Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Executive Director, InfoSec Governance, Risk, and Compliance

Disney France

Executive Director, Info Security

At Disney, we're storytellers. We make the impossible, possible. The Walt Disney Company is a world-class entertainment and technological leader. Walt's passion was to continuously envision new ways to move audiences around the world - a passion that remains our touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, TV, movies and a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences - and we're constantly looking for new ways to enhance these exciting experiences.

The Enterprise Technology & Data mission is to deliver technology solutions that align to business strategies while enabling enterprise efficiency and promoting cross-company collaborative innovation. Global Information Security (GIS) provides services to protect the value and use of Disney's information through collaboration, empowerment, and education across The Walt Disney Company.

At Disney, innovation and imagination fuel everything we do. The InfoSec Governance, Risk & Compliance (GRC) team is not just a guardian of standards - we are leaders who drive the evolution of information security. As a strategic powerhouse in the GIS organization, our mission transcends compliance, setting new benchmarks for risk intelligence, automation, and integrated governance. We aim to redefine what "great" looks like, pioneering visionary approaches that shape how Disney (and the industry) understands and manages security risk.

The GRC team is the pulse of Disney's enterprise technology ecosystem. We don't just follow regulatory mandates; we leap ahead, leveraging data-driven insights, advanced risk quantification, and automated control frameworks to empower business leaders and technologists. Our collaborative culture ensures that every corner of GIS speaks a unified risk language, propelling risk-aware thinking to the forefront of daily business decisions and fueling cross-company innovation.

By joining this team, you become a change agent, transforming GRC from a "checkbox" function to a dynamic, strategic enabler. You will lead and inspire a diverse, high-performing group that anticipates emerging risk domains, shapes industry-leading policy design, and drives measurable, business-aligned security outcomes. If your passion is to advance, not just meet, industry standards, and to make a lasting impact on a legendary brand's global footprint, the InfoSec GRC team at Disney is your stage.

Responsibilities of Role (List in order of priority, first few bullets should be the most important):

  • Transform GRC at Disney
    • Drive continuous evolution of Disney's InfoSec GRC program, replacing compliance-centric, checkbox-driven operations with a dynamic, risk-intelligence-led model that directly informs how Disney prioritizes investment, staffing, and remediation.
    • Define what "great" looks like, not by referencing existing standards but by advancing them. Develop novel approaches to risk quantification, compliance automation, and governance integration.
    • Partner with GIS Leadership and Segment CTO teams to ensure the GRC program functions as a strategic business enabler, translating complex risk landscapes into executive- and board-ready insights that drive confident decision-making.
    • Champion a culture shift across all of GIS and the broader enterprise: risk awareness is everyone's job, and GRC's role is to make risk-informed thinking intuitive, not burdensome.
  • Risk Management Leadership
    • Oversee the development and ongoing operations of Disney's comprehensive InfoSec Risk Management program, including the establishment, implementation, and continuous improvement of the enterprise Risk Management Framework.
    • Establish and operationalize risk tolerance frameworks in partnership with executive leadership, defining clear thresholds that translate business appetite into actionable security investment and prioritization decisions.
    • Build and mature a cybersecurity risk register that serves as the authoritative source of truth for Disney's threat and control posture, dynamically integrated with threat intelligence, vulnerability management, and third-party risk inputs.
    • Drive risk-based prioritization across all InfoSec operational functions (engineering, red team, SOC, cloud security, etc.) - ensuring that every team's roadmap is anchored in defensible risk reduction rationale, not reactive urgency.
    • Develop executive and board-level risk reporting that is clear, credible, and decision-ready; ensure Disney's risk narrative is consistent from the CISO to the Audit Committee.
    • Lead efforts to quantify InfoSec risk in financial terms (FAIR or equivalent), enabling direct comparison of security investment across Disney's ubiquitous businesses and against measurable risk reduction outcomes.
    • Lead a third-party and supply chain risk intelligence capability that goes beyond questionnaire-based assessments by integrating continuous external attack surface monitoring, threat intelligence on vendor compromise activity, and contractual control requirements into a unified third-party risk posture.
  • Governance Program Leadership
    • Oversee the development, maintenance, and lifecycle management of enterprise-wide Information Security policies, standards, and guidelines, ensuring they are risk-based, clear, and aligned to business realities (not just regulatory checklists).
    • Drive automated policy enforcement and integration of governance requirements into the technology design lifecycle (DevSecOps, cloud provisioning, infrastructure-as-code, etc.), reducing reliance on manual control operations and attestation.
    • Lead the development of a policy effectiveness measurement framework that moves beyond "is the policy published and attested to?" toward "is the policy actually changing behavior and reducing risk?" (tracked via control telemetry, exception rates, and risk outcome data).
    • Pioneer a forward-looking policy architecture that anticipates emerging technology risk domains (AI/ML model governance, quantum-safe cryptography transition, agentic automation).
    • Oversee annual NIST CSF assessments and provide rigorous, actionable reporting to the CISO and senior leadership on program maturity and investment gaps.
    • In partnership with ISO teams, lead the Governance team in providing consultation to segments and business units, ensuring security requirements are understood, contextualized, and achievable - not perceived as obstacles.
  • Compliance Program Leadership
    • Provide oversight across all regulatory, contractual, and policy compliance programs, including SOX 404, PCI DSS, K-ISMS, GDPR, COPPA, ISO 27001, and more.
    • Build compliance-as-a-service capabilities for technology teams: engineers and product owners access a self-service portal to understand what compliance requirements apply to their system, what controls are already satisfied by platform-level implementations they inherit, what evidence is auto-collected on their behalf, and what residual actions remain — compliance burden on tech teams is measured and systematically driven toward zero.
    • Proactively monitor the regulatory horizon: identify emerging requirements before they become mandates, and position Disney to comply with confidence rather than scrambling.
  • Organizational Leadership
    • Lead, develop, and inspire a high-performing organization of ~40+ professionals across Governance, Compliance, and Risk Management.
    • Model and demand intellectual rigor, ownership, and a continuous improvement mindset - leading a team that challenges assumptions, identifies root causes, and delivers scalable and dynamic solutions.

