跳至主要內容

Executive Director, Info Security

工作 ID 10152675 地點 西雅圖, 华盛顿州, 美國 / 格倫代爾, 加利福尼亚州, 美國 / 纽约, 纽约州, 美國 / 奧蘭多, 佛罗里达州, 美國 有意工作的公司 The Walt Disney Company (Corporate) 日期已公佈 May 29, 2026
申請

工作概要:

Department Description

At Disney, we’re storytellers. We make the impossible, possible. The Walt Disney Company is a world-class entertainment and technological leader. Walt’s passion was to continuously envision new ways to move audiences around the world - a passion that remains our touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, TV, movies and a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences - and we’re constantly looking for new ways to enhance these exciting experiences.

The Enterprise Technology & Data mission is to deliver technology solutions that align to business strategies while enabling enterprise efficiency and promoting cross-company collaborative innovation. Our group drives competitive advantage by enhancing our consumer experiences, enabling business growth, and advancing operational excellence. Global Information Security (GIS) provides services to protect the value and use of Disney’s information through collaboration, empowerment, and education across The Walt Disney Company.

Team Description:

At Disney, innovation and imagination fuel everything we do. The InfoSec Governance, Risk & Compliance (GRC) team is not just a guardian of standards - we are leaders who drive the evolution of information security. As a strategic powerhouse in the GIS organization, our mission transcends compliance, setting new benchmarks for risk intelligence, automation, and integrated governance. We aim to redefine what “great” looks like, pioneering visionary approaches that shape how Disney (and the industry) understands and manages security risk.

The GRC team is the pulse of Disney’s enterprise technology ecosystem. We don’t just follow regulatory mandates; we leap ahead, leveraging data-driven insights, advanced risk quantification, and automated control frameworks to empower business leaders and technologists. Our collaborative culture ensures that every corner of GIS speaks a unified risk language, propelling risk-aware thinking to the forefront of daily business decisions and fueling cross-company innovation.

By joining this team, you become a change agent, transforming GRC from a “checkbox” function to a dynamic, strategic enabler. You will lead and inspire a diverse, high-performing group that anticipates emerging risk domains, shapes industry-leading policy design, and drives measurable, business-aligned security outcomes. If your passion is to advance, not just meet, industry standards, and to make a lasting impact on a legendary brand’s global footprint, the InfoSec GRC team at Disney is your stage.

Responsibilities of Role (List in order of priority, first few bullets should be the most important):

  • Transform GRC at Disney
    • Drive continous evolution of Disney’s InfoSec GRC program, replacing compliance-centric, checkbox-driven operations with a dynamic, risk-intelligence-led model that directly informs how Disney prioritizes investment, staffing, and remediation.
    • Define what “great” looks like, not by referencing existing standards but by advancing them. Develop novel approaches to risk quantification, compliance automation, and governance integration.
    • Partner with GIS Leadership and Segment CTO teams to ensure the GRC program functions as a strategic business enabler, translating complex risk landscapes into executive- and board-ready insights that drive confident decision-making.
    • Champion a culture shift across all of GIS and the broader enterprise: risk awareness is everyone’s job, and GRC’s role is to make risk-informed thinking intuitive, not burdensome.

  • Risk Management Leadership
    • Oversee the development and ongoing operations of Disney’s comprehensive InfoSec Risk Management program, including the establishment, implementation, and continuous improvement of the enterprise Risk Management Framework.
    • Establish and operationalize risk tolerance frameworks in partnership with executive leadership, defining clear thresholds that translate business appetite into actionable security investment and prioritization decisions.
    • Build and mature a cybersecurity risk register that serves as the authoritative source of truth for Disney’s threat and control posture, dynamically integrated with threat intelligence, vulnerability management, and third-party risk inputs.
    • Drive risk-based prioritization across all InfoSec operational functions (engineering, red team, SOC, cloud security, etc.) - ensuring that every team’s roadmap is anchored in defensible risk reduction rationale, not reactive urgency.
    • Develop executive and board-level risk reporting that is clear, credible, and decision-ready; ensure Disney’s risk narrative is consistent from the CISO to the Audit Committee.
    • Lead efforts to quantify InfoSec risk in financial terms (FAIR or equivalent), enabling direct comparison of security investment across Disney’s ubiquitous businesses and against measurable risk reduction outcomes.
    • Lead a third-party and supply chain risk intelligence capability that goes beyond questionnaire-based assessments by integrating continuous external attack surface monitoring, threat intelligence on vendor compromise activity, and contractual control requirements into a unified third-party risk posture.

