メインコンテンツにスキップ

Executive Director, InfoSec Governance, Risk, & Compliance

ジョブID 10151183 勤務地を選択 グレンデール, カリフォルニア州, アメリカ合衆国 / ニューヨーク, ニューヨーク州, アメリカ合衆国 / シアトル, ワシントン州, アメリカ合衆国 / Lake Buena Vista, フロリダ州, アメリカ合衆国 企業名 The Walt Disney Company (Corporate) 掲載日 May 26, 2026
今すぐ応募

仕事内容:

At Disney, we’re storytellers. We make the impossible, possible. The Walt Disney Company (TWDC) is a world-class entertainment and technological leader. Walt’s passion was to continuously envision new ways to move audiences around the world—a passion that remains our touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, news, movies and a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences — and we’re constantly looking for new ways to enhance these exciting experiences.  

The Enterprise Technology mission is to deliver technology solutions that align to business strategies while enabling enterprise efficiency and promoting cross-company collaborative innovation. Our group drives competitive advantage by enhancing our consumer experiences, enabling business growth, and advancing operational excellence.  

Team Description: 

The Global Information Security (GIS) group provides services to protect the value and use of Disney’s information through collaboration, standardization, enforcement, and education across The Walt Disney Company. The main focus areas of this group are: Reduce the risk of both accidental and malicious data disclosure; Identify, monitor, engage with complete inventory of information; Establish appropriate policies and procedures to be followed; Educate user community to minimize risk. 

Disney’s InfoSec GRC team is seeking a transformational leader to drive the next evolution of Governance, Risk, and Compliance across the enterprise. Reporting to the VP of Information Security, this role will lead the shift from a traditional compliance-driven approach to a modern, risk-intelligence-led model that enables better business decisions, strengthens security posture, and scales with Disney’s global technology and content ecosystem. This leader will partner closely with GIS and business leadership to embed risk awareness into daily operations, ensuring GRC is a strategic enabler of innovation—not a barrier. 

What You'll Do 

Transform GRC at Disney 

  • Drive the evolution of Disney’s InfoSec GRC program from a compliance-centric model to a dynamic, risk-intelligence-led capability that informs enterprise investment and prioritization decisions 

  • Define and elevate GRC standards by introducing innovative approaches to risk quantification, compliance automation, and integrated governance 

  • Partner with GIS and segment technology leadership to position GRC as a strategic business enabler, translating complex risks into actionable, executive-ready insights 

  • Champion a culture where risk awareness is embedded into daily decision-making, enabling intuitive and scalable risk-informed behaviors across the enterprise 

 

Risk Management Leadership 

  • Lead the design, implementation, and continuous improvement of Disney’s enterprise InfoSec Risk Management Framework 

  • Establish and operationalize risk tolerance models, translating business objectives into clear prioritization, investment, and remediation decisions 

  • Build and mature a centralized cybersecurity risk register integrating threat intelligence, vulnerabilities, and third-party risk data 

  • Drive risk-based prioritization across InfoSec functions to ensure measurable risk reduction and alignment to enterprise objectives 

  • Deliver clear, credible, and decision-ready risk reporting to executive leadership and the Board, including financial risk quantification (e.g., FAIR) 

 

Governance Program Leadership 

  • Oversee the full lifecycle of InfoSec policies, standards, and guidelines, ensuring they are risk-based, actionable, and aligned with business needs 

  • Embed governance controls into the technology lifecycle (e.g., DevSecOps, cloud, infrastructure-as-code), reducing reliance on manual processes through automation 

  • Establish a policy effectiveness framework focused on behavioral change and measurable risk reduction 

  • Define and advance governance strategies for emerging technologies, including AI/ML, quantum security, and autonomous systems 

  • Lead enterprise maturity assessments (e.g., NIST CSF) to identify gaps and inform strategic investment decisions 

 

Compliance Program Leadership 

  • Provide oversight of global regulatory and contractual compliance programs (e.g., SOX, PCI, GDPR, ISO), ensuring consistency and scalability 

  • Build and operationalize a “compliance-as-a-service” model that enables self-service, automates evidence collection, and minimizes burden on engineering teams 

  • Monitor and anticipate changes in the regulatory landscape, proactively positioning Disney to meet evolving requirements 

 

Organizational Leadership 

  • Lead, develop, and scale a high-performing global GRC organization, fostering a culture of accountability, innovation, and continuous improvement 

  • Drive organizational excellence through strong leadership, talent development, and a focus on delivering scalable, forward-looking solutions 

What You’ll Bring 

Must-Have Qualifications 

  • You will have 12+ years of progressive experience in cybersecurity, technology risk, or compliance, including 3+ years leading enterprise-scale GRC functions  

  • You will bring structured problem-solving, audit rigor, and enterprise advisory experience  

  • You will have industry experience within large, complex organizations, with the ability to operate effectively in highly matrixed environments  

  • You will have a proven track record of transforming GRC programs into risk-driven operating models that influence enterprise decision-making  

  • You will have deep expertise across risk management, governance, and compliance, including frameworks, policy lifecycle, automation, audit, and controls assurance) 

  • You will have strong working knowledge of industry frameworks and regulations, including NIST CSF, NIST 800-53, ISO 27001, PCI DSS 4.0, SOX ITGC, and GDPR  

  • You will have demonstrated executive presence and exceptional influence skills, with the ability to operate as a trusted advisor to senior leadership and translate complex technical risk into clear business insights  

  • You will have experience applying financial risk quantification methodologies (e.g., FAIR) to support investment and prioritization decisions  

  • You will have a strong customer-focused mindset, ensuring GRC solutions enable the business and enhance—not hinder—user and product experiences  

  • You will have experience leading in highly matrixed, global environments, driving alignment across engineering, security, and business stakeholders  

 

Leadership & Transformation Profile (Critical for Success) 

  • You will have a mindset of a thought partner—not just an operator—bringing a strategic, forward-looking perspective to GRC  

  • You will have a track record of asking hard questions, challenging legacy ways of working, and driving meaningful change across organizations  

  • You will have the ability to connect cost, customer experience, and operational efficiency into a cohesive, risk-informed strategy  

  • You will have demonstrated success leading large-scale transformation initiatives, influencing without authority, and driving adoption across complex organizations  

 

Technical Expertise 

  • You will have advanced expertise in audit methodologies, controls testing, and assurance processes, including ITGCs and automated control environments (must have qualification) 

  • You will have hands-on experience with leading GRC platforms (e.g., Archer, ServiceNow GRC, SailPoint)  

  • You will have a strong understanding of cloud security and compliance across AWS, Azure, and GCP environments  

  • You will have familiarity with DevSecOps practices and integrating security and governance into software development and infrastructure pipelines  

 

Nice-to-Have Qualifications 

  • You may have experience within media, entertainment, or similarly complex, consumer-facing industries  

  • You may have experience from a Big 4 consulting firm. 

  • You may have experience advancing emerging risk domains such as AI/ML governance, third-party risk, or next-generation compliance capabilities  

 

Education 

  • You will have a bachelor’s degree in computer science, information security, or a related field—or equivalent practical experience (education) 

  • You may have advanced degrees or relevant certifications (e.g., CISSP, CISM, CRISC) (education) 

 


The hiring range for this position in Orlando, FL is $197,500 to $265,000 per year and in Glendale,CA is $207,400 to $278,200 per year. The hiring range for this position in Seattle, WA is $217,300 to $291,500 per year and in New York, NY is $217,300 to $291,500 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate’s geographic region, job-related knowledge, skills, and experience among other factors. A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.

