Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Executive Director, InfoSec Governance, Risk, and Compliance

$217.3k - $291.5k

Disney Consumer Products

Executive Director, InfoSec Governance, Risk, and Compliance

At Disney, we're storytellers. We make the impossible, possible. The Walt Disney Company (TWDC) is a world-class entertainment and technological leader. Walt's passion was to continuously envision new ways to move audiences around the world—a passion that remains our touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, news, movies and a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences—and we're constantly looking for new ways to enhance these exciting experiences.

The Enterprise Technology mission is to deliver technology solutions that align to business strategies while enabling enterprise efficiency and promoting cross-company collaborative innovation. Our group drives competitive advantage by enhancing our consumer experiences, enabling business growth, and advancing operational excellence.

The Global Information Security (GIS) group provides services to protect the value and use of Disney's information through collaboration, standardization, enforcement, and education across The Walt Disney Company. The main focus areas of this group are: Reduce the risk of both accidental and malicious data disclosure; Identify, monitor, engage with complete inventory of information; Establish appropriate policies and procedures to be followed; Educate user community to minimize risk.

Disney's InfoSec GRC team is seeking a transformational leader to drive the next evolution of Governance, Risk, and Compliance across the enterprise. Reporting to the VP of Information Security, this role will lead the shift from a traditional compliance-driven approach to a modern, risk-intelligence-led model that enables better business decisions, strengthens security posture, and scales with Disney's global technology and content ecosystem. This leader will partner closely with GIS and business leadership to embed risk awareness into daily operations, ensuring GRC is a strategic enabler of innovation—not a barrier.

What You'll Do

  • Transform GRC at Disney
  • Define and elevate GRC standards by introducing innovative approaches to risk quantification, compliance automation, and integrated governance
  • Partner with GIS and segment technology leadership to position GRC as a strategic business enabler, translating complex risks into actionable, executive-ready insights
  • Champion a culture where risk awareness is embedded into daily decision-making, enabling intuitive and scalable risk-informed behaviors across the enterprise

Risk Management Leadership

  • Lead the design, implementation, and continuous improvement of Disney's enterprise InfoSec Risk Management Framework
  • Establish and operationalize risk tolerance models, translating business objectives into clear prioritization, investment, and remediation decisions
  • Build and mature a centralized cybersecurity risk register integrating threat intelligence, vulnerabilities, and third-party risk data
  • Drive risk-based prioritization across InfoSec functions to ensure measurable risk reduction and alignment to enterprise objectives
  • Deliver clear, credible, and decision-ready risk reporting to executive leadership and the Board, including financial risk quantification (e.g., FAIR)

Governance Program Leadership

  • Oversee the full lifecycle of InfoSec policies, standards, and guidelines, ensuring they are risk-based, actionable, and aligned with business needs
  • Embed governance controls into the technology lifecycle (e.g., DevSecOps, cloud, infrastructure-as-code), reducing reliance on manual processes through automation
  • Establish a policy effectiveness framework focused on behavioral change and measurable risk reduction
  • Define and advance governance strategies for emerging technologies, including AI/ML, quantum security, and autonomous systems
  • Lead enterprise maturity assessments (e.g., NIST CSF) to identify gaps and inform strategic investment decisions

Compliance Program Leadership

  • Provide oversight of global regulatory and contractual compliance programs (e.g., SOX, PCI, GDPR, ISO), ensuring consistency and scalability
  • Build and operationalize a "compliance-as-a-service" model that enables self-service, automates evidence collection, and minimizes burden on engineering teams
  • Monitor and anticipate changes in the regulatory landscape, proactively positioning Disney to meet evolving requirements

Organizational Leadership

  • Lead, develop, and scale a high-performing global GRC organization, fostering a culture of accountability, innovation, and continuous improvement
  • Drive organizational excellence through strong leadership, talent development, and a focus on delivering scalable, forward-looking solutions

