Executive Director, Info Security

Disney Disney · Media · Seattle, WA +5

Executive Director, Info Security role focused on transforming the GRC program at Disney. This role will drive the evolution of the InfoSec GRC program from a compliance-centric model to a dynamic, risk-intelligence-led model. Responsibilities include overseeing risk management, developing risk tolerance frameworks, managing the cybersecurity risk register, and leading governance program development including policies and standards. The role emphasizes risk quantification, automated policy enforcement, and integrating governance into the technology lifecycle.

What you'd actually do

  1. Drive continous evolution of Disney’s InfoSec GRC program, replacing compliance-centric, checkbox-driven operations with a dynamic, risk-intelligence-led model that directly informs how Disney prioritizes investment, staffing, and remediation.
  2. Define what “great” looks like, not by referencing existing standards but by advancing them. Develop novel approaches to risk quantification, compliance automation, and governance integration.
  3. Partner with GIS Leadership and Segment CTO teams to ensure the GRC program functions as a strategic business enabler, translating complex risk landscapes into executive- and board-ready insights that drive confident decision-making.
  4. Champion a culture shift across all of GIS and the broader enterprise: risk awareness is everyone’s job, and GRC’s role is to make risk-informed thinking intuitive, not burdensome.
  5. Oversee the development and ongoing operations of Disney’s comprehensive InfoSec Risk Management program, including the establishment, implementation, and continuous improvement of the enterprise Risk Management Framework.

Skills

Required

  • Information Security
  • GRC (Governance, Risk, and Compliance)
  • Risk Management Frameworks
  • Policy Development
  • Risk Quantification (e.g., FAIR)
  • Third-Party Risk Management
  • Security Governance
  • Leadership
  • Strategic Planning
  • Executive Reporting

Nice to have

  • Experience in regulated industries
  • Automation in GRC
  • DevSecOps integration
  • Cloud Security Governance

What the JD emphasized

  • risk quantification
  • automated policy enforcement
  • risk-based prioritization
  • third-party risk
  • governance integration