Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Executive Director, InfoSec Governance, Risk, and Compliance

$197.5k - $265k

The Walt Disney Company

At Disney, we’re storytellers. We make the impossible, possible. The Walt Disney Company (TWDC) is a world-class entertainment and technological leader. Walt’s passion was to continuously envision new ways to move audiences around the world—a passion that remains our touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, news, movies and a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences — and we’re constantly looking for new ways to enhance these exciting experiences.

The Enterprise Technology mission is to deliver technology solutions that align to business strategies while enabling enterprise efficiency and promoting cross-company collaborative innovation. Our group drives competitive advantage by enhancing our consumer experiences, enabling business growth, and advancing operational excellence.

Team Description:

The Global Information Security (GIS) group provides services to protect the value and use of Disney’s information through collaboration, standardization, enforcement, and education across The Walt Disney Company. The main focus areas of this group are: Reduce the risk of both accidental and malicious data disclosure; Identify, monitor, engage with complete inventory of information; Establish appropriate policies and procedures to be followed; Educate user community to minimize risk.

Disney’s InfoSec GRC team is seeking a transformational leader to drive the next evolution of Governance, Risk, and Compliance across the enterprise. Reporting to the VP of Information Security, this role will lead the shift from a traditional compliance-driven approach to a modern, risk-intelligence-led model that enables better business decisions, strengthens security posture, and scales with Disney’s global technology and content ecosystem. This leader will partner closely with GIS and business leadership to embed risk awareness into daily operations, ensuring GRC is a strategic enabler of innovation—not a barrier.

What You'll Do

Transform GRC at Disney

  • Drive the evolution of Disney’s InfoSec GRC program from a compliance-centric model to a dynamic, risk-intelligence-led capability that informs enterprise investment and prioritization decisions

  • Define and elevate GRC standards by introducing innovative approaches to risk quantification, compliance automation, and integrated governance

  • Partner with GIS and segment technology leadership to position GRC as a strategic business enabler, translating complex risks into actionable, executive-ready insights

  • Champion a culture where risk awareness is embedded into daily decision-making, enabling intuitive and scalable risk-informed behaviors across the enterprise

Risk Management Leadership

  • Lead the design, implementation, and continuous improvement of Disney’s enterprise InfoSec Risk Management Framework

  • Establish and operationalize risk tolerance models, translating business objectives into clear prioritization, investment, and remediation decisions

  • Build and mature a centralized cybersecurity risk register integrating threat intelligence, vulnerabilities, and third-party risk data

  • Drive risk-based prioritization across InfoSec functions to ensure measurable risk reduction and alignment to enterprise objectives

  • Deliver clear, credible, and decision-ready risk reporting to executive leadership and the Board, including financial risk quantification (e.g., FAIR)

Governance Program Leadership

  • Oversee the full lifecycle of InfoSec policies, standards, and guidelines, ensuring they are risk-based, actionable, and aligned with business needs

  • Embed governance controls into the technology lifecycle (e.g., DevSecOps, cloud, infrastructure-as-code), reducing reliance on manual processes through automation

  • Establish a policy effectiveness framework focused on behavioral change and measurable risk reduction

  • Define and advance governance strategies for emerging technologies, including AI/ML, quantum security, and autonomous systems

  • Lead enterprise maturity assessments (e.g., NIST CSF) to identify gaps and inform strategic investment decisions

Compliance Program Leadership

  • Provide oversight of global regulatory and contractual compliance programs (e.g., SOX, PCI, GDPR, ISO), ensuring consistency and scalability

  • Build and operationalize a “compliance-as-a-service” model that enables self-service, automates evidence collection, and minimizes burden on engineering teams

  • Monitor and anticipate changes in the regulatory landscape, proactively positioning Disney to meet evolving requirements

Organizational Leadership

  • Lead, develop, and scale a high-performing global GRC organization, fostering a culture of accountability, innovation, and continuous improvement

  • Drive organizational excellence through strong leadership, talent development, and a focus on delivering scalable, forward-looking solutions

What You’ll Bring

Must-Have Qualifications

  • You will have 12+ years of progressive experience in cybersecurity, technology risk, or compliance, including 3+ years leading enterprise-scale GRC functions

  • You will bring structured problem-solving, audit rigor, and enterprise advisory experience

  • You will have industry experience within large, complex organizations, with the ability to operate effectively in highly matrixed environments