Must Haves (Years of Experience, languages, programs, tools, etc.):

  • Experience & Expertise
    • 12+ years of progressive experience in cybersecurity, technology risk, or technology compliance, with a minimum of 3 years in leadership roles overseeing GRC functions at enterprise scale.
    • Demonstrated track record of building and transforming GRC programs, moving organizations to risk-driven operating models.
    • Deep expertise across the full GRC spectrum: risk management (frameworks, quantification, reporting), governance (policy lifecycle, automated enforcement, metrics), and compliance (regulatory audit management, controls assurance, overall audit alignment).
    • Extensive knowledge of information security risk, governance, and control frameworks: NIST CSF, NIST 800-53, ISO/IEC 27001, PCI DSS 4.0, SOX ITGC, GDPR.
    • Proven executive presence: ability to command a room, build trust with senior leadership, and translate highly technical risk concepts into clear business language.
    • Strong experience in risk quantification methodologies (FAIR or equivalent) and experience driving financial-terms risk reporting for executive audiences.
  • Technical Knowledge
    • Expert-level understanding of security audit methodologies, controls testing, and assurance processes across both IT general controls (ITGCs) and automated application controls.
    • Hands-on familiarity with implementing and operating GRC tooling and platforms (Archer, SailPoint, ServiceNow GRC, or equivalent).
    • Solid understanding of cloud security architecture and the compliance implications of cloud-native environments (IaaS,
Vacancy posted 18 hours ago
Similar jobs that could be interesting for youBased on the Executive Director, InfoSec Governance, Risk, and Compliance in New York, NY vacancy
  • $200k

     ...States LogicGate is a global leader in Governance, Risk, and Compliance (GRC) solutions, with a mission to...  ...lead a team of Strategic Account Executives to drive enterprise revenue growth....  ...Risk Management / GRC, Cybersecurity / InfoSec, ITSM, or No‐Code platforms Proven ability... 
    Suggested
    Contract work
    Summer work
    Immediate start
    Remote work
    Flexible hours

    LogicGate

    New York, NY
    3 days ago
  • $275k - $325k

     ...operating system for governed financial...  ...hiring a Managing Director, Strategic Accounts...  ...and warm outreach, executive briefings, partner...  ...of Wealth, Head of Risk) and convert them...  ...procurement, risk, and InfoSec on the spot....  ...procurement, risk, and compliance Drive... 
    Suggested
    Contract work
    Shift work

    Monstro

    New York, NY
    4 days ago
  • $65k - $150k

     ...Overview This incumbent will provide Strategy, Programs, Governance, Risk and Compliance functions as required to fulfill BOCNY information...  ...initiatives tracking and associated KRIs to track progress and execution of the objectives Conduct quarterly strategy reviews... 
    Suggested
    Work experience placement
    Work at office

    Bank of China Limited, New York Branch

    New York, NY
    3 days ago
  •  ...owning operational oversight, governance, and compliance readiness across day-to-day marketing execution and the marketing tool ecosystem...  ...with Compliance, Legal, Risk & Controls, Technology, and Internal...  ...Audit. As an Executive Director within Consumer Bank Marketing... 
    Suggested

    JPMorgan Chase & Co.

