Manager - Information Security

Disney Disney · Media · Singapore

Manager for Information Security at Disney, focusing on expanding and maturing ISO services and programs across Southeast Asia, Australia, and India. Responsibilities include security baselining, monitoring, risk management, vendor risk, security training, and ensuring compliance with corporate policies and regulations. The role requires partnership with business and IT teams to integrate security into existing processes and provide visibility into regional risks. Requires a strong understanding of security best practices, regulatory frameworks (ISO, PCI, privacy regulations), cloud security, and risk assessment methodologies.

What you'd actually do

  1. Manage expansion and maturity of the following Disney Entertainment (DE) Information Security Office (ISO) services & programs within countries that include the South East Asia (e.g., Singapore, Indonesia, Thailand, Philippines), Australia, and India.
  2. Security baseline and monitoring of business-critical products
  3. Pervasive risk monitoring and reporting
  4. Security champions program
  5. Vendor risk management

Skills

Required

  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or comparable field of study, and / or equivalent work experience
  • At least 7 years of experience in Information Technology
  • At least 5 years of experience in Risk Management, Information Security, or Audit & Compliance
  • At least 3 years of leadership experience, including team management and oversight of direct reports.
  • Hands-on experience with regulatory security frameworks, including ISO standards
  • Experience of interpreting and assessing risk based on information from numerous sources to form practical and operational realistic solutions
  • Working knowledge of information security related best practices and standards such as ISO 2700x, SOC 2, NIST, PCI requirements etc.
  • Working knowledge of cloud infrastructure and security principles
  • Knowledge of conducting risk assessments using industry recognized risk management methodologies

Nice to have

  • Progress toward one or more industry-recognized certifications (e.g., CISA, CISM, CRISC, ISO 27001, CCSP, CISSP, Security+)
  • Master’s degree in computer science, information security, or a related technology discipline
  • Proficient understanding of security and vulnerabil

What the JD emphasized

  • Hands-on experience with regulatory security frameworks, including ISO standards
  • Working knowledge of information security related best practices and standards such as ISO 2700x, SOC 2, NIST, PCI requirements etc.
  • Ensure programs are in compliance with corporate policies and standards, and other applicable laws & regulations.