  • Governance Program Leadership
    • Oversee the development, maintenance, and lifecycle management of enterprise-wide Information Security policies, standards, and guidelines, ensuring they are risk-based, clear, and aligned to business realities (not just regulatory checklists).
    • Drive automated policy enforcement and integration of governance requirements into the technology design lifecycle (DevSecOps, cloud provisioning, infrastructure-as-code, etc.), reducing reliance on manual control operations and attestation.
    • Lead the development of a policy effectiveness measurement framework that moves beyond “is the policy published and attested to?” toward “is the policy actually changing behavior and reducing risk?” (tracked via control telemetry, exception rates, and risk outcome data).
    • Pioneer a forward-looking policy architecture that anticipates emerging technology risk domains (AI/ML model governance, quantum-safe cryptography transition, agentic automation).
    • Oversee annual NIST CSF assessments and provide rigorous, actionable reporting to the CISO and senior leadership on program maturity and investment gaps.
    • In partnership with ISO teams, lead the Governance team in providing consultation to segments and business units, ensuring security requirements are understood, contextualized, and achievable - not perceived as obstacles.

  • Compliance Program Leadership
    • Provide oversight across all regulatory, contractual, and policy compliance programs, including SOX 404, PCI DSS, K-ISMS, GDPR, COPPA, ISO 27001, and more.
    • Build compliance-as-a-service capabilities for technology teams: engineers and product owners access a self-service portal to understand what compliance requirements apply to their system, what controls are already satisfied by platform-level implementations they inherit, what evidence is auto-collected on their behalf, and what residual actions remain — compliance burden on tech teams is measured and systematically driven toward zero.
    • Proactively monitor the regulatory horizon: identify emerging requirements before they become mandates, and position Disney to comply with confidence rather than scrambling.

  • Organizational Leadership
    • Lead, develop, and inspire a high-performing organization of ~40+ professionals across Governance, Compliance, and Risk Management.
    • Model and demand intellectual rigor, ownership, and a continuous improvement mindset - leading a team that challenges assumptions, identifies root causes, and delivers scalable and dynamic solutions.

Must Haves (Years of Experience, languages, programs, tools, etc.):

  • Experience & Expertise
    • 12+ years of progressive experience in cybersecurity, technology risk, or technology compliance, with a minimum of 3 years in leadership roles overseeing GRC functions at enterprise scale.
    • Demonstrated track record of building and transforming GRC programs, moving organizations to risk-driven operating models.
    • Deep expertise across the full GRC spectrum: risk management (frameworks, quantification, reporting), governance (policy lifecycle, automated enforcement, metrics), and compliance (regulatory audit management, controls assurance, overall audit alignment).
    • Extensive knowledge of information security risk, governance, and control frameworks: NIST CSF, NIST 800-53, ISO/IEC 27001, PCI DSS 4.0, SOX ITGC, GDPR.
    • Proven executive presence: ability to command a room, build trust with senior leadership, and translate highly technical risk concepts into clear business language.
    • Strong experience in risk quantification methodologies (FAIR or equivalent) and experience driving financial-terms risk reporting for executive audiences.