今すぐ応募

The Walt Disney Company (Corporate)について:

The Walt Disney Companyでは強力なブランドが集結し、最も革新的で、広範囲にわたる影響力と尊敬される企業をグローバルで構築しています。記憶に残るエンターテインメントと体験の裏では、才能ある人材で構成された多種多様なビジネスサポートチームが、ディズニーの比類なきストーリーに生命を吹き込むために尽力しています。

The Walt Disney Company について:

The Walt Disney Companyは、その子会社・関連会社とともに、多様性あふれる国際企業として、Disney Entertainment、ESPN、Disney Experiencesの3事業を柱に、ファミリー向けエンターテインメントとメディアの世界をけん引しています。1920年代に小さなアニメ・スタジオとしてスタートしたDisneyは、今日のエンターテインメント業界において卓越した存在となりました。ディズニーは今後も、子供から大人まで、ご家族のだれもが楽しめる一流の物語や体験を生み出し続けます。Disneyのストーリーやキャラクター、体験は、世界中のあらゆる場所の消費者やお客様に届けられています。当社は40カ国以上で、従業員とキャストメンバーが一丸となり、世界的にも地域的にも歓迎されるエンターテインメント体験を創出しています。

このポジションはDisney Worldwide Services, Inc.という事業部門の一つであるThe Walt Disney Company (Corporate)でのお仕事です。

Disney Worldwide Services, Inc. は機会均等雇用主です。応募者は、人種、宗教、肌の色、性別、性的指向、ジェンダー、性自認、性表現、国籍、家柄、年齢、配偶者の有無、軍役経験の有無やその地位、健康状態、遺伝情報や障がい、または連邦法や州法、地方法で禁止されているその他の法的根拠に関係なく、雇用の検討対象となります。Disneyは、すべての人々のアイデアと決断が、成長、革新、最高のストーリーの創造に役立ち、絶えず進化する世界において、価値ある存在になれるよう支援するビジネス環境を支持します。

求人応募における障害者への配慮

The Walt Disney Company and its Affiliated Companies are Equal Employment Opportunity employers and welcome all job seekers including individuals with disabilities and veterans with disabilities. If you have a disability and believe you need a reasonable accommodation in order to search for a job opening or apply for a position, visit the Disney candidate disability accommodations FAQs. We will only respond to those requests that are related to the accessibility of the online application system due to a disability.

技術的な問題がある場合は、「よくあるご質問」をご覧ください。

採用プロセス

  • あなたのストーリーはどこから始まりますか?

    Disney CareersやLife at Disneyブログを探索し、ウォルト・ディズニー・カンパニーで待っている素晴らしい機会について学びましょう。

  • ストーリーに参加する

    探索できるさまざまなブランドやビジネスがあります。自分に合った機会を見つけたら、次のステップとして応募を完了させましょう。

  • 次の章

    応募が完了すると、候補者ダッシュボードへのアクセス方法が記載されたメールが届きます。ログインIDを作成し、ダッシュボードを頻繁にチェックして、応募の進捗状況を確認するようにしてください。

