The Walt Disney Company

Executive Director, InfoSec Governance, Risk, and Compliance

The Walt Disney Company$207K — $278K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 12+ years in cybersecurity, technology risk, or compliance, with 3+ years in leadership roles
  • Proven experience in transforming GRC programs to risk-driven models
  • Expertise in risk management, governance, and compliance frameworks
  • Strong understanding of NIST CSF, ISO/IEC 27001, PCI DSS, and GDPR
  • Proficient in risk quantification methodologies like FAIR
  • Demonstrated executive presence and ability to communicate complex risks simply

Responsibilities

  • Transform GRC at Disney by leading the shift to a risk-intelligence-driven model
  • Define new benchmarks for risk quantification and compliance automation
  • Collaborate with leadership to align GRC with business objectives
  • Foster a culture of risk awareness across the organization
  • Oversee the InfoSec Risk Management program including Risk Management Framework
  • Establish risk tolerance frameworks with executive leadership
  • Develop comprehensive, actionable risk reporting for executives

Benefits

  • Comprehensive medical benefits
  • 401(k) plan with company matching
  • Flexible work arrangements
  • Professional development opportunities
  • Access to Disney parks and employee discounts
Full Job Description
Job Posting Title:
Executive Director, InfoSec Governance, Risk, and Compliance

Req ID:


Job Description:

Team Description:

The Global Information Security (GIS) group provides services to protect the value and use of Disney's information through collaboration, standardization, enforcement, and education across The Walt Disney Company. The main focus areas of this group are: Reduce the risk of both accidental and malicious data disclosure; Identify, monitor, engage with complete inventory of information; Establish appropriate policies and procedures to be followed; Educate user community to minimize risk.

Disney's InfoSec GRC team is seeking a transformational leader to drive the next evolution of Governance, Risk, and Compliance across the enterprise. Reporting to the VP of Information Security, this role will lead the shift from a traditional compliance-driven approach to a modern, risk-intelligence-led model that enables better business decisions, strengthens security posture, and scales with Disney's global technology and content ecosystem. This leader will partner closely with GIS and business leadership to embed risk awareness into daily operations, ensuring GRC is a strategic enabler of innovation-not a barrier.

What You'll Do

Transform GRC at Disney

  • Drive the evolution of Disney's InfoSec GRC program from a compliance-centric model to a dynamic, risk-intelligence-led capability that informs enterprise investment and prioritization decisions


  • Define and elevate GRC standards by introducing innovative approaches to risk quantification, compliance automation, and integrated governance


  • Partner with GIS and segment technology leadership to position GRC as a strategic business enabler, translating complex risks into actionable, executive-ready insights


  • Champion a culture where risk awareness is embedded into daily decision-making, enabling intuitive and scalable risk-informed behaviors across the enterprise


Risk Management Leadership

  • Lead the design, implementation, and continuous improvement of Disney's enterprise InfoSec Risk Management Framework


  • Establish and operationalize risk tolerance models, translating business objectives into clear prioritization, investment, and remediation decisions


  • Build and mature a centralized cybersecurity risk register integrating threat intelligence, vulnerabilities, and third-party risk data


  • Drive risk-based prioritization across InfoSec functions to ensure measurable risk reduction and alignment to enterprise objectives


  • Deliver clear, credible, and decision-ready risk reporting to executive leadership and the Board, including financial risk quantification (e.g., FAIR)


Governance Program Leadership

  • Oversee the full lifecycle of InfoSec policies, standards, and guidelines, ensuring they are risk-based, actionable, and aligned with business needs


  • Embed governance controls into the technology lifecycle (e.g., DevSecOps, cloud, infrastructure-as-code), reducing reliance on manual processes through automation


  • Establish a policy effectiveness framework focused on behavioral change and measurable risk reduction


  • Define and advance governance strategies for emerging technologies, including AI/ML, quantum security, and autonomous systems


  • Lead enterprise maturity assessments (e.g., NIST CSF) to identify gaps and inform strategic investment decisions


Compliance Program Leadership

  • Provide oversight of global regulatory and contractual compliance programs (e.g., SOX, PCI, GDPR, ISO), ensuring consistency and scalability


  • Build and operationalize a "compliance-as-a-service" model that enables self-service, automates evidence collection, and minimizes burden on engineering teams


  • Monitor and anticipate changes in the regulatory landscape, proactively positioning Disney to meet evolving requirements


Organizational Leadership

  • Lead, develop, and scale a high-performing global GRC organization, fostering a culture of accountability, innovation, and continuous improvement


  • Drive organizational excellence through strong leadership, talent development, and a focus on delivering scalable, forward-looking solutions


What You'll Bring

Must-Have Qualifications

  • You will have 12+ years of progressive experience in cybersecurity, technology risk, or compliance, including 3+ years leading enterprise-scale GRC functions


  • You will bring structured problem-solving, audit rigor, and enterprise advisory experience


  • You will have industry experience within large, complex organizations, with the ability to operate effectively in highly matrixed environments


  • You will have a proven track record of transforming GRC programs into risk-driven operating models that influence enterprise decision-making


  • You will have deep expertise across risk management, governance, and compliance, including frameworks, policy lifecycle, automation, audit, and controls assurance)


  • You will have strong working knowledge of industry frameworks and regulations, including NIST CSF, NIST 800-53, ISO 27001, PCI DSS 4.0, SOX ITGC, and GDPR


  • You will have demonstrated executive presence and exceptional influence skills, with the ability to operate as a trusted advisor to senior leadership and translate complex technical risk into clear business insights


  • You will have experience applying financial risk quantification methodologies (e.g., FAIR) to support investment and prioritization decisions


  • You will have a strong customer-focused mindset, ensuring GRC solutions enable the business and enhance-not hinder-user and product experiences