  • You will have a proven track record of transforming GRC programs into risk-driven operating models that influence enterprise decision-making

  • You will have deep expertise across risk management, governance, and compliance, including frameworks, policy lifecycle, automation, audit, and controls assurance )

  • You will have strong working knowledge of industry frameworks and regulations, including NIST CSF, NIST 800-53, ISO 27001, PCI DSS 4.0, SOX ITGC, and GDPR

  • You will have demonstrated executive presence and exceptional influence skills, with the ability to operate as a trusted advisor to senior leadership and translate complex technical risk into clear business insights

  • You will have experience applying financial risk quantification methodologies (e.g., FAIR) to support investment and prioritization decisions

  • You will have a strong customer-focused mindset, ensuring GRC solutions enable the business and enhance—not hinder—user and product experiences

  • You will have experience leading in highly matrixed, global environments, driving alignment across engineering, security, and business stakeholders

Leadership & Transformation Profile (Critical for Success)

  • You will have a mindset of a thought partner—not just an operator—bringing a strategic, forward-looking perspective to GRC

  • You will have a track record of asking hard questions, challenging legacy ways of working, and driving meaningful change across organizations

  • You will have the ability to connect cost, customer experience, and operational efficiency into a cohesive, risk-informed strategy

  • You will have demonstrated success leading large-scale transformation initiatives, influencing without authority, and driving adoption across complex organizations

Technical Expertise

  • You will have advanced expertise in audit methodologies, controls testing, and assurance processes, including ITGCs and automated control environments (must have qualification)

  • You will have hands-on experience with leading GRC platforms (e.g., Archer, ServiceNow GRC, SailPoint)

  • You will have a strong understanding of cloud security and compliance across AWS, Azure, and GCP environments

  • You will have familiarity with DevSecOps practices and integrating security and governance into software development and infrastructure pipelines

Nice-to-Have Qualifications

  • You may have experience within media, entertainment, or similarly complex, consumer-facing industries

  • You may have experience from a Big 4 consulting firm.

  • You may have experience advancing emerging risk domains such as AI/ML governance, third-party risk, or next-generation compliance capabilities

Education

  • You will have a bachelor’s degree in computer science, information security, or a related field—or equivalent practical experience

  • You may have advanced degrees or relevant certifications (e.g., CISSP, CISM, CRISC)

The hiring range for this position in Orlando, FL is $197,500 to $265,000 per year and in Glendale,CA is $207,400 to $278,200 per year. The hiring range for this position in Seattle, WA is $217,300 to $291,500 per year and in New York, NY is $217,300 to $291,500 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate’s geographic region, job-related knowledge, skills, and experience among other factors. A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.

Job ID: 10152675

Location: Seattle,Washington

Job Posting Company: The Walt Disney Company (Corporate)

The Walt Disney Company and its Affiliated Companies are Equal Employment Opportunity employers and welcome all job seekers including individuals with disabilities and veterans with disabilities. If you have a disability and believe you need a reasonable accommodation in order to search for a job opening or apply for a position, email View email address on click.appcast.io with your request. This email address is not for general employment inquiries or correspondence. We will only respond to those requests that are related to the accessibility of the online application system due to a disability.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Executive Director, InfoSec Governance, Risk, and Compliance in Seattle, WA vacancy
  •  ...Executive Director, Info Security At Disney, we're storytellers. We make the impossible, possible. The Walt Disney Company...  ...innovation and imagination fuel everything we do. The InfoSec Governance, Risk & Compliance (GRC) team is not just a guardian of standards - we... 
    Suggested
    Shift work

    Disney France

    Seattle, WA
    3 days ago
  • $197.5k - $265k

     ...Job Title Job Description Responsibilities of Role Transform GRC at Disney Risk Management Leadership Governance Program Leadership Compliance Program Leadership Organizational Leadership Must Haves Experience & Expertise Technical... 
    Suggested
    Work experience placement

    The Walt Disney Studios

    Seattle, WA
    3 days ago
  •  ...Senior Vice President, Legal and Chief Compliance Officer (CCO) About the Company...  ...directly impacts organizational strategy, governance, and risk posture. The successful candidate will...  ...focus on scaling and development. This executive position requires a candidate with... 
    Suggested