    Brooklyn, NY
    4 days ago
  • $265k - $330k

     ...team at Diligent, #1 market leader in Governance, Risk & Compliance tech and used by 75% of Fortune 500...  ...is your stage to drive impact at executive altitude while still getting hands-on...  ...management with 5+ years senior leadership (Director+ level) ~ Track record building/... 
    Suggested
    Work at office
    Local area
    Flexible hours

    Diligent

    New York, NY
    4 days ago
  •  ...Vice President, Firmwide Risk Identification Bring your expertise...  ...part of Risk Management and Compliance, you are at the center of...  ...ambiguity, balancing technical execution with clear communication,...  ...exposure to senior stakeholders and governance forums across Risk Management... 

    Chase

    New York, NY
    4 days ago
  •  ...AI Compliance, Conduct And Operational Risk Vice President Bring your expertise to JPMorgan Chase. As part of Risk Management and Compliance, you are...  ...JPMorganChase's implementation of AI, including governance and controls that enable safe scaling and adoption.... 
    Work at office

    Chase

    New York, NY
    2 days ago
  • A prominent financial services firm is seeking an Executive Director - Head of Digital Governance for Finance in New York or Baltimore. This role is critical...  ...candidate has extensive experience in operational risk and strong communication skills. They will engage with... 

    PowerToFly

    New York, NY
    2 days ago
  • JPMorgan Chase & Co. is looking for an Executive Director within Consumer Bank Marketing to lead operational oversight and governance. This pivotal role involves strengthening the control environment, ensuring compliance, and enhancing marketing execution through data-driven... 

    JPMorgan Chase & Co.

    Brooklyn, NY
    4 days ago
  • $147.25k - $215k

     ...Bring your expertise to JPMorganChase. As part of Risk Management and Compliance, you play a crucial role in maintaining JPMorganChase's strength...  ...As a Quant Model Risk Vice President in the Model Risk Governance and Review team, you will be responsible for assessing and... 

    JPMorgan Chase Bank, N.A.

    Jersey City, NJ
    5 days ago
  •  ...Vice President, Model Risk Governance and Review Bring your expertise to JPMorgan Chase. As part of Risk Management and Compliance, you are at the center of keeping JPMorgan Chase strong...  ...-for-purpose and can be efficiently executed by model risk stakeholders Ensure... 

    Chase

    New York, NY
    1 day ago
  •  ...investment firm in New York is seeking a Vice President in Compliance to enhance governance frameworks for electronic trading activities. The ideal...  ...regulations. Responsibilities include overseeing regulatory risk assessments, collaborating with global teams, and providing... 

    Goldman Sachs Group, Inc.

    New York, NY
    4 days ago
  • $330k - $390k

     ...innovative precision medicines for AMD. Role: Sr. Medical Director (or Executive Medical Director or VP of Clinical Development) Reports to:...  ...modifications as new data emerges. Regulatory Documentation & Compliance Author, review, and approve clinical trial protocols,... 
    Full time
    Remote work

    Character Biosciences

    Jersey City, NJ
    5 days ago
  •  ...Risk Management Advisor Lead a regional team of specialist...  ...accountability for strengthening governance, control frameworks, and risk...  ...and their teams, and support execution of relevant strategies. Bring...  ...and Change Management, Compliance, Business Management, Strategy... 
    Work experience placement
    Work at office
    Work from home
    Flexible hours

    Standard Chartered

    New York, NY
    5 days ago
  • $180k - $275k

     ...Trading Corporate Title: Director Location: New York, NY...  ...initiatives as well as financial risk / non-financial risk domains....  ...challenges Participate in governance fora as a representative of...  ...issues, Group Audit findings and Compliance findings). Partner with... 
    Work from home

    Deutsche Bank

    New York, NY
    5 days ago
  •  ...Senior Vice President, Legal and Chief Compliance Officer (CCO) About the Company...  ...directly impacts organizational strategy, governance, and risk posture. The successful candidate will...  ...on scaling and development. This executive position requires a candidate with over... 

    Confidential

    New York, NY
    3 days ago
  •  ...Vice President and Executive Director, Bank Loan Operations About the Company Leading financial...  ...portfolio management, and disciplined risk control across various credit products....  ...operational risk, escalations, and compliance with legal and regulatory standards, and... 

