Executive Director, InfoSec Governance, Risk, and Compliance
$197.5k - $265kThe Walt Disney Studios
Disney Information Security Grc Leader
At Disney, we're storytellers. We make the impossible, possible. The Walt Disney Company (TWDC) is a world-class entertainment and technological leader. Walt's passion was to continuously envision new ways to move audiences around the world—a passion that remains our touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, news, movies and a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences—and we're constantly looking for new ways to enhance these exciting experiences.
The Enterprise Technology mission is to deliver technology solutions that align to business strategies while enabling enterprise efficiency and promoting cross-company collaborative innovation. Our group drives competitive advantage by enhancing our consumer experiences, enabling business growth, and advancing operational excellence.
The Global Information Security (GIS) group provides services to protect the value and use of Disney's information through collaboration, standardization, enforcement, and education across The Walt Disney Company. The main focus areas of this group are: Reduce the risk of both accidental and malicious data disclosure; Identify, monitor, engage with complete inventory of information; Establish appropriate policies and procedures to be followed; Educate user community to minimize risk.
Disney's InfoSec GRC team is seeking a transformational leader to drive the next evolution of Governance, Risk, and Compliance across the enterprise. Reporting to the VP of Information Security, this role will lead the shift from a traditional compliance-driven approach to a modern, risk-intelligence-led model that enables better business decisions, strengthens security posture, and scales with Disney's global technology and content ecosystem. This leader will partner closely with GIS and business leadership to embed risk awareness into daily operations, ensuring GRC is a strategic enabler of innovation—not a barrier.
What You'll Do
Transform GRC at Disney
- Drive the evolution of Disney's InfoSec GRC program from a compliance-centric model to a dynamic, risk-intelligence-led capability that informs enterprise investment and prioritization decisions
- Define and elevate GRC standards by introducing innovative approaches to risk quantification, compliance automation, and integrated governance
- Partner with GIS and segment technology leadership to position GRC as a strategic business enabler, translating complex risks into actionable, executive-ready insights
- Champion a culture where risk awareness is embedded into daily decision-making, enabling intuitive and scalable risk-informed behaviors across the enterprise
Risk Management Leadership
- Lead the design, implementation, and continuous improvement of Disney's enterprise InfoSec Risk Management Framework
- Establish and operationalize risk tolerance models, translating business objectives into clear prioritization, investment, and remediation decisions
- Build and mature a centralized cybersecurity risk register integrating threat intelligence, vulnerabilities, and third-party risk data
- Drive risk-based prioritization across InfoSec functions to ensure measurable risk reduction and alignment to enterprise objectives
- Deliver clear, credible, and decision-ready risk reporting to executive leadership and the Board, including financial risk quantification (e.g., FAIR)
Governance Program Leadership
- Oversee the full lifecycle of InfoSec policies, standards, and guidelines, ensuring they are risk-based, actionable, and aligned with business needs
- Embed governance controls into the technology lifecycle (e.g., DevSecOps, cloud, infrastructure-as-code), reducing reliance on manual processes through automation
- Establish a policy effectiveness framework focused on behavioral change and measurable risk reduction
- Define and advance governance strategies for emerging technologies, including AI/ML, quantum security, and autonomous systems
- Lead enterprise maturity assessments (e.g., NIST CSF) to identify gaps and inform strategic investment decisions
Compliance Program Leadership
- Provide oversight of global regulatory and contractual compliance programs (e.g., SOX, PCI, GDPR, ISO), ensuring consistency and scalability
- Build and operationalize a "compliance-as-a-service" model that enables self-service, automates evidence collection, and minimizes burden on engineering teams
- Monitor and anticipate changes in the regulatory landscape, proactively positioning Disney to meet evolving requirements
Organizational Leadership
- Lead, develop, and scale a high-performing global GRC organization, fostering a culture of accountability, innovation, and continuous improvement
- Drive organizational excellence through strong leadership, talent development, and a focus on delivering scalable, forward-looking solutions
What You'll Bring
Must-Have Qualifications
- You will have 12+ years of progressive experience in cybersecurity, technology risk, or compliance, including 3+ years leading enterprise-scale GRC functions
- You will bring structured problem-solving, audit rigor, and enterprise advisory experience
- You will have industry experience within large, complex organizations, with the ability to operate effectively in highly matrixed environments
- You will have a proven track record of transforming GRC programs into risk-driven operating models that influence enterprise decision-making
- You will have deep expertise across risk management, governance, and compliance, including frameworks, policy lifecycle, automation, audit, and controls assurance)
- You will have strong working knowledge of industry frameworks and regulations, including NIST CSF, NIST 800-53, ISO 27001, PCI DSS 4.0, SOX ITGC, and GDPR
- You will have demonstrated executive presence and exceptional influence skills, with the ability to operate as a trusted advisor to senior leadership and translate complex technical risk into clear business insights
- You will have experience applying financial risk quantification methodologies (e.g., FAIR) to support investment and prioritization decisions
- You will have a strong customer-focused mindset, ensuring GRC solutions enable the business and enhance—not hinder—user and product experiences
- You will have experience leading in highly matrixed, global environments, driving alignment across engineering, security, and business stakeholders
Leadership & Transformation Profile (Critical for Success)
- You will have a mindset of a thought partner—not just an operator—bringing a strategic, forward-looking perspective to GRC
- You will have a track record of asking hard questions, challenging legacy ways of working, and driving meaningful change across organizations
- You will have the ability to connect cost, customer experience, and operational efficiency into a cohesive, risk-informed strategy
- You will have demonstrated success leading large-scale transformation initiatives, influencing without authority, and driving adoption across complex organizations
Technical Expertise
- You will have advanced expertise in audit methodologies, controls testing, and assurance processes, including ITGCs and automated control environments (must have qualification)
- You will have hands-on experience with leading GRC platforms (e.g., Archer, ServiceNow GRC, SailPoint)
- You will have a strong understanding of cloud security and compliance across AWS, Azure, and GCP environments
- You will have familiarity with DevSecOps practices and integrating security and governance into software development and infrastructure pipelines
Nice-to-Have Qualifications
- You may have experience within media, entertainment, or similarly complex, consumer-facing industries
- You may have experience from a Big 4 consulting firm.