    Confidential

    Seattle, WA
    1 day ago
  • $157.06k - $219.88k

     ...ownership. The person in this role will be expected to help drive execution across key initiatives, review materials and recommendations...  ...tie functional activity to enterprise outcomes (getting to rate, risk reduction, employee/site safety) Drive special projects and... 
    Suggested
    Permanent employment
    Temporary work
    Work at office
    Local area
    Relocation

    Blue Origin

    Seattle, WA
    2 days ago
  •  ...particularly in the areas of time management, decision-making, and execution. The successful candidate will be a trusted partner, gatekeeper...  ...lead high-impact special projects, and a proactive approach to risk management are essential. Hiring Manager Title CEO Travel... 
    Suggested

    Confidential

    Seattle, WA
    1 day ago
  •  ...instrumental in optimizing the time, focus, decision-making, and execution of the Senior Leadership Team. The Chief of Staff will be a...  ...fully remote and requires a proactive individual who can surface risks and close gaps effectively. Hiring Manager Title Chief Executive... 
    Remote work

    Confidential

    Seattle, WA
    1 day ago
  •  ...Manage both ongoing and spur‑of‑the‑moment, deadline‑driven projects Work in partnership with the Marketing Department to plan and execute company‑wide events Coordinate travel and hotel accommodations for company parties, sales retreats, and other employee events File... 
    Work at office
    Remote work

    Rain City Capital

    Kirkland, WA
    1 day ago
  •  ...Member, Finance, Legal & Governance About the Company Mission...  ...of financial oversight, risk assessment, and compliance. This includes providing...  ...candidate will have a senior executive background in finance,...  ...Less than 10% Functions Board of Directors (non-operating)... 
    Remote work

    Confidential

    Seattle, WA
    12 hours ago
  •  ...Board Member, Nonprofit Governance About the Company Mission-driven organization producing...  ...individuals to join its Board of Directors. Board Members play a pivotal role in providing...  ...with its goals. Legal and ethical compliance is a key aspect of the role, and Board... 

    Confidential

    Seattle, WA
    1 day ago
  •  ...Board Member, Nonprofit Governance & Strategic Leadership About the Company Mission...  ...dedicated individuals to join its Board of Directors. Board Members will be instrumental in...  ..., and ensuring legal and ethical compliance. Travel Percent Less than 10% Functions... 

    Confidential

    Seattle, WA
    17 hours ago
  •  ...Board Member, Nonprofit Governance & Strategic Leadership About the Company Mission...  ...dedicated individuals to join its Board of Directors. Board Members play a crucial role in...  ..., and ensuring legal and ethical compliance. Candidates for the Board should have a... 

    Confidential

    Seattle, WA
    4 days ago
  •  ...Board Member, Nonprofit Governance About the Company Well-known child care resource...  ...dedicated individuals to join its Board of Directors. Board Members play a pivotal role in...  ...planning, and ensure legal and ethical compliance. The ideal candidate for the Board... 

    Confidential

    Seattle, WA
    4 days ago
  • Managing Director, Cybersecurity, Information Governance page is loaded## Managing Director, Cybersecurity...  ...services, cyber risk and data privacy...  ...deliver solutions. You will execute critical project deliverables...  ...technology, legal, compliance, information management,... 
    Remote work

    Ankura

    Seattle, WA
    3 days ago
  •  ...Board Member, Nonprofit Governance About the Company Mission-driven organization providing storytelling-based programs to diverse...  ...Company is seeking dedicated individuals to join its Board of Directors. Board Members play a crucial role in guiding the strategic direction... 

    Confidential

    Seattle, WA
    4 days ago
  • $159.3k - $273.2k

     ...goals. Reporting to the chief executive officer, the COO provides...  ...management, project scope definition, risk identification, project...  ...Supports, develops and validates compliance with operations policies,...  ...Experience related to publicly funded government health care programs (e.g.,... 
    Minimum wage
    Full time
    Contract work
    Work experience placement
    Local area
    Relocation

    UnitedHealthcare

    Renton, WA
    17 hours ago
  • $120k

     ...leadership team and the Board of Directors, the COO will oversee organizational operations, compliance, technology strategy, data...  .... The ideal candidate is execution-oriented, strategic, and adept...  ...Board to guide our long-term governance, and staff across the organization... 
    Full time
    Part time
    Summer holiday
    Live in
    Local area
    Immediate start
    Remote work
    Monday to Friday
    Flexible hours
    Shift work

    Rhizome co

    Seattle, WA
    17 hours ago
  •  ...Chief Operating Officer (COO) to join their executive team. This pivotal role requires a...  ...and asset strategy, including financial risk assessment and recapitalization or repositioning...  ...innovation, ideally spanning nonprofit, government, or mission-driven startups. ~1–3... 
    Local area
    Relocation
    Flexible hours

    Reneris

    Seattle, WA
    3 days ago
  •  ...Executive Vice President, Annuity Solutions About the Company Globally renowned reinsurance company Industry Insurance Type...  ...the oversight of in-force profitability, financial reporting, risk analysis, experience studies, and client relationship management... 