この場所を探索する カリフォルニア州グレンデール

ロサンゼルス郡にあるこの街には、本格的な中東料理、文化、そして有名な「ウォーク・オブ・フェイム」があります。

ウォルト・ディズニー・カンパニーの文化

campaign-__L10N__:English industry-The-Walt-Disney-Company-(Corporate) job_level-エグゼクティブ/上級管理職 job_status-Security-Engineering job_type-正社員 salary_relocation-IT-Info-Security-(Jason-Whitehurst)-(51067192) multivaluefield2-The-Walt-Disney-Company-(Corporate)-The-Walt-Disney-Company-(Corporate) custom_fields.test-valuetest custom_fields.WDJobs-Yes custom_fields.Country-Disney_WD_English_Test custom_fields.test123-test123 custom_fields.FlexType-いいえ custom_fields.TimeType-正社員 custom_fields.Campaign2-Technology custom_fields.FeedOrgID-WD-English custom_fields.ContactFax-Disney-Worldwide-Services,-Inc. custom_fields.FilterFlag-No custom_fields.Jobcountry-United-States-of-America custom_fields.RemoteType-Primarily-On-Site-/-Occasionally-from-Home custom_fields.FullAddress-1200-Grand-Central-Ave&#xa;Glendale,-CA-91201&#xa;United-States-of-America custom_fields.legalEntity--1008-Disney-Worldwide-Services,-Inc. custom_fields.CheckEquality-Yes custom_fields.ChinaBusiness-The-Walt-Disney-Company-China custom_fields.EmptyLocation-Yes custom_fields.SecondaryCity-,Seattle,Lake-Buena-Vista,New-York custom_fields.WorkerSubType-Regular custom_fields.ExportLocation-Glendale,California,United-States-of-America;Glendale,CA,USA;New-York,NY,USA;Seattle,WA,USA;Lake-Buena-Vista,FL,USA;Seattle,Washington,United-States-of-America;Lake-Buena-Vista,Florida,United-States-of-America;New-York,New-York,United-States-of-America custom_fields.JobLevelCustom-Executive custom_fields.SecondaryState-,Washington,Florida,New-York custom_fields.contactCompany-The-Walt-Disney-Company-(Corporate) custom_fields.jobPostingSite-External custom_fields.LIWorkplaceType-On-site custom_fields.PrimaryLocation-USA---CA---1200-Grand-Central-Ave custom_fields.PriorityIndustry-The-Walt-Disney-Company-(Corporate) custom_fields.SecondaryCountry-United-States-of-America,United-States-of-America,United-States-of-America custom_fields.AdditionalLocation-Lake-Buena-Vista,-FL,-USA;-Seattle,-WA,-USA;-New-York,-NY,-USA;-Glendale,-CA,-USA custom_fields.FullJobDescription-<div><div><p><span><span>At-Disney, </span><span>we’re</span><span> storytellers.-We-make-the </span><span>impossible,</span><span> possible.-The-Walt-Disney-Company-(TWDC)-is-a-world-class-entertainment-and-technological-leader.-Walt’s-passion-was-to-continuously-envision-new-ways-to-move-audiences-around-the-world—a-passion-that </span><span>remains</span><span> our-touchstone-in-an-enterprise-that-stretches-from-theme-parks,-resorts-and-a-cruise-line-to-sports,-news, </span><span>movies</span><span> and-a-variety-of-other-businesses.-Uniting-each-endeavor-is-a-commitment-to-creating-and-delivering-unforgettable-experiences-—-and </span><span>we’re</span><span> constantly-looking-for-new-ways-to-enhance-these-exciting-experiences. </span></span><span> </span></p><p></p></div><div><p><span><span>The-Enterprise-Technology-mission-is-to-deliver-technology-solutions-that-align-to-business-strategies-while-enabling-enterprise-efficiency-and-promoting-cross-company-collaborative-innovation.-Our-group-drives-competitive-advantage-by-enhancing-our-consumer-experiences,-enabling-business-growth,-and-advancing-operational-excellence. </span></span><span> </span></p><p></p></div><div><p><b><span>Team-Description:</span></b><span> </span></p></div><div><p><span><span>The-Global-Information-Security-(GIS)</span></span><i><span> </span></i><span><span>group-provides-services-to-protect-the-value-and-use-of-Disney’s-information-through-collaboration,-standardization,-enforcement,-and-education-across-The-Walt-Disney-Company.-The </span><span>main-focus</span><span> areas-of-this-group-are:-Reduce-the-risk-of-both-accidental-and-malicious-data-disclosure;-I</span><span>dentify</span><span>,-monitor,-engage-with-complete-inventory-of-information; </span><span>Establish-</span><span>appropriate-policies</span><span> and-procedures-to-be-followed;-Educate-user-community-to-minimize-risk.</span></span><span> </span></p><p></p></div><div><p><span><span>Disney’s-InfoSec-GRC-team-is-seeking-a-transformational-leader-to-drive-the-next-evolution-of-Governance,-Risk,-and-Compliance-across-the-enterprise.-Reporting-to-the-VP-of-Information-Security,-this-role-will-lead-the-shift-from-a-traditional-compliance-driven-approach-to-a-modern,-risk-intelligence-led-model-that-enables-better-business-decisions,-strengthens-security-posture,-and-scales-with-Disney’s-global-technology-and-content-ecosystem.-This-leader-will-partner-closely-with-GIS-and-business-leadership-to-embed-risk-awareness-into-daily-operations,-ensuring-GRC-is-a-strategic-enabler-of-innovation—not-a-barrier.</span></span><span> </span></p></div><div><p></p><p><u><b><span>What-You&#39;ll-Do</span></b><span> </span></u></p></div><div><p><b><span>Transform-GRC-at-Disney</span></b><span> </span></p></div><div><ul><li><p><span><span>Drive-the-evolution-of-Disney’s-InfoSec-GRC-program-from-a-compliance-centric-model-to-a-dynamic,-risk-intelligence-led-capability-that-informs-enterprise-investment-and-prioritization-decisions</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Define-and-elevate-GRC-standards-by-introducing-innovative-approaches-to-risk-quantification,-compliance-automation,-and-integrated-governance</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Partner-with-GIS-and-segment-technology-leadership-to-position-GRC-as-a-strategic-business-enabler,-translating-complex-risks-into-actionable,-executive-ready-insights</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Champion-a-culture-where-risk-awareness-is-embedded-into-daily-decision-making,-enabling-intuitive-and-scalable-risk-informed-behaviors-across-the-enterprise</span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><b><span>Risk-Management-Leadership</span></b><span> </span></p></div><div><ul><li><p><span><span>Lead-the-design,-implementation,-and-continuous-improvement-of-Disney’s-enterprise-InfoSec-Risk-Management-Framework</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Establish-and-operationalize-risk-tolerance-models,-translating-business </span><span>objectives</span><span> into-clear-prioritization,-investment,-and-remediation-decisions</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Build-and-mature-a-centralized-cybersecurity-risk-register-integrating-threat-intelligence,-vulnerabilities,-and-third-party-risk-data</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Drive-risk-based-prioritization-across-InfoSec-functions-to-ensure-measurable-risk-reduction-and-alignment-to-enterprise-objectives</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Deliver-clear,-credible,-and-decision-ready-risk-reporting-to-executive-leadership-and-the-Board,-including-financial-risk-quantification-(e.g.,-FAIR)</span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><b><span>Governance-Program-Leadership</span></b><span> </span></p></div><div><ul><li><p><span><span>Oversee-the-full-lifecycle-of-InfoSec-policies,-standards,-and-guidelines,-ensuring-they-are-risk-based,-actionable,-and-aligned-with-business-needs</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Embed-governance-controls-into-the-technology-lifecycle-(e.g., </span><span>DevSecOps</span><span>,-cloud,-infrastructure-as-code),-reducing-reliance-on-manual-processes-through-automation</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Establish-a-policy-effectiveness-framework-focused-on-behavioral-change-and-measurable-risk-reduction</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Define-and-advance-governance-strategies-for-emerging-technologies,-including-AI/ML,-quantum-security,-and-autonomous-systems</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Lead-enterprise-maturity-assessments-(e.g.,-NIST-CSF)-to </span><span>identify</span><span> gaps-and-inform-strategic-investment-decisions</span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><b><span>Compliance-Program-Leadership</span></b><span> </span></p></div><div><ul><li><p><span><span>Provide-oversight-of-global-regulatory-and-contractual-compliance-programs-(e.g.,-SOX,-PCI,-GDPR,-ISO),-ensuring-consistency-and-scalability</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Build-and-operationalize-a-“compliance-as-a-service”-model-that-enables-self-service,-automates-evidence-collection,-and-minimizes-burden-on-engineering-teams</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Monitor-and </span><span>anticipate</span><span> changes-in-the-regulatory-landscape,-proactively-positioning-Disney-to-meet-evolving-requirements</span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><b><span>Organizational-Leadership</span></b><span> </span></p></div><div><ul><li><p><span><span>Lead,-develop,-and-scale-a-high-performing-global-GRC-organization,-fostering-a-culture-of-accountability,-innovation,-and-continuous-improvement</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Drive-organizational-excellence-through-strong-leadership,-talent-development,-and-a-focus-on-delivering-scalable,-forward-looking-solutions</span></span><span> </span></p></li></ul></div><div><p></p><p><b><span>What </span><span>You’ll</span><span> Bring</span></b><span> </span></p></div><div><p><i><span>Must-Have-Qualifications</span></i><span> </span></p></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> 12&#43;-years-of-progressive-experience-in-cybersecurity,-technology-risk,-or-compliance,-including-3&#43;-years-leading-enterprise-scale-GRC-functions </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-bring</span></b><span><span> structured-problem-solving,-audit-rigor,-and-enterprise-advisory-experience </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> industry-experience-within-large,-complex-organizations,-with-the-ability-to </span><span>operate</span><span> effectively-in-highly-matrixed-environments </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> a-proven </span><span>track-record</span><span> of-transforming-GRC-programs-into-risk-driven-operating-models-that-influence-enterprise-decision-making </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> deep </span><span>expertise</span><span> across-risk-management,-governance,-and-compliance,-including-frameworks,-policy-lifecycle,-automation,-audit,-and-controls-assurance</span></span><i><span>)</span></i><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> strong-working-knowledge-of-industry-frameworks-and-regulations,-including-NIST-CSF,-NIST-800-53,-ISO-27001,-PCI-DSS-4.0,-SOX-ITGC,-and-GDPR </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> </span><span>demonstrated</span><span> executive-presence-and-exceptional-influence-skills,-with-the-ability-to </span><span>operate</span><span> as-a-trusted-advisor-to-senior-leadership-and-translate-complex-technical-risk-into-clear-business-insights </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> experience-applying-financial-risk-quantification-methodologies-(e.g.,-FAIR)-to-support-investment-and-prioritization-decisions </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> a-strong-customer-focused-mindset,-ensuring-GRC-solutions-enable-the-business-and-enhance—not-hinder—user-and-product-experiences </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> experience-leading-in-highly-matrixed,-global-environments,-driving-alignment-across-engineering,-security,-and-business-stakeholders </span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><i><span>Leadership-&amp;-Transformation-Profile-(Critical-for-Success)</span></i><span> </span></p></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> a-mindset-of-a-thought-partner—not-just-an-operator—bringing-a-strategic,-forward-looking-perspective-to-GRC </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> </span><span>a-track-record</span><span> of-asking </span><span>hard-questions</span><span>,-challenging-legacy-ways-of-working,-and-driving-meaningful-change-across-organizations </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> the-ability-to-connect-cost,-customer-experience,-and-operational-efficiency-into-a-cohesive,-risk-informed-strategy </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> </span><span>demonstrated</span><span> success-leading-large-scale-transformation-initiatives,-influencing-without-authority,-and-driving-adoption-across-complex-organizations </span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><i><span>Technical-Expertise</span></i><span> </span></p></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> advanced </span><span>expertise</span><span> in-audit-methodologies,-controls-testing,-and-assurance-processes,-including-ITGCs-and-automated-control-environments </span></span><i><span>(must-have-qualification)</span></i><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> hands-on-experience-with-leading-GRC-platforms-(e.g.,-Archer,-ServiceNow-GRC,-SailPoint) </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> a-strong-understanding-of-cloud-security-and-compliance-across-AWS,-Azure,-and-GCP-environments </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> familiarity-with </span><span>DevSecOps</span><span> practices-and-integrating-security-and-governance-into-software-development-and-infrastructure-pipelines </span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><i><span>Nice-to-Have-Qualifications</span></i><span> </span></p></div><div><ul><li><p><b><span>You-may-have</span></b><span><span> experience-within-media,-entertainment,-or-similarly-complex,-consumer-facing-industries </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-may-have</span></b><span><span> experience-from-a-Big-4-consulting-firm.</span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-may-have</span></b><span><span> experience-advancing-emerging-risk-domains-such-as-AI/ML-governance,-third-party-risk,-or-next-generation-compliance-capabilities </span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><i><span>Education</span></i><span> </span></p></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> a-bachelor’s-degree-in-computer-science,-information-security,-or-a-related-field—or-equivalent-practical-experience </span></span><i><span>(education)</span></i><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-may-have</span></b><span><span> advanced-degrees-or-relevant-certifications-(e.g.,-CISSP,-CISM,-CRISC) </span></span><i><span>(education)</span></i><span> </span></p></li></ul></div><div><p><span> </span></p></div></div><br>The-hiring-range-for-this-position-in-Orlando,-FL-is-$197,500-to-$265,000-per-year-and-in-Glendale,CA-is-$207,400-to-$278,200-per-year.-The-hiring-range-for-this-position-in-Seattle,-WA-is-$217,300-to-$291,500-per-year-and-in-New-York,-NY-is-$217,300-to-$291,500-per-year.-The-base-pay-actually-offered-will-take-into-account-internal-equity-and-also-may-vary-depending-on-the-candidate’s-geographic-region,-job-related-knowledge,-skills,-and-experience-among-other-factors.-A-bonus-and/or-long-term-incentive-units-may-be-provided-as-part-of-the-compensation-package,-in-addition-to-the-full-range-of-medical,-financial,-and/or-other-benefits,-dependent-on-the-level-and-position-offered. custom_fields.IndustryCustomField-The-Walt-Disney-Company-(Corporate) custom_fields.ExternalReferenceCode-10151183 custom_fields.PayTransparencyStatement-The-hiring-range-for-this-position-in-Orlando,-FL-is-$197,500-to-$265,000-per-year-and-in-Glendale,CA-is-$207,400-to-$278,200-per-year.-The-hiring-range-for-this-position-in-Seattle,-WA-is-$217,300-to-$291,500-per-year-and-in-New-York,-NY-is-$217,300-to-$291,500-per-year.-The-base-pay-actually-offered-will-take-into-account-internal-equity-and-also-may-vary-depending-on-the-candidate’s-geographic-region,-job-related-knowledge,-skills,-and-experience-among-other-factors.-A-bonus-and/or-long-term-incentive-units-may-be-provided-as-part-of-the-compensation-package,-in-addition-to-the-full-range-of-medical,-financial,-and/or-other-benefits,-dependent-on-the-level-and-position-offered.