- You may have experience advancing emerging risk domains such as AI/ML governance, third-party risk, or next-generation compliance capabilities
Education
- You will have a bachelor's degree in computer science, information security, or a related field—or equivalent practical experience
- You may have advanced degrees or relevant certifications (e.g., CISSP, CISM, CRISC)
The hiring range for this position in Orlando, FL is $197,500 to $265,000 per year and in Glendale,CA is $207,400 to $278,200 per year. The hiring range for this position in Seattle, WA is $217,300 to $291,500 per year and in New York, NY is $217,300 to $291,500 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate's geographic region, job-related knowledge, skills, and experience among other factors. A bonus and/or long-term incentive units may be provided as
- ...Executive Director, Info Security At Disney, we're storytellers. We make the impossible, possible. The Walt Disney Company... ...innovation and imagination fuel everything we do. The InfoSec Governance, Risk & Compliance (GRC) team is not just a guardian of standards - we...SuggestedShift work
- The Walt Disney Company is seeking an Executive Director of Info Security, overseeing the InfoSec Governance, Risk & Compliance team. This role drives the evolution of security practices and policies, while ensuring compliance with various standards. Candidates should have...Suggested
- ...Senior Vice President, Legal and Chief Compliance Officer (CCO) About the Company... ...directly impacts organizational strategy, governance, and risk posture. The successful candidate will... ...focus on scaling and development. This executive position requires a candidate with...Suggested
$131k - $150k
...Executive Director, Asia Society Southern California Los Angeles - CA Overview Salary Range $131,000.00 - $150,000.00 Salary/year... ...thought leadership in policy, the arts, education as well as in governance and philanthropy. Asia Society is committed to creating a...SuggestedFull timeSummer workShift work- Job Description Womenswear Boho Fashion Brand CEO / COO / MD job opening or private equity investment and business turnaround opportunity remote based near Los Angeles. We are looking for experienced individuals or firms with a proven track record of turning around...SuggestedRemote work
- ...confidence to reach your potential by taking risks, thinking boldly, and responding to the... ...excellence of the organization. This executive position is responsible for integrating... ...revenue enhancement while maintaining compliance with regulatory standards. Ultimately, this...
- ...day‑to‑day operations of the company while acting as a strategic partner to the Founder, ensuring that vision is translated into execution, systems are running smoothly, and teams can focus on creating culture rather than firefighting logistics. You will coordinate...Full time
- ...instrumental in optimizing the time, focus, decision-making, and execution of the Senior Leadership Team. The Chief of Staff will be a... ...fully remote and requires a proactive individual who can surface risks and close gaps effectively. Hiring Manager Title Chief Executive...Remote work
- ...particularly in the areas of time management, decision-making, and execution. The successful candidate will be a trusted partner, gatekeeper... ...lead high-impact special projects, and a proactive approach to risk management are essential. Hiring Manager Title CEO...
- ...communication and alignment across teams, managing and optimizing operational tools, and ensuring the successful execution of projects by identifying resource gaps, timeline risks, and competing priorities. Applicants for the Chief of Staff position at the company should have a...Remote work
- Minimed is hiring a Director of Executive Compensation based in Los Angeles, CA, to design and govern executive pay strategies aligning with shareholder interests. The role... ...conducting market analyses and ensuring compliance with SEC regulations. With a minimum of 10 years...