    Confidential

    New York, NY
    4 days ago
  • $180k - $200k

     ...institutions, corporates and governments through its three...  ...businesses as well as Technology, Risk Management, Legal and Compliance and Finance specialists,...  ...Technology Portfolio Director who is responsible for the...  ...leading, managing and executing Global Markets technology... 
    Work experience placement
    Relocation package

    Nomura

    New York, NY
    3 days ago
  •  .../restructure memos Monitor portfolio risk and proactively work to improve portfolio...  ...loan closing, credit administration and compliance procedures Ability to communicate...  ...prominent corporate, institutional and government clients under the J.P. Morgan and Chase... 
    Local area

    Chase

    New York, NY
    2 days ago
  • A leading financial services firm in New York is seeking a Technical Program Assurance Lead in Information Security. This role involves driving the assurance program, collaborating with senior leadership across various departments, and ensuring alignment with security strategies...

    Bloomberg L.P.

    New York, NY
    3 days ago
  • $100k - $140k

    Firm Risk Management Firm Risk Management (FRM) supports Morgan Stanley to achieve its...  ...manage routine processes, ensure on-time execution and proactively escalate risks and issues...  ...priorities. Designed, built, and governed enterprise reporting and dashboards spanning... 
    Temporary work
    Work at office
    Shift work

    Morgan Stanley

    New York, NY
    3 days ago
  • $210k - $255k

     ...newspaper by paid circulation; Barron's, MarketWatch, Mansion Global, Financial News, Investor's Business Daily, Factiva, Dow Jones Risk & Compliance, Dow Jones Newswires, OPIS and Chemical Market Analytics. Dow Jones is a division of News Corp (Nasdaq: NWS, NWSA; ASX: NWS,... 
    Work experience placement
    Local area
    Flexible hours

    Dow Jones & Company, Inc.

    New York, NY
    4 days ago
  • $220k - $250k

     ...visionary, and highly accomplished leader to serve as its Executive Director . This position reports to the Dean of the School of International...  ...with external stakeholders-heads of state, senior government officials, global institutions, NGOs, and private-sector leaders... 
    Temporary work
    Local area
    Immediate start

    Columbia University in the City of New York

    New York, NY
    1 day ago
  •  ...Applied Ai Modeling Executive Director Our Branch Network Modeling team develops advanced...  ...Market Strategy, as well as with Governance and Compliance stakeholders. Your success will be measured...  ...of models, proactively identifying risks and ensuring adherence to internal... 
    Relocation

    Chase

    New York, NY
    1 day ago
  •  ...Supervise credit approval memos/restructure memos Monitor portfolio risk and proactively work to improve portfolio quality and prevent...  ...account maintenance, loan closing, credit administration and compliance procedures Ability to communicate sophisticated credit concepts... 
    Local area

    JPMorgan Chase & Co.

    New York, NY
    3 days ago
  •  ...Credit Officer in Asset Based Lending Credit Risk Job Description Bring your...  ...risk professionals. In Risk Management and Compliance, you are at the center of keeping JPMorgan...  ..., you will be part of the firm's risk governance framework and a critical member of the risk... 

    JPMorgan Chase

    New York, NY
    2 days ago
  • $93.4k - $106.6k

    Principal Process Manager - Training Governance The Anti-Money Laundering (AML)University (...  ...governance improvements / controls to mitigate risk or increase quality of work Provide...  ...or more years of experience in a Risk, Compliance, Project or Process Management role... 
    Full time
    Part time
    Local area

    Capital One National Association

    New York, NY
    3 days ago
  • $262k - $289k

     ...ensuring that every deal and every line of business delivers sustainable, risk-appropriate economic value. The CPO serves as the central hub for pricing frameworks, tools, assumptions, and governance across the organization. The CPO mandate includes: Establishing... 
    Work at office
    Shift work

    Munich Re

    New York, NY
    4 days ago
  • $174k - $220k

     ...Director Engineering Operations (Chief Of Staff)...  ...Drive fiscal and resource governance, partnering with Finance...  ...bottlenecks, risks, or delivery challenges...  ...lightweight yet high-compliance definitions of "Ready"...  ..." to drive consistent execution across teams. · Oversee... 
    Work at office
    Flexible hours

    Diligent

    New York, NY
    1 day ago
  •  ...Chief Executive Officer (CEO) and Chief Operating Officer (COO) About the Company Well-regarded independent company in the FMCG & CPG sectors Industry Food & Beverages Type Privately Held About the Role The Company is in search of a dynamic... 
    Worldwide

    Confidential

    New York, NY
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Executive Director, InfoSec Governance, Risk, and Compliance. Be the first to apply!