campaign-__L10N__:English industry-The-Walt-Disney-Company-(Corporate) job_level-エグゼクティブ/上級管理職 job_status-Security-Engineering job_type-正社員 salary_relocation-IT-Info-Security-(Jason-Whitehurst)-(51067192) multivaluefield2-The-Walt-Disney-Company-(Corporate)-The-Walt-Disney-Company-(Corporate) custom_fields.test-valuetest custom_fields.WDJobs-Yes custom_fields.Country-Disney_WD_English_Test custom_fields.test123-test123 custom_fields.FlexType-いいえ custom_fields.TimeType-正社員 custom_fields.Campaign2-Technology custom_fields.FeedOrgID-WD-English custom_fields.ContactFax-Disney-Worldwide-Services,-Inc. custom_fields.FilterFlag-No custom_fields.Jobcountry-United-States-of-America custom_fields.RemoteType-Primarily-On-Site-/-Occasionally-from-Home custom_fields.FullAddress-1200-Grand-Central-Ave&#xa;Glendale,-CA-91201&#xa;United-States-of-America custom_fields.legalEntity--1008-Disney-Worldwide-Services,-Inc. custom_fields.CheckEquality-Yes custom_fields.ChinaBusiness-The-Walt-Disney-Company-China custom_fields.EmptyLocation-Yes custom_fields.SecondaryCity-,Seattle,Lake-Buena-Vista,New-York custom_fields.WorkerSubType-Regular custom_fields.ExportLocation-Glendale,California,United-States-of-America;Glendale,CA,USA;New-York,NY,USA;Seattle,WA,USA;Lake-Buena-Vista,FL,USA;Seattle,Washington,United-States-of-America;Lake-Buena-Vista,Florida,United-States-of-America;New-York,New-York,United-States-of-America custom_fields.JobLevelCustom-Executive custom_fields.SecondaryState-,Washington,Florida,New-York custom_fields.contactCompany-The-Walt-Disney-Company-(Corporate) custom_fields.jobPostingSite-External custom_fields.LIWorkplaceType-On-site custom_fields.PrimaryLocation-USA---CA---1200-Grand-Central-Ave custom_fields.PriorityIndustry-The-Walt-Disney-Company-(Corporate) custom_fields.SecondaryCountry-United-States-of-America,United-States-of-America,United-States-of-America custom_fields.AdditionalLocation-Lake-Buena-Vista,-FL,-USA;-Seattle,-WA,-USA;-New-York,-NY,-USA;-Glendale,-CA,-USA custom_fields.FullJobDescription-<div><div><p><span><span>At-Disney, </span><span>we’re</span><span> storytellers.-We-make-the </span><span>impossible,</span><span> possible.-The-Walt-Disney-Company-(TWDC)-is-a-world-class-entertainment-and-technological-leader.-Walt’s-passion-was-to-continuously-envision-new-ways-to-move-audiences-around-the-world—a-passion-that </span><span>remains</span><span> our-touchstone-in-an-enterprise-that-stretches-from-theme-parks,-resorts-and-a-cruise-line-to-sports,-news, </span><span>movies</span><span> and-a-variety-of-other-businesses.-Uniting-each-endeavor-is-a-commitment-to-creating-and-delivering-unforgettable-experiences-—-and </span><span>we’re</span><span> constantly-looking-for-new-ways-to-enhance-these-exciting-experiences. </span></span><span> </span></p><p></p></div><div><p><span><span>The-Enterprise-Technology-mission-is-to-deliver-technology-solutions-that-align-to-business-strategies-while-enabling-enterprise-efficiency-and-promoting-cross-company-collaborative-innovation.-Our-group-drives-competitive-advantage-by-enhancing-our-consumer-experiences,-enabling-business-growth,-and-advancing-operational-excellence. </span></span><span> </span></p><p></p></div><div><p><b><span>Team-Description:</span></b><span> </span></p></div><div><p><span><span>The-Global-Information-Security-(GIS)</span></span><i><span> </span></i><span><span>group-provides-services-to-protect-the-value-and-use-of-Disney’s-information-through-collaboration,-standardization,-enforcement,-and-education-across-The-Walt-Disney-Company.-The </span><span>main-focus</span><span> areas-of-this-group-are:-Reduce-the-risk-of-both-accidental-and-malicious-data-disclosure;-I</span><span>dentify</span><span>,-monitor,-engage-with-complete-inventory-of-information; </span><span>Establish-</span><span>appropriate-policies</span><span> and-procedures-to-be-followed;-Educate-user-community-to-minimize-risk.</span></span><span> </span></p><p></p></div><div><p><span><span>Disney’s-InfoSec-GRC-team-is-seeking-a-transformational-leader-to-drive-the-next-evolution-of-Governance,-Risk,-and-Compliance-across-the-enterprise.-Reporting-to-the-VP-of-Information-Security,-this-role-will-lead-the-shift-from-a-traditional-compliance-driven-approach-to-a-modern,-risk-intelligence-led-model-that-enables-better-business-decisions,-strengthens-security-posture,-and-scales-with-Disney’s-global-technology-and-content-ecosystem.-This-leader-will-partner-closely-with-GIS-and-business-leadership-to-embed-risk-awareness-into-daily-operations,-ensuring-GRC-is-a-strategic-enabler-of-innovation—not-a-barrier.</span></span><span> </span></p></div><div><p></p><p><u><b><span>What-You&#39;ll-Do</span></b><span> </span></u></p></div><div><p><b><span>Transform-GRC-at-Disney</span></b><span> </span></p></div><div><ul><li><p><span><span>Drive-the-evolution-of-Disney’s-InfoSec-GRC-program-from-a-compliance-centric-model-to-a-dynamic,-risk-intelligence-led-capability-that-informs-enterprise-investment-and-prioritization-decisions</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Define-and-elevate-GRC-standards-by-introducing-innovative-approaches-to-risk-quantification,-compliance-automation,-and-integrated-governance</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Partner-with-GIS-and-segment-technology-leadership-to-position-GRC-as-a-strategic-business-enabler,-translating-complex-risks-into-actionable,-executive-ready-insights</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Champion-a-culture-where-risk-awareness-is-embedded-into-daily-decision-making,-enabling-intuitive-and-scalable-risk-informed-behaviors-across-the-enterprise</span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><b><span>Risk-Management-Leadership</span></b><span> </span></p></div><div><ul><li><p><span><span>Lead-the-design,-implementation,-and-continuous-improvement-of-Disney’s-enterprise-InfoSec-Risk-Management-Framework</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Establish-and-operationalize-risk-tolerance-models,-translating-business </span><span>objectives</span><span> into-clear-prioritization,-investment,-and-remediation-decisions</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Build-and-mature-a-centralized-cybersecurity-risk-register-integrating-threat-intelligence,-vulnerabilities,-and-third-party-risk-data</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Drive-risk-based-prioritization-across-InfoSec-functions-to-ensure-measurable-risk-reduction-and-alignment-to-enterprise-objectives</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Deliver-clear,-credible,-and-decision-ready-risk-reporting-to-executive-leadership-and-the-Board,-including-financial-risk-quantification-(e.g.,-FAIR)</span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><b><span>Governance-Program-Leadership</span></b><span> </span></p></div><div><ul><li><p><span><span>Oversee-the-full-lifecycle-of-InfoSec-policies,-standards,-and-guidelines,-ensuring-they-are-risk-based,-actionable,-and-aligned-with-business-needs</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Embed-governance-controls-into-the-technology-lifecycle-(e.g., </span><span>DevSecOps</span><span>,-cloud,-infrastructure-as-code),-reducing-reliance-on-manual-processes-through-automation</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Establish-a-policy-effectiveness-framework-focused-on-behavioral-change-and-measurable-risk-reduction</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Define-and-advance-governance-strategies-for-emerging-technologies,-including-AI/ML,-quantum-security,-and-autonomous-systems</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Lead-enterprise-maturity-assessments-(e.g.,-NIST-CSF)-to </span><span>identify</span><span> gaps-and-inform-strategic-investment-decisions</span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><b><span>Compliance-Program-Leadership</span></b><span> </span></p></div><div><ul><li><p><span><span>Provide-oversight-of-global-regulatory-and-contractual-compliance-programs-(e.g.,-SOX,-PCI,-GDPR,-ISO),-ensuring-consistency-and-scalability</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Build-and-operationalize-a-“compliance-as-a-service”-model-that-enables-self-service,-automates-evidence-collection,-and-minimizes-burden-on-engineering-teams</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Monitor-and </span><span>anticipate</span><span> changes-in-the-regulatory-landscape,-proactively-positioning-Disney-to-meet-evolving-requirements</span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><b><span>Organizational-Leadership</span></b><span> </span></p></div><div><ul><li><p><span><span>Lead,-develop,-and-scale-a-high-performing-global-GRC-organization,-fostering-a-culture-of-accountability,-innovation,-and-continuous-improvement</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Drive-organizational-excellence-through-strong-leadership,-talent-development,-and-a-focus-on-delivering-scalable,-forward-looking-solutions</span></span><span> </span></p></li></ul></div><div><p></p><p><b><span>What </span><span>You’ll</span><span> Bring</span></b><span> </span></p></div><div><p><i><span>Must-Have-Qualifications</span></i><span> </span></p></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> 12&#43;-years-of-progressive-experience-in-cybersecurity,-technology-risk,-or-compliance,-including-3&#43;-years-leading-enterprise-scale-GRC-functions </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-bring</span></b><span><span> structured-problem-solving,-audit-rigor,-and-enterprise-advisory-experience </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> industry-experience-within-large,-complex-organizations,-with-the-ability-to </span><span>operate</span><span> effectively-in-highly-matrixed-environments </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> a-proven </span><span>track-record</span><span> of-transforming-GRC-programs-into-risk-driven-operating-models-that-influence-enterprise-decision-making </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> deep </span><span>expertise</span><span> across-risk-management,-governance,-and-compliance,-including-frameworks,-policy-lifecycle,-automation,-audit,-and-controls-assurance</span></span><i><span>)</span></i><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> strong-working-knowledge-of-industry-frameworks-and-regulations,-including-NIST-CSF,-NIST-800-53,-ISO-27001,-PCI-DSS-4.0,-SOX-ITGC,-and-GDPR </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> </span><span>demonstrated</span><span> executive-presence-and-exceptional-influence-skills,-with-the-ability-to </span><span>operate</span><span> as-a-trusted-advisor-to-senior-leadership-and-translate-complex-technical-risk-into-clear-business-insights </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> experience-applying-financial-risk-quantification-methodologies-(e.g.,-FAIR)-to-support-investment-and-prioritization-decisions </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> a-strong-customer-focused-mindset,-ensuring-GRC-solutions-enable-the-business-and-enhance—not-hinder—user-and-product-experiences </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> experience-leading-in-highly-matrixed,-global-environments,-driving-alignment-across-engineering,-security,-and-business-stakeholders </span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><i><span>Leadership-&amp;-Transformation-Profile-(Critical-for-Success)</span></i><span> </span></p></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> a-mindset-of-a-thought-partner—not-just-an-operator—bringing-a-strategic,-forward-looking-perspective-to-GRC </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> </span><span>a-track-record</span><span> of-asking </span><span>hard-questions</span><span>,-challenging-legacy-ways-of-working,-and-driving-meaningful-change-across-organizations </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> the-ability-to-connect-cost,-customer-experience,-and-operational-efficiency-into-a-cohesive,-risk-informed-strategy </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> </span><span>demonstrated</span><span> success-leading-large-scale-transformation-initiatives,-influencing-without-authority,-and-driving-adoption-across-complex-organizations </span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><i><span>Technical-Expertise</span></i><span> </span></p></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> advanced </span><span>expertise</span><span> in-audit-methodologies,-controls-testing,-and-assurance-processes,-including-ITGCs-and-automated-control-environments </span></span><i><span>(must-have-qualification)</span></i><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> hands-on-experience-with-leading-GRC-platforms-(e.g.,-Archer,-ServiceNow-GRC,-SailPoint) </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> a-strong-understanding-of-cloud-security-and-compliance-across-AWS,-Azure,-and-GCP-environments </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> familiarity-with </span><span>DevSecOps</span><span> practices-and-integrating-security-and-governance-into-software-development-and-infrastructure-pipelines </span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><i><span>Nice-to-Have-Qualifications</span></i><span> </span></p></div><div><ul><li><p><b><span>You-may-have</span></b><span><span> experience-within-media,-entertainment,-or-similarly-complex,-consumer-facing-industries </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-may-have</span></b><span><span> experience-from-a-Big-4-consulting-firm.</span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-may-have</span></b><span><span> experience-advancing-emerging-risk-domains-such-as-AI/ML-governance,-third-party-risk,-or-next-generation-compliance-capabilities </span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><i><span>Education</span></i><span> </span></p></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> a-bachelor’s-degree-in-computer-science,-information-security,-or-a-related-field—or-equivalent-practical-experience </span></span><i><span>(education)</span></i><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-may-have</span></b><span><span> advanced-degrees-or-relevant-certifications-(e.g.,-CISSP,-CISM,-CRISC) </span></span><i><span>(education)</span></i><span> </span></p></li></ul></div><div><p><span> </span></p></div></div><br>The-hiring-range-for-this-position-in-Orlando,-FL-is-$197,500-to-$265,000-per-year-and-in-Glendale,CA-is-$207,400-to-$278,200-per-year.-The-hiring-range-for-this-position-in-Seattle,-WA-is-$217,300-to-$291,500-per-year-and-in-New-York,-NY-is-$217,300-to-$291,500-per-year.-The-base-pay-actually-offered-will-take-into-account-internal-equity-and-also-may-vary-depending-on-the-candidate’s-geographic-region,-job-related-knowledge,-skills,-and-experience-among-other-factors.-A-bonus-and/or-long-term-incentive-units-may-be-provided-as-part-of-the-compensation-package,-in-addition-to-the-full-range-of-medical,-financial,-and/or-other-benefits,-dependent-on-the-level-and-position-offered. custom_fields.IndustryCustomField-The-Walt-Disney-Company-(Corporate) custom_fields.ExternalReferenceCode-10151183 custom_fields.PayTransparencyStatement-The-hiring-range-for-this-position-in-Orlando,-FL-is-$197,500-to-$265,000-per-year-and-in-Glendale,CA-is-$207,400-to-$278,200-per-year.-The-hiring-range-for-this-position-in-Seattle,-WA-is-$217,300-to-$291,500-per-year-and-in-New-York,-NY-is-$217,300-to-$291,500-per-year.-The-base-pay-actually-offered-will-take-into-account-internal-equity-and-also-may-vary-depending-on-the-candidate’s-geographic-region,-job-related-knowledge,-skills,-and-experience-among-other-factors.-A-bonus-and/or-long-term-incentive-units-may-be-provided-as-part-of-the-compensation-package,-in-addition-to-the-full-range-of-medical,-financial,-and/or-other-benefits,-dependent-on-the-level-and-position-offered.

