Executive Director, InfoSec Governance, Risk, and Compliance

The Walt Disney Company

Remote

Quick summary

Work type
Remote
Location
Seattle, WA · Orlando, FL · New York, NY · Glendale, CA
Salary
$197,500–$265,000 / yr
Posted
5 days ago

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $177k
This role $231k
$115k most similar roles pay here $281k

This role pays more than 85% of similar roles. Most pay $142,450–$211,200 — the shaded band above. At the midpoint, this role pays about $231k versus about $177k for comparable roles.

Based on 238 similar postings.

Employer

About The Walt Disney Company

The Walt Disney Company is a diversified global entertainment and media enterprise operating in segments including Disney Parks, Experiences and Products; Entertainment (ABC, Hulu, Disney+); and ESPN. Industry: Entertainment & Media

The Walt Disney Company currently has 62 open roles on FindRole.

Listed pay typically runs $146,850–$196,900 across 58 roles with salary data.

Most-posted roles

View all roles at The Walt Disney Company

At a glance

TL;DR · Executive Director, InfoSec Governance, Risk, and Compliance

The Executive Director of Info Security at Disney leads the Global Information Security (GIS) Governance, Risk & Compliance (GRC) team, a strategic powerhouse driving the evolution of information security beyond mere compliance to risk intelligence and automation. This executive role involves transforming GRC into a dynamic, business-aligned function by developing novel approaches to risk quantification and governance integration, ensuring that every decision is informed by robust risk analysis. Key responsibilities include overseeing comprehensive InfoSec Risk Management programs, establishing risk tolerance frameworks, and leading the development of enterprise-wide security policies and standards. The ideal candidate has over 12 years of experience in cybersecurity with a focus on GRC at an enterprise level, expertise in NIST CSF, ISO/IEC 27001, and other critical frameworks, and hands-on familiarity with GRC tooling such as Archer or ServiceNow GRC. Additionally, the role demands strong leadership skills to inspire a high-performing team of around 40 professionals while navigating the unique regulatory landscape of a global entertainment brand.

What you'll do

  • Drive the continuous evolution of Disney’s InfoSec GRC program to a risk-intelligence-led model.
  • Define and advance industry standards for risk quantification and compliance automation.
  • Oversee development and operationalization of comprehensive InfoSec Risk Management Frameworks.
  • Lead the creation of executive-level risk reporting that translates complex risk landscapes into actionable insights.
  • Develop and maintain enterprise-wide Information Security policies aligned with business realities, not just regulatory checklists.

What we're looking for

  • 12+ years of experience in cybersecurity with at least 3 years in leadership roles overseeing GRC functions.
  • Deep expertise in risk management, governance, and compliance across various security frameworks.
  • Proven track record of building and transforming GRC programs to risk-driven models.
  • Strong executive presence and ability to translate technical concepts into clear business language.
  • Expert-level knowledge in implementing and operating GRC tooling platforms.
  • Required certifications: CISSP, CISM, CISA, or CRISC.

More like this

Similar roles

Director, Information Security Officer

Capital One Financial

McLean, VA 25 days ago $269,100$307,200
AWS Azure GCP DevOps CI/CD Kubernetes Docker Microservices Serverless APIs Encryption Zero Trust NIST CSF FFIEC CAT CIS RAM PCI DSS Generative AI Data Lakes Cloud Services Containers

Director, IT Security Operations

University of Miami

Miami, FL 58 days ago
SIEM MDR CISSP CISM Security+ Certified Ethical Hacker Cloud Security certification ISO27000 COBIT NIST 800 Cybersecurity Incident Response Network and security architecture Regulatory compliance

Sr. Red Team Specialist

Cboe Global Markets

Chicago, IL 2 days ago $121,550$157,300
Python PowerShell Bash MITRE ATT&CK EDR SIEM Cloud Security Controls TTPs Endpoint Detection Identity Protection Network Security Application Security Threat Intelligence CI/CD
Hybrid

Senior Lead Information Security Office Consultant

Capital One Financial

Plano, TX 39 days ago $229,900$262,400
AWS Azure GCP Cloud Security Engineering CI/CD Agile Methodologies Threat Modeling Penetration Testing Vulnerability Management SaaS Integration Container Services Splunk PostgreSQL Python Kubernetes Terraform

Senior Lead Information Security Office Consultant

Capital One Financial

McLean, VA 29 days ago $229,900$262,400
AWS Azure GCP Cloud Security Engineering Public Cloud Environment Agile Methodologies Software Security Architecture Application Security Threat Modeling Penetration Testing Vulnerability Management SaaS Integration Container Services Splunk CI/CD

Senior Lead Information Security Office Consultant

Capital One Financial

McLean, VA 22 days ago $229,900$262,400
AWS Azure GCP DevSecOps CI/CD ISO 27001 ITIL COBIT PCI DSS GDPR NIST Cyber Security Framework CISSP CISM CISA Threat Modeling SaaS Integration Container Services Cloud Security Engineering