Principal Compliance Analyst
Detalles del empleo:
Technology is at the heart of Disney’s past, present, and future. Disney Entertainment and ESPN Product & Technology is a global organization of engineers, product developers, designers, technologists, data scientists, and more – all working to build and advance the technological backbone for Disney’s media business globally.
The team marries technology with creativity to build world-class products, enhance storytelling, and drive velocity, innovation, and scalability for our businesses. We are Storytellers and Innovators. Creators and Builders. Entertainers and Engineers. We work with every part of The Walt Disney Company’s media portfolio to advance the technological foundation and consumer media touch points serving millions of people around the world.
Here are a few reasons why we think you’d love working here:
Building the future of Disney’s media: Our Technologists are designing and building the products and platforms that will power our media, advertising, and distribution businesses for years to come.
Reach, Scale & Impact: More than ever, Disney’s technology and products serve as a signature doorway for fans' connections with the company’s brands and stories. Disney+. Hulu. ESPN. ABC. ABC News…and many more. These products and brands – and the unmatched stories, storytellers, and events they carry – matter to millions of people globally.
Innovation: We develop and implement groundbreaking products and techniques that shape industry norms, and solve complex and distinctive technical problems.
The Business Operations team helps guide and articulate technology strategy and research, and is responsible for driving the day-to-day operation of the Product & Technology organization, including: project and portfolio management and tracking; organization-level capital, space, and resource management and allocation; process management; technical incident management; and our administrative and workplace experience support team.
Role Summary
P&T is supporting a multi‑year GIS initiative aligned to the NIST Cybersecurity Framework (CSF) to strengthen operational resilience, reduce enterprise risk, and demonstrate measurable security maturity to shareholders, regulators, and external customers.
Achieving meaningful improvement across NIST domains requires coordinated execution across numerous security programs, engineering teams, and operational functions. To ensure success, we are establishing a dedicated NIST Security Program Lead responsible for governing and orchestrating the delivery of all NIST‑aligned initiatives across the enterprise security roadmap.
This role must be filled as a project hire (employee) rather than a contractor due to the sensitivity of the work. The position will have visibility into confidential security architecture, control weaknesses, internal audit findings, risk assessments, and remediation strategies that directly impact the organization's security posture. The NIST Principal Compliance Analyst operates as the central execution authority for the NIST program, ensuring that all framework‑aligned initiatives progress with clear governance, measurable outcomes, and transparent reporting to senior leadership.
Program Philosophy and Operating Model
The NIST program will be executed using a framework‑driven operational model focused on measurable security maturity and transparent governance.
- Framework Alignment – All initiatives must map clearly to NIST CSF domains: Identify, Protect, Detect, Respond, and Recover.
- Measurable Progress – Security improvements must be quantifiable through defined maturity targets and scorecards.
- Transparent Governance – Program progress must be visible to engineering teams, program leaders, and executive stakeholders.
- Cross‑Enterprise Collaboration – The program coordinates across security engineering, infrastructure, application development, and operations teams.
Key Responsibilities – NIST Program Leadership & Governance
- Serve as enterprise program leader responsible for execution of the NIST CSF roadmap.
- Establish the governance model for NIST initiatives including initiative ownership, accountability, and reporting cadence.
- Coordinate program execution across security engineering, infrastructure teams, and application teams.
- Ensure initiatives move from design to deployment to operational maturity.
Workstream Coordination & Delivery Oversight
- IT Asset Management and CMDB maturity
- Zero Trust architecture deployment
- Data Security Posture Management (DSPM)
- Privileged Access Management (PAM) expansion
- Identity and application authentication governance
- Secrets management lifecycle automation
- Consumer protection security controls
- AI security governance and defensive controls
- Insider threat monitoring capabilities
- Vendor risk management processes
- Patch and vulnerability management automation
- Ensure each initiative maintains clear deliverables, milestone tracking, measurable outcomes, and NIST alignment.
Program Scorecards & Security Maturity Measurement
- Execute the P&T work of a GIS driven and designed security maturity measurement framework aligned to NIST CSF.
- Develop standardized scorecards measuring control maturity, implementation coverage, operational adoption, and risk reduction impact in partnership with GIS.
- Build program dashboards that show initiative progress, maturity improvement, remediation velocity, and participation across teams.
- Provide and support executive‑level reporting enabling leadership to understand security posture and risk reduction progress.
Executive Stakeholder Communication
- Serve as central communication lead for the NIST program.
- Develop structured communications including monthly executive briefings and quarterly maturity reports.
- Translate technical security work into strategic insights for leadership.
- Ensure leadership visibility into both program progress and emerging risks.
Matrix Leadership & Cross‑Functional Execution
- Lead execution across a matrixed organization without direct reporting authority.
- Influence engineering leaders, architects, and security teams to align with NIST objectives.
- Coordinate contributions from security engineering, identity teams, infrastructure teams, platform teams, and application development.
- Drive accountability across distributed teams to ensure measurable outcomes.
Risk Identification and Remediation Strategy
- Continuously assess the organization's security posture relative to NIST expectations.
- Identify gaps between current control maturity and target maturity.
- Coordinate remediation strategies prioritizing highest risk exposure areas.
- Ensure remediation initiatives deliver sustainable security improvements.
Governance Structure
- NIST Steering Committee – Participate with other senior leadership oversight responsible for strategic direction.
- Initiative Workstream Leads – Coordinate / Lead technical leaders responsible for execution within each domain.
- Program Management Layer – Operational coordination ensuring milestones and dependencies remain aligned.
- Executive Reporting Cadence – Regular updates on maturity progress, risk posture, and initiative health.
Qualifications – Experience
- 10+ years in enterprise security, security architecture, risk management, or security program leadership or equivalent program leading experience
- Experience leading large‑scale security or related transformation programs.
- Familiarity with operating security programs aligned to NIST, ISO 27001, PCI DSS, or SOX.
- Experience coordinating cross‑functional engineering, technical, data and/or security initiatives within complex enterprise / technical / service environments.
- Bachelor’s degree required
Core Competencies
- Enterprise program leadership
- Matrix leadership across engineering teams
- Strategic planning and operational execution
- Security framework interpretation and implementation
- Executive communication and influence
- Data‑driven program reporting
Impact of This Role
- Improves measurable maturity against the NIST Cybersecurity Framework.
- Strengthens enterprise security posture across identity, asset visibility, privileged access, and data protection.
- Provides leadership clear insight into security maturity and risk exposure.
- Aligns engineering teams with operational security improvements while maintaining delivery velocity.
- Demonstrates to customers, partners, regulators, and shareholders a structured and continuously improving security posture.
The hiring range for this position in Connecticut is $155,700.00 to $208,700.00 per year and in New York is $163,100.00 to $218,700.00 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate’s geographic region, job-related knowledge, skills, and experience among other factors. A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.
Acerca de Disney Entertainment and ESPN Product & Technology:
En Disney Entertainment and ESPN Product & Technology, fusionamos imaginación e innovación para reinventar las formas en las que las personas disfrutan e interactúan con los cuentos y los productos más queridos del mundo. Nuestro trabajo tiene un gran alcance y es sumamente sofisticado. Brindamos experiencias increíbles, transformamos el futuro de los medios de comunicación y creamos productos y plataformas que permiten la conexión entre las personas de cualquier lugar del mundo y los cuentos y los deportes que más les gustan.
Disney tiene la capacidad de combinar tecnología de primer nivel con una creatividad inigualable, y eso nos hace únicos. Es la esencia de nuestro pasado, presente y futuro. Somos narradores e innovadores. Creadores y constructores. Artistas e ingenieros.
Acerca de The Walt Disney Company:
The Walt Disney Company, junto con sus subsidiarias y afiliadas, es una empresa internacional diversificada líder en entretenimiento familiar y medios de comunicación que incluye tres segmentos comerciales principales: Disney Entertainment, ESPN y Disney Experiences. Desde sus humildes comienzos como estudio de dibujos animados en la década de 1920 hasta su reconocido nombre en la industria del entretenimiento en la actualidad, Disney continúa con orgullo su legado de crear historias y experiencias de clase mundial para toda la familia. Las historias, los personajes y las experiencias de Disney llegan a consumidores e invitados de todos los rincones del mundo. Con operaciones en más de 40 países, nuestros empleados y miembros del elenco trabajan juntos para crear experiencias de entretenimiento que sean apreciadas a nivel local y global.
Este puesto es en Disney Entertainment & Sports LLC, que forma parte de una empresa comercial que denominamos Disney Entertainment and ESPN Product & Technology.