campaign-__L10N__:English industry-The-Walt-Disney-Company-(Corporate) job_level-エグゼクティブ/上級管理職 job_status-Security-Engineering job_type-正社員 salary_relocation-IT-Info-Security-(Jason-Whitehurst)-(51067192) multivaluefield2-The-Walt-Disney-Company-(Corporate)-The-Walt-Disney-Company-(Corporate) custom_fields.test-valuetest custom_fields.WDJobs-Yes custom_fields.Country-Disney_WD_English_Test custom_fields.test123-test123 custom_fields.FlexType-いいえ custom_fields.TimeType-正社員 custom_fields.Campaign2-Technology custom_fields.FeedOrgID-WD-English custom_fields.ContactFax-Disney-Worldwide-Services,-Inc. custom_fields.FilterFlag-No custom_fields.Jobcountry-United-States-of-America custom_fields.RemoteType-Primarily-On-Site-/-Occasionally-from-Home custom_fields.FullAddress-1200-Grand-Central-Ave&#xa;Glendale,-CA-91201&#xa;United-States-of-America custom_fields.legalEntity--1008-Disney-Worldwide-Services,-Inc. custom_fields.CheckEquality-Yes custom_fields.ChinaBusiness-The-Walt-Disney-Company-China custom_fields.EmptyLocation-Yes custom_fields.SecondaryCity-,Seattle,Lake-Buena-Vista,New-York custom_fields.WorkerSubType-Regular custom_fields.ExportLocation-Glendale,California,United-States-of-America;Glendale,CA,USA;New-York,NY,USA;Seattle,WA,USA;Lake-Buena-Vista,FL,USA;Seattle,Washington,United-States-of-America;Lake-Buena-Vista,Florida,United-States-of-America;New-York,New-York,United-States-of-America custom_fields.JobLevelCustom-Executive custom_fields.SecondaryState-,Washington,Florida,New-York custom_fields.contactCompany-The-Walt-Disney-Company-(Corporate) custom_fields.jobPostingSite-External custom_fields.LIWorkplaceType-On-site custom_fields.PrimaryLocation-USA---CA---1200-Grand-Central-Ave custom_fields.PriorityIndustry-The-Walt-Disney-Company-(Corporate) custom_fields.SecondaryCountry-United-States-of-America,United-States-of-America,United-States-of-America custom_fields.AdditionalLocation-Lake-Buena-Vista,-FL,-USA;-Seattle,-WA,-USA;-New-York,-NY,-USA;-Glendale,-CA,-USA custom_fields.FullJobDescription-<div><div><p><span><span>At-Disney, </span><span>we’re</span><span> storytellers.-We-make-the </span><span>impossible,</span><span> possible.-The-Walt-Disney-Company-(TWDC)-is-a-world-class-entertainment-and-technological-leader.-Walt’s-passion-was-to-continuously-envision-new-ways-to-move-audiences-around-the-world—a-passion-that </span><span>remains</span><span> our-touchstone-in-an-enterprise-that-stretches-from-theme-parks,-resorts-and-a-cruise-line-to-sports,-news, </span><span>movies</span><span> and-a-variety-of-other-businesses.-Uniting-each-endeavor-is-a-commitment-to-creating-and-delivering-unforgettable-experiences-—-and </span><span>we’re</span><span> constantly-looking-for-new-ways-to-enhance-these-exciting-experiences. </span></span><span> </span></p><p></p></div><div><p><span><span>The-Enterprise-Technology-mission-is-to-deliver-technology-solutions-that-align-to-business-strategies-while-enabling-enterprise-efficiency-and-promoting-cross-company-collaborative-innovation.-Our-group-drives-competitive-advantage-by-enhancing-our-consumer-experiences,-enabling-business-growth,-and-advancing-operational-excellence. </span></span><span> </span></p><p></p></div><div><p><b><span>Team-Description:</span></b><span> </span></p></div><div><p><span><span>The-Global-Information-Security-(GIS)</span></span><i><span> </span></i><span><span>group-provides-services-to-protect-the-value-and-use-of-Disney’s-information-through-collaboration,-standardization,-enforcement,-and-education-across-The-Walt-Disney-Company.-The </span><span>main-focus</span><span> areas-of-this-group-are:-Reduce-the-risk-of-both-accidental-and-malicious-data-disclosure;-I</span><span>dentify</span><span>,-monitor,-engage-with-complete-inventory-of-information; </span><span>Establish-</span><span>appropriate-policies</span><span> and-procedures-to-be-followed;-Educate-user-community-to-minimize-risk.</span></span><span> </span></p><p></p></div><div><p><span><span>Disney’s-InfoSec-GRC-team-is-seeking-a-transformational-leader-to-drive-the-next-evolution-of-Governance,-Risk,-and-Compliance-across-the-enterprise.-Reporting-to-the-VP-of-Information-Security,-this-role-will-lead-the-shift-from-a-traditional-compliance-driven-approach-to-a-modern,-risk-intelligence-led-model-that-enables-better-business-decisions,-strengthens-security-posture,-and-scales-with-Disney’s-global-technology-and-content-ecosystem.-This-leader-will-partner-closely-with-GIS-and-business-leadership-to-embed-risk-awareness-into-daily-operations,-ensuring-GRC-is-a-strategic-enabler-of-innovation—not-a-barrier.</span></span><span> </span></p></div><div><p></p><p><u><b><span>What-You&#39;ll-Do</span></b><span> </span></u></p></div><div><p><b><span>Transform-GRC-at-Disney</span></b><span> </span></p></div><div><ul><li><p><span><span>Drive-the-evolution-of-Disney’s-InfoSec-GRC-program-from-a-compliance-centric-model-to-a-dynamic,-risk-intelligence-led-capability-that-informs-enterprise-investment-and-prioritization-decisions</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Define-and-elevate-GRC-standards-by-introducing-innovative-approaches-to-risk-quantification,-compliance-automation,-and-integrated-governance</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Partner-with-GIS-and-segment-technology-leadership-to-position-GRC-as-a-strategic-business-enabler,-translating-complex-risks-into-actionable,-executive-ready-insights</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Champion-a-culture-where-risk-awareness-is-embedded-into-daily-decision-making,-enabling-intuitive-and-scalable-risk-informed-behaviors-across-the-enterprise</span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><b><span>Risk-Management-Leadership</span></b><span> </span></p></div><div><ul><li><p><span><span>Lead-the-design,-implementation,-and-continuous-improvement-of-Disney’s-enterprise-InfoSec-Risk-Management-Framework</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Establish-and-operationalize-risk-tolerance-models,-translating-business </span><span>objectives</span><span> into-clear-prioritization,-investment,-and-remediation-decisions</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Build-and-mature-a-centralized-cybersecurity-risk-register-integrating-threat-intelligence,-vulnerabilities,-and-third-party-risk-data</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Drive-risk-based-prioritization-across-InfoSec-functions-to-ensure-measurable-risk-reduction-and-alignment-to-enterprise-objectives</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Deliver-clear,-credible,-and-decision-ready-risk-reporting-to-executive-leadership-and-the-Board,-including-financial-risk-quantification-(e.g.,-FAIR)</span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><b><span>Governance-Program-Leadership</span></b><span> </span></p></div><div><ul><li><p><span><span>Oversee-the-full-lifecycle-of-InfoSec-policies,-standards,-and-guidelines,-ensuring-they-are-risk-based,-actionable,-and-aligned-with-business-needs</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Embed-governance-controls-into-the-technology-lifecycle-(e.g., </span><span>DevSecOps</span><span>,-cloud,-infrastructure-as-code),-reducing-reliance-on-manual-processes-through-automation</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Establish-a-policy-effectiveness-framework-focused-on-behavioral-change-and-measurable-risk-reduction</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Define-and-advance-governance-strategies-for-emerging-technologies,-including-AI/ML,-quantum-security,-and-autonomous-systems</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Lead-enterprise-maturity-assessments-(e.g.,-NIST-CSF)-to </span><span>identify</span><span> gaps-and-inform-strategic-investment-decisions</span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><b><span>Compliance-Program-Leadership</span></b><span> </span></p></div><div><ul><li><p><span><span>Provide-oversight-of-global-regulatory-and-contractual-compliance-programs-(e.g.,-SOX,-PCI,-GDPR,-ISO),-ensuring-consistency-and-scalability</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Build-and-operationalize-a-“compliance-as-a-service”-model-that-enables-self-service,-automates-evidence-collection,-and-minimizes-burden-on-engineering-teams</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Monitor-and </span><span>anticipate</span><span> changes-in-the-regulatory-landscape,-proactively-positioning-Disney-to-meet-evolving-requirements</span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><b><span>Organizational-Leadership</span></b><span> </span></p></div><div><ul><li><p><span><span>Lead,-develop,-and-scale-a-high-performing-global-GRC-organization,-fostering-a-culture-of-accountability,-innovation,-and-continuous-improvement</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Drive-organizational-excellence-through-strong-leadership,-talent-development,-and-a-focus-on-delivering-scalable,-forward-looking-solutions</span></span><span> </span></p></li></ul></div><div><p></p><p><b><span>What </span><span>You’ll</span><span> Bring</span></b><span> </span></p></div><div><p><i><span>Must-Have-Qualifications</span></i><span> </span></p></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> 12&#43;-years-of-progressive-experience-in-cybersecurity,-technology-risk,-or-compliance,-including-3&#43;-years-leading-enterprise-scale-GRC-functions </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-bring</span></b><span><span> structured-problem-solving,-audit-rigor,-and-enterprise-advisory-experience </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> industry-experience-within-large,-complex-organizations,-with-the-ability-to </span><span>operate</span><span> effectively-in-highly-matrixed-environments </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> a-proven </span><span>track-record</span><span> of-transforming-GRC-programs-into-risk-driven-operating-models-that-influence-enterprise-decision-making </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> deep </span><span>expertise</span><span> across-risk-management,-governance,-and-compliance,-including-frameworks,-policy-lifecycle,-automation,-audit,-and-controls-assurance</span></span><i><span>)</span></i><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> strong-working-knowledge-of-industry-frameworks-and-regulations,-including-NIST-CSF,-NIST-800-53,-ISO-27001,-PCI-DSS-4.0,-SOX-ITGC,-and-GDPR </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> </span><span>demonstrated</span><span> executive-presence-and-exceptional-influence-skills,-with-the-ability-to </span><span>operate</span><span> as-a-trusted-advisor-to-senior-leadership-and-translate-complex-technical-risk-into-clear-business-insights </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> experience-applying-financial-risk-quantification-methodologies-(e.g.,-FAIR)-to-support-investment-and-prioritization-decisions </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> a-strong-customer-focused-mindset,-ensuring-GRC-solutions-enable-the-business-and-enhance—not-hinder—user-and-product-experiences </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> experience-leading-in-highly-matrixed,-global-environments,-driving-alignment-across-engineering,-security,-and-business-stakeholders </span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><i><span>Leadership-&amp;-Transformation-Profile-(Critical-for-Success)</span></i><span> </span></p></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> a-mindset-of-a-thought-partner—not-just-an-operator—bringing-a-strategic,-forward-looking-perspective-to-GRC </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> </span><span>a-track-record</span><span> of-asking </span><span>hard-questions</span><span>,-challenging-legacy-ways-of-working,-and-driving-meaningful-change-across-organizations </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> the-ability-to-connect-cost,-customer-experience,-and-operational-efficiency-into-a-cohesive,-risk-informed-strategy </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> </span><span>demonstrated</span><span> success-leading-large-scale-transformation-initiatives,-influencing-without-authority,-and-driving-adoption-across-complex-organizations </span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><i><span>Technical-Expertise</span></i><span> </span></p></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> advanced </span><span>expertise</span><span> in-audit-methodologies,-controls-testing,-and-assurance-processes,-including-ITGCs-and-automated-control-environments </span></span><i><span>(must-have-qualification)</span></i><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> hands-on-experience-with-leading-GRC-platforms-(e.g.,-Archer,-ServiceNow-GRC,-SailPoint) </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> a-strong-understanding-of-cloud-security-and-compliance-across-AWS,-Azure,-and-GCP-environments </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> familiarity-with </span><span>DevSecOps</span><span> practices-and-integrating-security-and-governance-into-software-development-and-infrastructure-pipelines </span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><i><span>Nice-to-Have-Qualifications</span></i><span> </span></p></div><div><ul><li><p><b><span>You-may-have</span></b><span><span> experience-within-media,-entertainment,-or-similarly-complex,-consumer-facing-industries </span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-may-have</span></b><span><span> experience-from-a-Big-4-consulting-firm.</span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-may-have</span></b><span><span> experience-advancing-emerging-risk-domains-such-as-AI/ML-governance,-third-party-risk,-or-next-generation-compliance-capabilities </span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><i><span>Education</span></i><span> </span></p></div><div><ul><li><p><b><span>You-will-have</span></b><span><span> a-bachelor’s-degree-in-computer-science,-information-security,-or-a-related-field—or-equivalent-practical-experience </span></span><i><span>(education)</span></i><span> </span></p></li></ul></div><div><ul><li><p><b><span>You-may-have</span></b><span><span> advanced-degrees-or-relevant-certifications-(e.g.,-CISSP,-CISM,-CRISC) </span></span><i><span>(education)</span></i><span> </span></p></li></ul></div><div><p><span> </span></p></div></div><br>The-hiring-range-for-this-position-in-Orlando,-FL-is-$197,500-to-$265,000-per-year-and-in-Glendale,CA-is-$207,400-to-$278,200-per-year.-The-hiring-range-for-this-position-in-Seattle,-WA-is-$217,300-to-$291,500-per-year-and-in-New-York,-NY-is-$217,300-to-$291,500-per-year.-The-base-pay-actually-offered-will-take-into-account-internal-equity-and-also-may-vary-depending-on-the-candidate’s-geographic-region,-job-related-knowledge,-skills,-and-experience-among-other-factors.-A-bonus-and/or-long-term-incentive-units-may-be-provided-as-part-of-the-compensation-package,-in-addition-to-the-full-range-of-medical,-financial,-and/or-other-benefits,-dependent-on-the-level-and-position-offered. custom_fields.IndustryCustomField-The-Walt-Disney-Company-(Corporate) custom_fields.ExternalReferenceCode-10151183 custom_fields.PayTransparencyStatement-The-hiring-range-for-this-position-in-Orlando,-FL-is-$197,500-to-$265,000-per-year-and-in-Glendale,CA-is-$207,400-to-$278,200-per-year.-The-hiring-range-for-this-position-in-Seattle,-WA-is-$217,300-to-$291,500-per-year-and-in-New-York,-NY-is-$217,300-to-$291,500-per-year.-The-base-pay-actually-offered-will-take-into-account-internal-equity-and-also-may-vary-depending-on-the-candidate’s-geographic-region,-job-related-knowledge,-skills,-and-experience-among-other-factors.-A-bonus-and/or-long-term-incentive-units-may-be-provided-as-part-of-the-compensation-package,-in-addition-to-the-full-range-of-medical,-financial,-and/or-other-benefits,-dependent-on-the-level-and-position-offered.