  • You will have experience leading in highly matrixed, global environments, driving alignment across engineering, security, and business stakeholders


Leadership & Transformation Profile (Critical for Success)

  • You will have a mindset of a thought partner-not just an operator-bringing a strategic, forward-looking perspective to GRC


  • You will have a track record of asking hard questions, challenging legacy ways of working, and driving meaningful change across organizations


  • You will have the ability to connect cost, customer experience, and operational efficiency into a cohesive, risk-informed strategy


  • You will have demonstrated success leading large-scale transformation initiatives, influencing without authority, and driving adoption across complex organizations


Technical Expertise

  • You will have advanced expertise in audit methodologies, controls testing, and assurance processes, including ITGCs and automated control environments (must have qualification)


  • You will have hands-on experience with leading GRC platforms (e.g., Archer, ServiceNow GRC, SailPoint)


  • You will have a strong understanding of cloud security and compliance across AWS, Azure, and GCP environments


  • You will have familiarity with DevSecOps practices and integrating security and governance into software development and infrastructure pipelines


Nice-to-Have Qualifications

  • You may have experience within media, entertainment, or similarly complex, consumer-facing industries


  • You may have experience from a Big 4 consulting firm.


  • You may have experience advancing emerging risk domains such as AI/ML governance, third-party risk, or next-generation compliance capabilities


Education

  • You will have a bachelor's degree in computer science, information security, or a related field-or equivalent practical experience


  • You may have advanced degrees or relevant certifications (e.g., CISSP, CISM, CRISC)


The hiring range for this position in Orlando, FL is $197,500 to $265,000 per year and in Glendale,CA is $207,400 to $278,200 per year. The hiring range for this position in Seattle, WA is $217,300 to $291,500 per year and in New York, NY is $217,300 to $291,500 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate's geographic region, job-related knowledge, skills, and experience among other factors. A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.

Job Posting Segment:
Enterprise Technology and Data

Job Posting Primary Business:
Global Information Security

Primary Job Posting Category:
Security Operations

Employment Type:
Full time

Primary City, State, Region, Postal Code:
Seattle, WA, USA

Alternate City, State, Region, Postal Code:
USA - CA - 1200 Grand Central Ave

Date Posted:
2026-05-29

About The Walt Disney Company

The Walt Disney Company started as a cartoon studio and evolves into sports coverage and television shows. Using the company's portfolio of brands to differentiate our content, services, and consumer products, Walt Disney seeks to develop creative, innovative, and profitable entertainment experiences and related products.

The Walt Disney Company Careers

Join the magical world of The Walt Disney Company, a place where dreams come true and imagination meets innovation. As a global leader in entertainment and media, we offer unparalleled job opportunities that invite you to be part of a beloved brand known for its influential culture, diversity, and dynamic growth. Work You’ll Do Embark on a career journey with The Walt Disney Company and play a pivotal role in shaping the future of media and entertainment. Engage in work that matters, contributes to storytelling excellence, and brings joy to millions around the globe. Transform your professional life by joining a team that values creativity, leadership, and visionary thinking. The Walt Disney Company stands at the forefront of industry innovation, constantly pushing the boundaries of what’s possible in entertainment and beyond. Lead with us from a unique position in the marketplace, where your skills in technology, creativity, and management converge to create extraordinary experiences. Collaborate with a diverse group of talented professionals, united in their passion for delivering magical experiences. Our team at The Walt Disney Company is composed of over 200,000 dedicated individuals who thrive in an environment that fosters growth, mentorship, and innovation. Introducing The Walt Disney Company Leadership and Professional Growth Programs We are committed to developing leaders who can navigate the challenges of the digital era and drive success across our various business segments. Our leadership programs are designed to hone your skills and prepare you for executive roles within the company. Do Innovative Work Join our team and contribute to projects that redefine the entertainment landscape. From groundbreaking films and television series to pioneering technological advancements, your work at The Walt Disney Company will set new standards in the creative and business worlds. Be Part of a Great Team Experience a culture that is inclusive, collaborative, and forward-thinking. Work alongside the best in the business and see how diversity and inclusion fuel our creativity and success. The Walt Disney Company’s commitment to a diverse workforce is evident in our hiring practices, training programs, and our everyday operations. Future-Proof Your Career With a wide array of benefits, continuous learning opportunities, and a network of supportive colleagues, your career at The Walt Disney Company is equipped for longevity and success. Our benefits package includes comprehensive health care, employee discounts, and access to exclusive company events and previews. Explore Job Opportunities and Internships Whether you’re a seasoned professional looking for your next challenge or a student seeking a transformative internship, The Walt Disney Company offers positions across a spectrum of fields and disciplines. Explore our career portal to find job opportunities that match your skills and passions. Stay Connected Join Our Team Search open positions, apply through our streamlined application process, and take the first step towards a magical career. We look for individuals who are passionate, curious, and eager to contribute to our legacy of storytelling and innovation. Keep Up to Date Stay informed with the latest company news, career tips, and insider perspectives—all from the people who make The Walt Disney Company a place of inspiration and excitement. Job Alert Emails Customize your subscription to receive job alerts and updates that align with your career interests. Discover the exciting and rewarding opportunities that await at The Walt Disney Company. Join us, and be part of the magic that only happens here at The Walt Disney Company!
Learn more about The Walt Disney Company
Size
190,000 employees
Market Cap
$155.1 billion
Industry
Net Income
-$4.9 billion
Founded
1923
5 Year Trend
+3.9%
Revenue
$60.7 billion
NASDAQ

Similar Jobs

More Jobs at The Walt Disney Company

More Information Technology Jobs

Find similar Executive Director, InfoSec Governance, Risk, and Compliance jobs: