Executive Director, InfoSec Governance, Risk, and Compliance
Core
Lead the transformation of Disney's InfoSec Governance, Risk, and Compliance (GRC) program from a compliance-centric model to a dynamic, risk-intelligence-led capability that informs enterprise investment and prioritization decisions.
Role type
Executive Director, InfoSec GRC
Builds
Enterprise risk management frameworks, automated compliance programs, and strategic risk reporting for executive leadership and the Board.
Domain
Information Security, Enterprise Risk Management, Regulatory Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Enterprise-scale GRC leadership, risk quantification (FAIR), policy lifecycle management, audit methodologies, controls testing, regulatory compliance (SOX, PCI, GDPR, ISO), cloud security (AWS, Azure, GCP), DevSecOps integration, financial risk modeling, executive advisory, organizational transformation.
Preferred skills
Experience in media/entertainment industry, Big 4 consulting background, emerging risk domains (AI/ML governance, third-party risk).
Technologies
Archer, ServiceNow GRC, SailPoint, NIST CSF, NIST 800-53, ISO 27001, PCI DSS 4.0, SOX ITGC, GDPR, AWS, Azure, GCP.
Responsibilities
Drive the evolution of GRC to a risk-intelligence-led model; define and elevate GRC standards with innovative risk quantification; partner with GIS and business leadership to embed risk awareness; lead the design and improvement of the enterprise InfoSec Risk Management Framework; oversee the full lifecycle of InfoSec policies and standards; provide oversight of global regulatory compliance programs; lead, develop, and scale a high-performing global GRC organization.
Seniority
Executive Director, strategic leadership & transformation