  • Technical Knowledge
    • Expert-level understanding of security audit methodologies, controls testing, and assurance processes across both IT general controls (ITGCs) and automated application controls.
    • Hands-on familiarity with implementing and operating GRC tooling and platforms (Archer, SailPoint, ServiceNow GRC, or equivalent).
    • Solid understanding of cloud security architecture and the compliance implications of cloud-native environments (IaaS, PaaS, SaaS) across major providers (AWS, Azure, GCP).
    • Familiarity with DevSecOps practices and the integration of security governance and compliance controls into software development and infrastructure deployment pipelines.

Nice To Haves (see above):

  • Experience in the Media & Entertainment, Sports, Hospitality, and/or Retail industries.
  • An understanding of the unique regulatory, content protection, and consumer-facing risks and compliance requirements of a global entertainment brand.
  • Big 4 accounting firm experience (audit or advisory) with direct exposure to Fortune 100 technology and security compliance programs.
  • CPA certification (active or expired).
  • Experience operating in a large, complex, matrixed enterprise with multiple business segments, regulatory regimes, and stakeholder groups.

Education:

  • Bachelor’s degree in Computer Science, Information Systems, Software, Electrical or Electronics Engineering, or comparable field of study, and/or equivalent work experience.
  • One or more of the following certifications required: CISSP, CISM, CISA, CRISC.


The hiring range for this position in Orlando, FL is $197,500 to $265,000 per year and in Glendale,CA is $207,400 to $278,200 per year. The hiring range for this position in Seattle, WA is $217,300 to $291,500 per year and in New York, NY is $217,300 to $291,500 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate’s geographic region, job-related knowledge, skills, and experience among other factors. A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.

申請

關於The Walt Disney Company (Corporate):

在 The Walt Disney Company (Corporate),你會看到公司強大品牌背後各業務如何融會交流,建構出全球最創新、影響深遠和備受尊崇的娛樂公司。作為企業團隊的一份子,你將會與推動策略以讓The Walt Disney Company穩佔娛樂界頂尖地位的世界精英領袖一同工作。與其他具有創新精神的思想家惺惺相惜,同時讓這個世界上最偉大的故事敍述家為全球各地千百萬家庭締造回憶。

關於 The Walt Disney Company:

Walt Disney Company 連同其子公司和聯營公司,是領先的多元化國際家庭娛樂和媒體企業,其業務主要涉及三個範疇:Disney Entertainment、ESPN 及 Disney Experiences。Disney 在 1920 年代的起步之初,只是一間卡通工作室,至今已成為娛樂界的翹楚,並昂然堅守傳承,繼續為家庭中每位成員創造世界一流的故事與體驗。Disney 的故事、人物與體驗傳遍世界每個角落,深入人心。我們在 40 多個國家/地區營運業務,僱員及演藝人員攜手協力,創造全球和當地人們都珍愛的娛樂體驗。

這個職位隸屬於 Disney Worldwide Services, Inc.,其所屬的業務部門是 The Walt Disney Company (Corporate)。

Disney Worldwide Services, Inc. 是提供平等就業機會的僱主。求職者都會獲得聘僱考量的機會,不分種族、宗教、膚色、生理性別、性傾向、社會性別、性別認同、性別表達、原國籍、血統、年齡、婚姻狀態、軍人或退伍軍人身份、醫療狀況、遺傳資訊或殘疾狀況、或者聯邦、州級或地方法律所禁止的其他任何基本特徵。Disney 提倡讓所有人的想法和決策都有助我們發展、創新、創造最好故事的商業環境,並與瞬息萬變的世界息息相關。

就業申請的殘疾便利安排

The Walt Disney Company and its Affiliated Companies are Equal Employment Opportunity employers and welcome all job seekers including individuals with disabilities and veterans with disabilities. If you have a disability and believe you need a reasonable accommodation in order to search for a job opening or apply for a position, visit the Disney candidate disability accommodations FAQs. We will only respond to those requests that are related to the accessibility of the online application system due to a disability.

遇到技術問題?查看常見問題以尋求協助。

招聘流程

  • 您的故事從哪裡開始?

