee Stories Work & Innovation Creating Wonders & Ensuring Safety: Meet Jana, Structural Engineer, Disneyland Resort -
Culture & Values Students & Recent Graduates Disney Internships Lead to Magical Friendships and Careers at Hong Kong Disneyland Resort -
Career Opportunities Career Development Disney Cruise Line’s leadership team in The Bahamas on growth, building careers, and making magic -
Diversity, Equity, and Inclusion Culture & Values Employee Stories Women + Tech BERG Spotlight: Meet Four Female Technologists -
Diversity, Equity, and Inclusion Culture & Values Employee Stories Work & Innovation Students & Recent Graduates Life at Disney: Hong Kong Disneyland Resort -
Career Opportunities Employee Stories Students & Recent Graduates A Dream to Perform Comes True for a Disney Intern at Hong Kong Disneyland -
Career Opportunities Employee Stories Ben’s Journey from Human Resources to Facility Services -
Culture & Values Employee Stories Growing a Garden of Magic at Hong Kong Disneyland -
Employee Stories Students & Recent Graduates From Disney Internships to Beyond: Meet Three Hong Kong Disneyland Resort Cast Members Making an Impact -
Employee Stories Students & Recent Graduates Disney Internships Lead to Magical Friendships and Careers at Hong Kong Disneyland Resort -
Employee Stories Finding New Angles with Data Science: Meet Henry -
-
-
-
Job Resources Benefits Benefits - Disney Cruise Line Shipboard Roles -
Job Resources Benefits Benefits - Disney Cruise Line Island Roles -
Employee Stories Ben’s Journey from Human Resources to Facility Services -
Students & Recent Graduates Disney International Programs -
-
Diversity, Equity, and Inclusion Culture & Values Employee Stories Students & Recent Graduates Disney on the Yard -
Job Resources Benefits Benefits - Disney Cruise Line Shoreside Roles -
Employee Stories From Shore to Sea: Simon, Manager, Fleet Operations Training -
Career Opportunities Career Development Diversity, Equity, and Inclusion Culture & Values Employee Stories Students & Recent Graduates Life at Disney Podcast | Building Your Career at Disney: Lessons From Former Interns Around the World -
Career Development Employee Stories Disney Cruise Line’s leadership team in The Bahamas on growth, building careers, and making magic -
Employee Stories Unlocking career dreams with Disney Cruise Line: Jarrett’s journey as a Third Officer Postgraduate -
-
Culture & Values Employee Stories Learn about the vibrant culture of The Walt Disney Company Latin America! -
Employee Stories Work & Innovation Mexico Internships & Apprenticeships: Here’s What You Need To Know -
Career Opportunities Disneyland Resort Hiring Events -
Employee Stories Creating Magical Narratives: Bill’s Journey to Storyliving by Disney -
Career Opportunities Career Development Students & Recent Graduates Pixar Internships and Residences -
Career Opportunities Career Development Students & Recent Graduates Jedi Academy | Industrial Light & Magic -
Career Opportunities Career Development Students & Recent Graduates Marvel Internships -
Career Opportunities Disneyland Resort Culinary Hiring Events -
Benefits The Walt Disney Company Benefits -
Students & Recent Graduates What My Disney Internship Taught Me – As Told By Disney Songs -
Culture & Values A Wish Every Hour of Every Day
-
Executive Leadership
Our senior executives bring tremendous experience, visionary thinking and a shared commitment to excellence, creativity and innovation to the day to day operation of the company.
Learn more -
Social Responsibility
Explore our commitments and our work to create a better world through our stories, experiences, operations, and philanthropy.
Learn more -
Inclusion
At Disney, we want everyone to belong and thrive. Creating a welcoming and respectful environment for our employees and guests is core to our company culture and our business. We strive to build supportive work environments that drive innovation and reinforce a culture in which all employees feel welcome, respected, and valued.
Learn more -
Heroes Work Here
Heroes Work Here reflects the long history of respect and appreciation Disney has for the U.S. Armed Services. We recognize the commitment and dedication it takes to serve your country, both as military personnel and military spouses, and value the leadership skills and sense of purpose it has instilled in you.
Learn more
Sign Up for Job Alerts
Get the latest job opportunities as they become available.
SHARE
Links open in new tabs.