    Confidential

    Seattle, WA
    1 day ago
  • $250k - $325k

     ...We are looking for an experienced and execution-focused Chief Operating Officer (COO) to...  ...customer support, incident management, compliance, and cross-functional execution.  As COO...  ...operational cadence.  Compliance & Risk Management   ~ Ensure HIPAA, HITRUST,... 
    Full time
    H1b

    Curative AI, Inc.

    Bellevue, WA
    2 days ago
  •  ...Introduction: AstroHire Executive Search (Est. 2017), a 100% Native American...  ...increase efficiency, service quality, and compliance readiness. Strengthen communication channels...  ...property performance monitoring, risk mitigation, and compliance across the housing... 
    Permanent employment
    Full time
    Contract work
    Temporary work
    For contractors
    Interim role
    Local area
    Immediate start
    Relocation
    Night shift

    Astrohire

    Seattle, WA
    2 days ago
  • Do NOT apply through VolunteerMatch. Please apply here instead. Note: Please apply using our website here. No applications directly from VolunteerMatch are accepted. Responsibilities - Collaborate with CEO in setting and driving organizational vision...

    Digital Aid Seattle

    Seattle, WA
    1 day ago
  •  ...organization in the U.S. is seeking a Chief Operating Officer. This leader will build an operations system that enables effective execution across various markets. With over 15 years of experience in healthcare operations, the COO will ensure alignment in priorities and... 
    Remote work

    Zócalo Health

    Seattle, WA
    2 days ago
  •  ...project management office, procurement, and vendor management. This executive will be tasked with delivering operational excellence,...  ...current operational practices, taking ownership of issues and risks, and establishing a culture of excellence and continuous improvement... 

    Confidential

    Seattle, WA
    1 day ago
  • $195k - $220k

     ...Job Type Full-time Description Chief Operating Officer Reports To: Managing Director Salary: $195,000 - $220,000 Status: Exempt Location: Seattle About Us: Williams Kastner is a premier multi-practice law firm in the Pacific... 
    Full time
    Temporary work
    Work at office
    Local area
    Remote work
    2 days per week

    Williams Kastner

    Seattle, WA
    1 day ago
  •  ...seeking a Chief Operating Officer (COO) to serve as the operational leader and drive the company's performance in partnership with the executive team and board. The COO will be responsible for overseeing branch operations, ensuring high-quality service delivery, and meeting... 

    Confidential

    Seattle, WA
    3 days ago
  •  ...and commercial operations, and will work closely with the CEO, CMO, and CFO to ensure the translation of strategy into effective execution. This role demands a leader who can scale the organization, strengthen distributor performance, and is adept at building and leading... 

    Confidential

    Seattle, WA
    3 days ago
  •  ...Computer Software Type Privately Held About the Role The Company is seeking a Chief Operating Officer (COO) to join its executive team and play a pivotal role in the organization. The successful candidate will be responsible for driving the company through its... 

    Confidential

    Seattle, WA
    2 days ago
  •  ...for those with experience in manufacturing building materials. The role demands a leader with a proven track record in a similar executive position, a minimum of 10 years in a manufacturing environment, and a deep understanding of lean manufacturing principles. The ideal... 

    Confidential

    Seattle, WA
    2 days ago
  •  ...understanding of supply chain, vendor management, and regulatory compliance, and experience in process improvement and technology...  ...centric approach. Key responsibilities include direct tactical execution across various operational functions, optimizing resource allocation... 

    Confidential

    Seattle, WA
    3 days ago
  •  ...Operating Officer About the Company The firm is a global executive search and leadership advisory firm. Industry Management...  ...executive coaching strategy private equity consulting risk digital transformation succession planning board & c-level... 
    Flexible hours

    Confidential

    Seattle, WA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Executive Director, InfoSec Governance, Risk, and Compliance. Be the first to apply!