- ...Officer (COO) to lead their operations. LM Hurley & Associates Executive Search has been retained to identify the new COO. About... ...Ensuring the highest resident care standards and regulations compliance. Community Engagement: Building strong relationships with residents...Relocation package
$100k - $150k
A nonprofit educational organization in Los Angeles seeks a Chief of Staff for Fundraising. The ideal candidate will excel in project management and have over 5 years of experience in similar roles. Key responsibilities include liaising with fundraising teams, managing ...- ...Executive Vice President, Employee Benefits Sales & Market Growth About the Company Leading provider of insurance & risk management services Industry Insurance Type Public Company Founded 1927 Employees 10,001+ Categories Insurance Risk...Local area
- ...Area Executive Vice President, Los Angeles Market Leader At Gallagher Benefit Services, you're a trusted partner to organizations... ...to being submitted for approval, to ensure required profit and compliance requirements are met. With Producers, participates on sales...Full timeWork at officeLocal areaFlexible hours
- A non-profit organization in Los Angeles is seeking a dedicated Executive Assistant to support the CEO and other executives. The role involves managing calendars, providing administrative support, and coordinating meetings for senior leadership. Candidates should have at...Full timeWork at office
- ...Board Member, Nonprofit Governance About the Company Mission-driven organization producing... ...individuals to join its Board of Directors. Board Members play a pivotal role in... ...align with its goals. Legal and ethical compliance is a key aspect of the role, and Board...
- ...Board Member, Nonprofit Governance & Strategic Leadership About the Company Mission... ...dedicated individuals to join its Board of Directors. Board Members play a crucial role in... ..., and ensuring legal and ethical compliance. Candidates for the Board should have a...
- ...Board Member, Nonprofit Governance & Strategic Leadership About the Company Mission... ...dedicated individuals to join its Board of Directors. Board Members will be instrumental in... ..., and ensuring legal and ethical compliance. Travel Percent Less than 10% Functions...
- ...Executive Director About the Company Well-regarded commercial airport Industry Airlines/Aviation Type Non Profit Founded... ...staff, and represent the airport at various industry and government meetings. Hiring Manager Title Chief Executive Officer...
- ...Board Member, Nonprofit Governance & Strategic Leadership About the Company Well-known... ...individuals to join its Board of Directors. Board Members play a crucial role in guiding... ..., and ensuring legal and ethical compliance. Candidates for the Board of Directors...
- ...Board Member, Nonprofit Governance About the Company Well-known child care resource... ...dedicated individuals to join its Board of Directors. Board Members play a pivotal role in... ...planning, and ensure legal and ethical compliance. The ideal candidate for the Board...
- ...Member, Finance, Legal & Governance About the Company Mission... ...of financial oversight, risk assessment, and compliance. This includes providing... ...will have a senior executive background in finance, law... ...Functions ~ Board of Directors (non-operating) ConfidentialRemote work
- .... This is a volunteer, unpaid role. Our most immediate needs are in Technology and Innovation , Impact Investing and Governance and Compliance , but we are also looking for individuals with expertise in: Media & Storytelling Public Relations Ad Sales...Immediate startRemote workFlexible hours
$245k - $275k
NCAA is seeking an Executive Senior Associate Athletic Director, Administration & Risk in Los Angeles, California. This role will oversee the Human Resources, compliance, risk management, and legal operations related to college athletics. The ideal candidate will have...Full time- ...reflect the communities we serve. Ensure governance decisions, resource allocations, and... .... Partner with and advise the Executive Director on key initiatives and organizational... ...outcomes. Financial Stewardship and Compliance Ensure strong financial...Local areaRemote work
$160k - $180k
...Officer to act as a key partner to executive leadership and drive the... ...growth and scalability Ensure compliance with applicable regulations, internal controls, and risk management policies Oversee... ...state and local laws governing non-discrimination in employment...Local area- ...compassion and accountability. Specific duties include leading program operations, partnering with the executive team to drive a unified vision, maintaining compliance with regulatory standards, and collaborating with the CFO on budget management. The ideal candidate...
- ...care capitation value-based care healthcare policy risk contracting risk-based care population health macra... ...excellent communication abilities to engage with the Board of Directors and other stakeholders. The role demands a self-starter who is...
- ...seeking a Chief Operating Officer (COO) to serve as the operational leader and drive the company's performance in partnership with the executive team and board. The COO will be responsible for overseeing branch operations, ensuring high-quality service delivery, and meeting...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Executive Director, InfoSec Governance, Risk, and Compliance. Be the first to apply!
- college president Glendale, CA
- chief dental officer Glendale, CA
- store executive Glendale, CA
- assisted living executive director Glendale, CA
- executive director Glendale, CA
- chief industries Glendale, CA
- information technology executive Glendale, CA
- chief Glendale, CA
- chief executive officer Glendale, CA
- chief executive officer ceo Glendale, CA