  • エグゼクティブ/上級管理職

    ディズニーの上級管理職は、素晴らしい経験、先見的思考、そして卓越性、創造性、革新性に対する共通のコミットメントを日々の業務に生かしています。

    詳細はこちら 
  • インクルージョン

    Disneyは、すべての人々が受け入れられ、目標に向かって活躍してほしいと考えています。従業員とゲストの方々を温かく迎え入れ、尊重する環境を築き上げることは、私たちの企業文化とビジネスの中核をなしています。私たちは、支えとなる職場環境を構築することで、イノベーションを推進し、全従業員が歓迎され、尊重され、価値が認められていると感じられる文化の醸成に努めています。

    詳細はこちら 

ジョブアラートに登録

新しい採用情報を随時掲載しています。

ジョブアラートに登録する

*は必須項目です。

興味のある内容選択リストから業種/カテゴリーを選択してください。選択リストから勤務地を選択してください。最後に「追加」をクリックして、ジョブアラートを作成します。

「送信」をクリックすると、当社の利用規約(新しいウィンドウで開きます)に同意し、当社のプライバシーポリシー(新しいウィンドウで開きます)を承諾したことになります。

「送信」をクリックすると、当社の利用規約(新しいウィンドウで開きます)に同意し、当社のプライバシーポリシー(新しいウィンドウで開きます)を承諾したことになります。マーケティングメッセージやニュースレターの受信を選択した場合、私は、いつでもこれらのマーケティングメッセージに対する同意を撤回することができます。

「送信」をクリックすると、当社の利用規約(新しいウィンドウで開きます)に同意し、当社のプライバシーポリシー(新しいウィンドウで開きます)クッキーポリシー(新しいウィンドウで開きます)EUのプライバシー権(新しいウィンドウで開きます)を承諾したことになります。

個人情報及び個人の権利の取り扱いについて:

  1. お客様の個人情報は、3 Queen Caroline Street, London, W6 9PE, United Kingdomにあるウォルト・ディズニー・カンパニー株式会社によって管理されます。
  2. ディズニーへの訪問やそこでの買い物、ディズニーの商品、サービス、モバイルアプリをご利用いただくと、ウォルト・ディズニー・カンパニーファミリー企業がお客様の個人情報を用いてこれらのサービスを提供したり、お客様の体験をパーソナライズしたり、サービスに関わる更新情報や連絡をお送りしたりする場合があります。
  3. お客様には、ご自身の個人情報に対して、アクセスや、変更・削除の要請をする権利、マーケティングに関する設定を変更(常時の同意撤回も含む)する権利があります。マーケティングに関する設定の管理やアカウントの削除に関する詳細は、弊社のプライバシーポリシー(新しいウィンドウで開きます)をご覧ください。
  4. 当社のデータ保護責任者にEメールにてご連絡いただくことも可能です(dataprotection@disney.co.uk宛)。
  5. お客様は、英国個人情報保護監督機関(https://ico.org.uk/(新しいウィンドウで開きます))に苦情を申し立てる権利を有しています。
  6. ディズニーのデータ収集とその利用方法についての詳細は、ディズニーのプライバシーポリシー(新しいウィンドウで開きます)をお読みください。

当社の一般的なデータ収集、使用、および慣行に関する詳細情報(お客様の設定の管理方法を含む)については、当社のプライバシーポリシー(新しいウィンドウで開きます)をお読みください。私は利用規約(新しいウィンドウで開きます)を読み、これに同意します。

Privacy Policy Agreement

Privacy Policy Agreement

Privacy Policy Agreement

Privacy Policy Agreement

Privacy Policy Agreement