What You'll Bring

Must-Have Qualifications

  • 12+ years of progressive experience in cybersecurity, technology risk, or compliance, including 3+ years leading enterprise-scale GRC functions
  • Structured problem-solving, audit rigor, and enterprise advisory experience
  • Industry experience within large, complex organizations, with the ability to operate effectively in highly matrixed environments
  • Proven track record of transforming GRC programs into risk-driven operating models that influence enterprise decision-making
  • Deep expertise across risk management, governance, and compliance, including frameworks, policy lifecycle, automation, audit, and controls assurance
  • Strong working knowledge of industry frameworks and regulations, including NIST CSF, NIST 800-53, ISO 27001, PCI DSS 4.0, SOX ITGC, and GDPR
  • Demonstrated executive presence and exceptional influence skills, with the ability to operate as a trusted advisor to senior leadership and translate complex technical risk into clear business insights
  • Experience applying financial risk quantification methodologies (e.g., FAIR) to support investment and prioritization decisions
  • Strong customer-focused mindset, ensuring GRC solutions enable the business and enhance—not hinder—user and product experiences
  • Experience leading in highly matrixed, global environments, driving alignment across engineering, security, and business stakeholders

Leadership & Transformation Profile (Critical for Success)

  • Mindset of a thought partner—not just an operator—bringing a strategic, forward-looking perspective to GRC
  • Track record of asking hard questions, challenging legacy ways of working, and driving meaningful change across organizations
  • Ability to connect cost, customer experience, and operational efficiency into a cohesive, risk-informed strategy
  • Demonstrated success leading large-scale transformation initiatives, influencing without authority, and driving adoption across complex organizations

Technical Expertise

  • Advanced expertise in audit methodologies, controls testing, and assurance processes, including ITGCs and automated control environments
  • Hands-on experience with leading GRC platforms (e.g., Archer, ServiceNow GRC, SailPoint)
  • Strong understanding of cloud security and compliance across AWS, Azure, and GCP environments
  • Familiarity with DevSecOps practices and integrating security and governance into software development and infrastructure pipelines

Nice-to-Have Qualifications

  • Experience within media, entertainment, or similarly complex, consumer-facing industries
  • Experience from a Big 4 consulting firm
  • Experience advancing emerging risk domains such as AI/ML governance, third-party risk, or next-generation compliance capabilities

Education

  • Bachelor's degree in computer science, information security, or a related field—or equivalent practical experience
  • Advanced degrees or relevant certifications (e.g., CISSP, CISM, CRISC)

The hiring range for this position in Seattle, WA is $217,300 to $291,500 per year and in New York, NY is $217,300 to $291,500 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate's geographic region, job-related knowledge, skills, and experience among other factors. A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Executive Director, InfoSec Governance, Risk, and Compliance in Glendale, CA vacancy
  •  ..., the COO oversees financial stability, risk management, and corporate sustainability...  ...Board's vision and ensuring regulatory compliance. Help Us Get to Know You A bachelor...  ...with members, co-workers, the Board of Directors, management, business partners, and the... 
    Suggested
    Work at office

    Humanidei

    Glendale, CA
    4 days ago
  •  ...Develop cost‑effective solutions to optimize profits while balancing risks and growth opportunities. Lead the sales and operations...  ...and manage monthly reviews with cross‑functional teams. Governance Responsibilities: Manage the budget for all operational areas... 
    Suggested

    Jobleads-US

    Glendale, CA
    3 days ago
  • Job Description Womenswear Boho Fashion Brand CEO / COO / MD job opening or private equity investment and business turnaround opportunity remote based near Los Angeles. We are looking for experienced individuals or firms with a proven track record of turning around...
    Suggested
    Remote work

    BluZinc

    Los Angeles, CA
    1 day ago
  •  ...s sales and service culture, and ensuring financial stability, risk management, and corporate sustainability. Candidates for the COO...  ...also be expected to have a strong understanding of regulatory compliance, including the Bank Secrecy Act and other relevant federal laws... 
    Suggested

    Confidential

    Glendale, CA
    6 days ago
  • $240k - $275k

    The Executive Senior Associate Athletic Director, Administration & Risk will serve as the primary liaison between USC's Athletic Department and University Human Resources...  ...General Counsel (OGC) and Office of Athletics Compliance (OAC). Reporting to the Director of Athletics... 
    Suggested
    Contract work
    Work experience placement
    Work at office
    Weekend work
    Afternoon shift

    University of Southern California

    Glendale, CA
    3 days ago
  • $240k - $275k

    The University of Southern California is seeking an Executive Senior Associate Athletic Director to manage human resources, compliance, and risk management for athletics. The role requires strong leadership and legal skills, along with eight years of HR experience. The... 

