Advertisement

Compliance Manager

Sorry, this job was removed at 8:03 a.m. (CST) on Wednesday, November 10, 2021
Find out who's hiring in Los Angeles, CA.
See all Operations jobs in Los Angeles, CA
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Job Summary:The Global Information Security (GIS) group provides services and solutions to protect the value and use of Disney’s information through risk evaluation, collaboration, standardization, enforcement, and education across the enterprise. We protect the brand and reputation while enabling and supporting business objectives.
In order to ensure that our services keep The Walt Disney Company (TWDC) secure, we follow an ongoing, iterative process, including continued reevaluation of our services over time to address emerging threats as well as changes in business and technology. This process includes:

  1. Analysis of known and emerging threats to determine risks against TWDC assets
  2. Creation, maintenance, governance and communication of security policies and standards across TWDC
  3. Assessment and audit of compliance against the security policies and standards
  4. Assurance that TWDC assets are effectively managed and monitored to meet TWDC security criteria

We look add people to our team who are focused on delivery, prioritize data-driven decisions over opinions, are
continuous learners, passionate about information security and love their work.
TWDC Information Security Governance, Risk Management, & Compliance provide organizational structure, processes, and oversight to ensure policies, standards, and management practices meet TWDC’s information security objectives.
TWDC Information Security Compliance run ongoing security programs to evaluate the health of TWDC’s control environment. These programs include external audits, internal control validation, third party assessments, and ongoing consulting.
Responsibilities:Develops and evaluates compliance with programs and processes to mitigate cybersecurity risk and ensure protection of company and allied assets and information. Reviews and enhances network systems and processes for compliance with external regulations and internal standards. Proactively identifies non-conforming areas and assesses risk. Recommends and implements compliance measures. Provides leadership on compliance issues to solve challenging security compliance problems. Ensures documentation and reporting in support of analysis. Stays current on evolving legislative / regulatory changes related to security compliance.
Coordinates with multiple stakeholder groups across TWDC to optimize standards and procedures to assess and monitor information security risks resulting from the use of external service providers.
Responsible for the strategic and operational oversight of third party assessment related initiatives:

  • Third party assessment planning, execution, and reporting
  • Enhanced continuous monitoring of critical vendors
  • Assessment of a variety of third party technology and business process solutions
  • Third party contract review of information security language
  • Review of various key third party compliance artifacts


Provide consulting to internal business partners regarding third party risk and business side responsibility for controls when engaging a third party to deliver business objectives.
Basic Qualifications:

  • 10+ years of IT audit, or IT security and/or compliance experience
  • Prior experience working within a global media or entertainment organization, supporting enterprise security functions
  • Experience working with procurement and legal teams
  • Knowledge of laws, regulations, and industry requirements related to Information Security (i.e. GDPR, Payment Card Industry, Domestic and International Privacy regulations)
  • Knowledge and experience with diverse IT architectures and enterprise IT data centers, hosted services and cloud computing environments
  • Knowledge of configuration management, change control/problem management integration, risk assessment, exception management and security baselines (e.g. COBIT, CIS Baselines, NIST, vendor security technical implementation guides, etc.)
  • Must be a strategic thinker and operator capable of monitoring and commenting on complex business and security matters
  • Must have ability to communicate effectively to all levels of the organization as well as to external stakeholders
  • Must be able to establish credibility as a business partner respected by client-base with proven ability to gain “buy-in” from teams without direct line of authority
  • Ability to develop consensus within an organization climate of diverse operational activities, cultures and geographic locations
  • Project/program management and prioritization skills
  • Financial acumen and experience managing budgets


Preferred Qualifications:

  • External audit (e.g., Big Four) and /or internal audit (e.g., Fortune 500)
  • 5+ years of program and project management experience
  • 5+ years of experience in third party risk management or IT vendor management experience.
  • 5+ years of experience managing budgets and reporting security risks
  • Experience in implementing programs that assess compliance, design, operational effectiveness and resiliency of Third party services within a large international company
  • Experience presenting and influencing C-level executives on IT security and matters
  • Knowledge and experience applying common security frameworks such as MITRE, OWASP, PTES
  • Knowledge of Cloud and Perimeter technologies (e.g., router, firewalls, web proxies and intrusion prevention, etc.) and security tools (i.e. web application scanners, vulnerability scanners, file integrity monitoring, configuration monitoring, etc.)
  • Experience with Security Scorecard or other vendor monitoring assurance service
  • Experience creating and designing data analytics dashboards


Required Education

  • 4-year degree Computer Science, Risk Management, Information Security and/or equivalent professional experience
  • Cert/s such as CISSP, CISA, AWS


Preferred Education

  • Master's degree in computer science or IT Security / IT Audit related field is preferred
  • ISC2 CCSP, SANS, AZURE, GCP other relevant cybersecurity certification
  • Tableau / PowerBI certification


Additional Information:DISNEYTECH
#LI-JH8

Read Full Job Description
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

Technology we use

  • Engineering
    • C++Languages
    • JavascriptLanguages
    • PHPLanguages
    • PythonLanguages
    • ScalaLanguages
    • SqlLanguages
    • SwiftLanguages
    • Backbone.jsFrameworks
    • DjangoFrameworks
    • HadoopFrameworks
    • JSFFrameworks
    • MeteorFrameworks
    • Node.jsFrameworks
    • Ruby on RailsFrameworks

An Insider's view of The Walt Disney Company

How does the company support your career growth?

Over my 13 years with the company, I’ve had passionate leaders and colleagues with diverse backgrounds who have taught me and given me opportunities to expand into areas I never thought possible. You have the freedom to take career risks and apply your previous experience in ways you may not anticipate.

Chase

Product Management Director

What is your vision for the company?

Disney has always been at the heart of the evolution of the media industry, and technology is an essential part of that. The way that we tell and consume stories in the future is going to be completely different than it is today, and The Walt Disney Company is uniquely positioned to shape and create that future.

Jamie

SVP/Chief Technology Officer, The Walt Disney Studios

What are The Walt Disney Company Perks + Benefits

The Walt Disney Company Benefits Overview

Because our employees and cast members are at the heart of everything we do, Disney offers a competitive total rewards package that includes pay, health and savings benefits, time-off programs, educational opportunities and more. Together, these rewards make up a comprehensive package that help you live your best life, grow personally and professionally and take advantage of the special extras that only Disney can provide.

Eligibility for certain reward programs will vary based on your job status, work location and/or the terms of any applicable collective bargaining agreement.

Culture
Volunteer in local community
Partners with nonprofits
Diversity
Dedicated diversity and inclusion staff
Diversity employee resource groups
Hiring practices that promote diversity
Health Insurance & Wellness Benefits
Dental insurance
Vision insurance
Health insurance
Life insurance
Mental health benefits
Financial & Retirement
401(K)
401(K) matching
Charitable contribution matching
Child Care & Parental Leave Benefits
Childcare benefits
Generous parental leave
Vacation & Time Off Benefits
Generous PTO
Paid holidays
Paid sick days

More Jobs at The Walt Disney Company

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about The Walt Disney CompanyFind similar jobs like this