Security Specialist

Disney Disney · Media · Burbank, CA +4

This role is for a Security Specialist at Disney, focusing on IT audit support, control health checks, remediation testing, and risk assessment within the Global Information Security (GIS) organization. The primary responsibilities include supporting SOX 404 ITGC, PII, PCI, and ISPS audits, performing control testing, participating in audit walkthroughs, and providing requirements input for automation. The role requires a strong understanding of IT audit and compliance functions, particularly SOX ITGC and ICFR 404 standards.

What you'd actually do

  1. Independent audit support for: SOX 404 ITGC, PII, PCI, ISPS
  2. Perform control health checks and remediation testing procedures to address issues identified via audit assessments, internal or external audits, and/or other assessments.
  3. Participate in audit walkthrough meetings to gain operational comfort in the design of the Company’s automated controls.
  4. Perform impact analysis and risk assessment on deficiency findings and documentation associated with the assessment
  5. Perform control finding investigation and record in internal SOCD/SAD

Skills

Required

  • Minimum of 3 years of IT SOX experience and proven experience in supporting IT audit/compliance functions
  • Thorough understanding of SOX ITGC and ICFR 404 standards and audit objectives
  • Interpersonal skills with the ability to work with teams cross-functionally
  • Strong verbal and written communication skills
  • Ability to effectively communicate to technical and non-technical audiences
  • Highly organized and efficient
  • Ability to navigate through ambiguity, manage and coordinate multiple project assignments simultaneously in a fast-paced, deadline-driven environment, accepting ownership and accountability of the process and deliver on commitments

Nice to have

  • Experience and knowledge of NIST framework, ISO 27001, K-ISMS, GDPR
  • Experience working with companies that have a heavy microservice architecture

What the JD emphasized

  • SOX 404 ITGC
  • PII
  • PCI
  • ISPS
  • SOX 404
  • ITGC
  • ICFR 404