    University of Southern California

    Glendale, CA
    3 days ago
  • USA-Medtronic MiniMed, Inc 1017 in Los Angeles is looking for a Director of Executive Compensation to lead the design, administration, and governance of executive compensation programs. This hybrid role involves advising top executives and ensuring alignment with shareholder... 

    USA-Medtronic MiniMed, Inc 1017

    Los Angeles, CA
    5 days ago
  •  ...About the Role The Company is in search of a Chief of Staff with a focus on strategy and operations to join their team. This executive leadership role is pivotal in driving the company's strategy, enhancing operational execution, and ensuring the alignment and efficiency... 

    Confidential

    Los Angeles, CA
    6 days ago
  •  ...instrumental in optimizing the time, focus, decision-making, and execution of the Senior Leadership Team. The Chief of Staff will be a...  ...fully remote and requires a proactive individual who can surface risks and close gaps effectively. Hiring Manager Title Chief Executive... 
    Remote work

    Confidential

    Los Angeles, CA
    6 days ago
  •  ...particularly in the areas of time management, decision-making, and execution. The successful candidate will be a trusted partner, gatekeeper...  ...lead high-impact special projects, and a proactive approach to risk management are essential. Hiring Manager Title CEO... 

    Confidential

    Los Angeles, CA
    2 days ago
  •  ...day‑to‑day operations of the company while acting as a strategic partner to the Founder, ensuring that vision is translated into execution, systems are running smoothly, and teams can focus on creating culture rather than firefighting logistics. You will coordinate between... 
    Full time

    TEEMA Solutions Group

    Beverly Hills, CA
    2 days ago
  •  ...communication and alignment across teams, managing and optimizing operational tools, and ensuring the successful execution of projects by identifying resource gaps, timeline risks, and competing priorities. Applicants for the Chief of Staff position at the company should have a... 
    Remote work

    Confidential

    Los Angeles, CA
    2 days ago
  •  ...About the Role The Company is in search of a Chief of Staff with a focus on strategy and operations to join their team. This executive leadership role is pivotal in driving the company's strategy, enhancing operational execution, and ensuring the alignment and efficiency... 

    Confidential

    Los Angeles, CA
    6 days ago
  •  ...are met - Ensure effective recruiting, onboarding, professional development, performance management, and retention - Ensure compliance with national and local business regulations, and take appropriate action when necessary Responsibilities - Analyse internal... 
    Temporary work
    Local area

    DHD Consulting

    Los Angeles, CA
    4 days ago
  •  ...reflect the communities we serve. Ensure governance decisions, resource allocations, and...  .... Partner with and advise the Executive Director on key initiatives and organizational...  ...outcomes. Financial Stewardship and Compliance Ensure strong financial... 
    Local area
    Remote work

    Aspire Public Schools

    Los Angeles, CA
    4 days ago
  •  ...You'll partner directly with leaders across operations, billing, and technology to improve systems, document processes, and drive execution on high-impact initiatives that support growth across new and existing states. Responsibilities Serve as a power user of Microsoft... 
    Work at office

    Comprehensive Mobile Care

    Glendale, CA
    9 days ago
  •  ...Position The Chief Operating Officer (COO) is a key member of the executive leadership team and is responsible for translating the CEO’s...  ...depreciation strategies, RPO programs, and regulatory/safety compliance. Leadership Capability: Proven success leading... 