    探索 Disney 職位空缺和 The Life at Disney 網誌,了解華特迪士尼公司有待發掘的所有精彩機會。

  • 迪士尼的故事裏,有你更精彩成就迪士尼故事

    有許多不同品牌和業務可供探索。當您找到適合您的機會後,請填寫您的申請,進行下一步。

  • 下一章

    申請後,您將收到一封電子郵件,讓您可存取應徵者控制面板。建立您的登入資料,並確保經常檢視您的控制面板,以查看申請進度。

探索此地點 華盛頓州西雅圖

西雅圖坐落在西北太平洋地區,擁有繁榮的餐飲場所、不拘一格的社區和迷人的海岸環境,是一個充滿活力的城市。該市被東邊的華盛頓湖和西邊的普吉特海灣包圍,是水上康樂和觀光遊船的理想地點。

我們的文化

  • 行政領導

    我們的高級主管為公司的日常營運帶來了豐富經驗、遠見思維和對卓越、創意和創新的共同承諾。

    了解更多 
  • 共融

    在Disney,我們希望每個人都能夠有歸屬感,並且茁壯成長。為員工和賓客創造一個互相尊重的共融環境,是我們公司文化和業務的核心。我們致力建立支援強大的工作環境以推動創新,並鞏固讓所有員工都感到備受接納、尊重和重視的文化。

    了解更多 

登記收取職缺通知

即時收到最新的工作機會的資訊。

關注我們的職位

星號表示必填欄位。

興趣要求從選項列表中選擇工作類別。從選項列表中選擇工作地點。最後,點擊「添加 (Add)」以建立你的職缺通知。

一經建立帳戶,即代表本人同意使用條款(在新視窗中開啟),並確認已閱讀私隱政策(在新視窗中開啟)

一經點擊「提交」,即同意我們的使用條款(在新視窗中開啟),並確認已閱讀我們的私隱政策(在新視窗中開啟)。如果本人選擇接收營銷訊息或電子通訊,本人可以隨時撤回對這些營銷訊息的同意。

一經點擊「提交」,即同意我們的使用條款(在新視窗中開啟),並確認已閱讀私隱政策(在新視窗中開啟)Cookie 政策(在新視窗中開啟)歐盟私隱權內容(在新視窗中開啟)

我們如何使用您的個人資料以及您的權利:

  1. 你的個人資料由 The Walt Disney Company Limited 控制,公司地址為:3 Queen Caroline Street, London, W6 9PE, United Kingdom。
  2. 當你遊覽 Disney、在 Disney 購物或使用任何 Disney 產品、服務或流動應用程式,The Walt Disney Company Family of Companies 亦可能使用你的資料,以向你提供此等服務、度身定制你的體驗,並向你發送有關服務的最新消息及通訊資料。
  3. 你擁有多項權利,包括有權要求存取、更改或移除你的個人資料,或更改你的營銷偏好設定(包括隨時撤回同意)。請參閱我們的私隱政策(在新視窗中開啟),以進一步了解如何管理你的營銷偏好設定或刪除你的帳戶。
  4. 如欲聯絡我們的資料保護專員,可發送電郵至:dataprotection@disney.co.uk
  5. 你有權向英國資訊專員的辦事處投訴:https://ico.org.uk/(在新視窗中開啟)
  6. 有關 Disney 資料收集和使用方式的更多資料,請見 Disney 的私隱政策(在新視窗中開啟)

點擊「提交」,即表示你同意我們的使用條款(在新視窗中開啟),並確認你已經閱讀我們的私隱政策(在新視窗中開啟)收集聲明(在新視窗中開啟)

如要進一步了解我們的一般資料收集、用途及做法,包括如何管理你的喜好設定,請參閱我們的私隱政策(在新視窗中開啟)。本人已閱讀和同意使用條款(在新視窗中開啟)

Privacy Policy Agreement

Privacy Policy Agreement

Privacy Policy Agreement

Privacy Policy Agreement

Privacy Policy Agreement