Disney Entertainment & Sports LLC es un empleador que ofrece igualdad de oportunidades. Los solicitantes recibirán consideración para el empleo independientemente de su raza, religión, color, sexo, orientación sexual, género, identidad de género, expresión de género, nacionalidad, ascendencia, edad, estado civil, condición de militar o veterano, afección médica, información genética o discapacidad, o cualquier otro fundamento prohibido por la ley federal, estatal o local. Disney defiende un entorno empresarial donde las ideas y decisiones de todas las personas nos ayudan a crecer, innovar, crear las mejores historias y ser relevantes en un mundo en constante evolución.
ADAPTACIÓN POR DISCAPACIDAD PARA SOLICITUDES DE EMPLEO
The Walt Disney Company and its Affiliated Companies are Equal Employment Opportunity employers and welcome all job seekers including individuals with disabilities and veterans with disabilities. If you have a disability and believe you need a reasonable accommodation in order to search for a job opening or apply for a position, visit the Disney candidate disability accommodations FAQs. We will only respond to those requests that are related to the accessibility of the online application system due to a disability.
¿Tiene problemas técnicos? Consulte las preguntas frecuentes para obtener ayuda.
Proceso de contratación
-
¿Dónde comienza tu cuento?
Explora Disney Careers y el blog Life at Disney para conocer las increíbles oportunidades que esperan a ser descubiertas en The Walt Disney Company.
-
Formar parte del cuento
Hay muchas marcas y negocios diferentes para explorar. Una vez que hayas encontrado la oportunidad adecuada para ti, da el próximo paso completando su solicitud.
-
El próximo capítulo
Una vez que hayas presentado la solicitud, recibirás un correo electrónico que te permitirá acceder al panel de candidatos. Crea tu información de inicio de sesión y asegúrate de revisar el panel con frecuencia para ver el progreso de tu aplicación.
Explora esta ubicación Bristol, CT
Bristol, en Connecticut, está a solo dos horas de Boston y Nueva York y a solo una hora de la costa. Desde la belleza natural de las pintorescas colinas y el follaje de otoño, hasta las antenas satelitales de alta tecnología de ESPN, Bristol, con el tamaño de una ciudad, pero el ambiente de un pueblo pequeño, ofrece recuerdos maravillosos sin importar el ritmo al que quieras vivirlos.
Empleos relacionados
- Senior Product Manager II, Loyalty & Retention Disney Entertainment and ESPN Product & Technology 10147146 Nueva York, Nueva York Presentar una solicitud
- Transmission Specialist I Disney Entertainment and ESPN Product & Technology 10147184 Bristol, Connecticut Presentar una solicitud
- Principal Product Manager - Customer Identity Product Disney Entertainment and ESPN Product & Technology 10148453 Nueva York, Nueva York / Santa Mónica, California / San Francisco, California / Seattle, Washington Presentar una solicitud
NUESTRA CULTURA
Contenidos relacionados
-
Oportunidades profesionales Historias de empleados Disney Cruise Line cast delivers magic in The Bahamas -
Estudiantes y Graduados Recientes Disney International Programs -
Historias de empleados From Shore to Sea: Simon, Manager, Fleet Operations Training -
Oportunidades profesionales Desarrollo profesional Diversidad, equidad e inclusión Cultura y valores Historias de empleados Estudiantes y Graduados Recientes Entradas del blog "Vida en Disney LATAM" -
Desarrollo profesional Historias de empleados Disney Cruise Line’s leadership team in The Bahamas on growth, building careers, and making magic -
Historias de empleados Celebrating Tonie Rose, first woman at Disney Cruise Line to lead a pool deck crew -
Historias de empleados Trabajo e innovación Podcast Life at Disney | Cómo convertir datos en soluciones de negocio en América Latina
-
Líderes ejecutivos
Nuestros altos ejecutivos aportan una tremenda experiencia, pensamiento visionario y un compromiso compartido con la excelencia, la creatividad y la innovación en el funcionamiento diario de la empresa.
Obtén más información -
Inclusión
En Disney, queremos que todas las personas tengan un sentido de pertenencia y que prosperen. Crear un ambiente acogedor y respetuoso para nuestros empleados y visitantes es fundamental para la cultura de nuestra empresa y nuestro negocio. Nos esforzamos por crear entornos de trabajo solidarios que impulsen la innovación y refuercen una cultura en la que todos los empleados se sientan bienvenidos, respetados y valorados.
Obtén más información
Registrarse para recibir alertas de trabajo
Entérese de las últimas ofertas de trabajo a medida que se publiquen.
COMPARTIR
Los enlaces se abren en pestañas nuevas.