    Kimmel & Associates

    Los Angeles, CA
    4 days ago
  • $400k

     ...construction company is seeking a Senior Vice President to provide executive leadership and operational oversight. This role will be...  ...Expertise in construction methodologies, contract negotiations, and risk management. Strong financial acumen, with experience... 
    Contract work
    For contractors
    For subcontractor
    Relocation package

    Blue Ridge Executive Search

    Los Angeles, CA
    1 day ago
  •  ...not a maintenance role. The COO will serve as the CEO’s closest strategic partner — translating creative ambition into disciplined execution across operations, people, finance, marketing, production, technology, construction, and guest experience. We need someone who... 
    Local area

    MUSEUM OF ICE CREAM

    Los Angeles, CA
    2 days ago
  •  ...The incumbent leads the development and execution of strategic plans to ensure the organization...  ...opportunities, and assess potential risks. • Lead the strategic planning process...  ...impacting healthcare. • Ensures compliance with regulatory requirements and industry... 

    AHMC Healthcare

    Alhambra, CA
    2 days ago
  • $175k - $300k

    Position Title: Chief Operating Officer The Chief Operating Officer will lead the team, develop strategic plans, and ensure that all departments function effectively. The position requires a deep understanding of the legal industry, as well as financial acumen to manage...
    Temporary work

    Boutique Recruiting

    Los Angeles, CA
    4 days ago
  • $110k - $130k

     ...organizational effectiveness, supervise Directors, ensure that we produce outcomes...  ...and small business support. ● Ensure compliance with all legal, regulatory, and funder...  ...relationships with community stakeholders, government agencies, funders, and local organizations... 
    Temporary work
    Apprenticeship
    Work at office
    Local area
    Work from home
    Flexible hours

    COMMUNITY DEVELOPMENT TECHNOLO

    Los Angeles, CA
    3 days ago
  •  ...optimizing efficiency and quality to ensure a seamless customer journey from order to service. Growth Strategy: Collaborate with the executive team to develop and execute strategic plans for rapid expansion while maintaining brand integrity. Culinary Innovation: Work... 
    Casual work

    Leap Brands

    Los Angeles, CA
    3 days ago
  • $150k - $200k

     ...operational expansion that requires stronger systems, tighter execution, and constant accountability across all teams. The Managing Partner...  ...Managing Partner. The COO will oversee finance, HR, staffing, compliance, technology, marketing, intake, and workflow management,... 
    Shift work

    JBA International

    Los Angeles, CA
    4 days ago
  •  ...Member, Finance, Legal & Governance About the Company Mission...  ...of financial oversight, risk assessment, and compliance. This includes providing...  ...candidate will have a senior executive background in finance,...  ...Less than 10% Functions Board of Directors (non-operating)... 
    Remote work

    Confidential

    Los Angeles, CA
    5 days ago
  •  ...Board Member, Nonprofit Governance About the Company Mission-driven organization producing...  ...individuals to join its Board of Directors. Board Members play a pivotal role in providing...  ...with its goals. Legal and ethical compliance is a key aspect of the role, and Board... 

    Confidential

    Los Angeles, CA
    3 days ago
  •  ...candidates will have 7-12+ years in operations or senior administrative roles, strong judgment, and an ability to balance strategic thinking with frontline execution. Join Lemonaid Health in improving healthcare access across the nation. #J-18808-Ljbffr Lemonaid Health

    Lemonaid Health

    Los Angeles, CA
    1 day ago
  •  ...Executive Vice President, Annuity Solutions About the Company Globally renowned reinsurance company Industry Insurance Type Privately Held...  ...the oversight of in-force profitability, financial reporting, risk analysis, experience studies, and client relationship... 

    Confidential

    Los Angeles, CA
    5 days ago
  •  ...Executive Vice President of Business Development About the Company Dynamic, innovative company helping the life sciences sector accelerate growth and business success. Industry Biotechnology Type Privately Held About the Role The Company is in search of an Executive Vice... 

    Confidential

    Los Angeles, CA
    5 days ago
  •  ...Business Development Executive You are customer focused, passionate about working...  ...business, with a keen eye towards risk mitigation and compliance Lead the new business origination...  ...prominent corporate, institutional and government clients under the J.P. Morgan and... 
    Local area

    Chase

    Los Angeles, CA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Executive Director, InfoSec Governance, Risk, and Compliance. Be the first to apply!