Principal Compliance Analyst
Descrição do cargo:
Technology is at the heart of Disney’s past, present, and future. Disney Entertainment and ESPN Product & Technology is a global organization of engineers, product developers, designers, technologists, data scientists, and more – all working to build and advance the technological backbone for Disney’s media business globally.
The team marries technology with creativity to build world-class products, enhance storytelling, and drive velocity, innovation, and scalability for our businesses. We are Storytellers and Innovators. Creators and Builders. Entertainers and Engineers. We work with every part of The Walt Disney Company’s media portfolio to advance the technological foundation and consumer media touch points serving millions of people around the world.
Here are a few reasons why we think you’d love working here:
Building the future of Disney’s media: Our Technologists are designing and building the products and platforms that will power our media, advertising, and distribution businesses for years to come.
Reach, Scale & Impact: More than ever, Disney’s technology and products serve as a signature doorway for fans' connections with the company’s brands and stories. Disney+. Hulu. ESPN. ABC. ABC News…and many more. These products and brands – and the unmatched stories, storytellers, and events they carry – matter to millions of people globally.
Innovation: We develop and implement groundbreaking products and techniques that shape industry norms, and solve complex and distinctive technical problems.
The Business Operations team helps guide and articulate technology strategy and research, and is responsible for driving the day-to-day operation of the Product & Technology organization, including: project and portfolio management and tracking; organization-level capital, space, and resource management and allocation; process management; technical incident management; and our administrative and workplace experience support team.
Role Summary
P&T is supporting a multi‑year GIS initiative aligned to the NIST Cybersecurity Framework (CSF) to strengthen operational resilience, reduce enterprise risk, and demonstrate measurable security maturity to shareholders, regulators, and external customers.
Achieving meaningful improvement across NIST domains requires coordinated execution across numerous security programs, engineering teams, and operational functions. To ensure success, we are establishing a dedicated NIST Security Program Lead responsible for governing and orchestrating the delivery of all NIST‑aligned initiatives across the enterprise security roadmap.
This role must be filled as a project hire (employee) rather than a contractor due to the sensitivity of the work. The position will have visibility into confidential security architecture, control weaknesses, internal audit findings, risk assessments, and remediation strategies that directly impact the organization's security posture. The NIST Principal Compliance Analyst operates as the central execution authority for the NIST program, ensuring that all framework‑aligned initiatives progress with clear governance, measurable outcomes, and transparent reporting to senior leadership.
Program Philosophy and Operating Model
The NIST program will be executed using a framework‑driven operational model focused on measurable security maturity and transparent governance.
- Framework Alignment – All initiatives must map clearly to NIST CSF domains: Identify, Protect, Detect, Respond, and Recover.
- Measurable Progress – Security improvements must be quantifiable through defined maturity targets and scorecards.
- Transparent Governance – Program progress must be visible to engineering teams, program leaders, and executive stakeholders.
- Cross‑Enterprise Collaboration – The program coordinates across security engineering, infrastructure, application development, and operations teams.
Key Responsibilities – NIST Program Leadership & Governance
- Serve as enterprise program leader responsible for execution of the NIST CSF roadmap.
- Establish the governance model for NIST initiatives including initiative ownership, accountability, and reporting cadence.
- Coordinate program execution across security engineering, infrastructure teams, and application teams.
- Ensure initiatives move from design to deployment to operational maturity.
Workstream Coordination & Delivery Oversight
- IT Asset Management and CMDB maturity
- Zero Trust architecture deployment
- Data Security Posture Management (DSPM)
- Privileged Access Management (PAM) expansion
- Identity and application authentication governance
- Secrets management lifecycle automation
- Consumer protection security controls
- AI security governance and defensive controls
- Insider threat monitoring capabilities
- Vendor risk management processes
- Patch and vulnerability management automation
- Ensure each initiative maintains clear deliverables, milestone tracking, measurable outcomes, and NIST alignment.
Program Scorecards & Security Maturity Measurement
- Execute the P&T work of a GIS driven and designed security maturity measurement framework aligned to NIST CSF.
- Develop standardized scorecards measuring control maturity, implementation coverage, operational adoption, and risk reduction impact in partnership with GIS.
- Build program dashboards that show initiative progress, maturity improvement, remediation velocity, and participation across teams.
- Provide and support executive‑level reporting enabling leadership to understand security posture and risk reduction progress.
Executive Stakeholder Communication
- Serve as central communication lead for the NIST program.
- Develop structured communications including monthly executive briefings and quarterly maturity reports.
- Translate technical security work into strategic insights for leadership.
- Ensure leadership visibility into both program progress and emerging risks.
Matrix Leadership & Cross‑Functional Execution
- Lead execution across a matrixed organization without direct reporting authority.
- Influence engineering leaders, architects, and security teams to align with NIST objectives.
- Coordinate contributions from security engineering, identity teams, infrastructure teams, platform teams, and application development.
- Drive accountability across distributed teams to ensure measurable outcomes.
Risk Identification and Remediation Strategy
- Continuously assess the organization's security posture relative to NIST expectations.
- Identify gaps between current control maturity and target maturity.
- Coordinate remediation strategies prioritizing highest risk exposure areas.
- Ensure remediation initiatives deliver sustainable security improvements.
Governance Structure
- NIST Steering Committee – Participate with other senior leadership oversight responsible for strategic direction.
- Initiative Workstream Leads – Coordinate / Lead technical leaders responsible for execution within each domain.
- Program Management Layer – Operational coordination ensuring milestones and dependencies remain aligned.
- Executive Reporting Cadence – Regular updates on maturity progress, risk posture, and initiative health.
Qualifications – Experience
- 10+ years in enterprise security, security architecture, risk management, or security program leadership or equivalent program leading experience
- Experience leading large‑scale security or related transformation programs.
- Familiarity with operating security programs aligned to NIST, ISO 27001, PCI DSS, or SOX.
- Experience coordinating cross‑functional engineering, technical, data and/or security initiatives within complex enterprise / technical / service environments.
- Bachelor’s degree required
Core Competencies
- Enterprise program leadership
- Matrix leadership across engineering teams
- Strategic planning and operational execution
- Security framework interpretation and implementation
- Executive communication and influence
- Data‑driven program reporting
Impact of This Role
- Improves measurable maturity against the NIST Cybersecurity Framework.
- Strengthens enterprise security posture across identity, asset visibility, privileged access, and data protection.
- Provides leadership clear insight into security maturity and risk exposure.
- Aligns engineering teams with operational security improvements while maintaining delivery velocity.
- Demonstrates to customers, partners, regulators, and shareholders a structured and continuously improving security posture.
The hiring range for this position in Connecticut is $155,700.00 to $208,700.00 per year and in New York is $163,100.00 to $218,700.00 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate’s geographic region, job-related knowledge, skills, and experience among other factors. A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.
Sobre o Disney Entertainment and ESPN Product & Technology:
Na Disney Entertainment and ESPN Product & Technology, estamos combinando imaginação e inovação para reimaginar as maneiras como as pessoas experimentam e se envolvem com as histórias e produtos mais adorados do mundo. Nosso trabalho é amplo e profundamente sofisticado. Criamos experiências incríveis, transformamos o futuro da mídia e criamos produtos e plataformas que permitem a conexão entre pessoas em todos os lugares e as histórias e esportes que elas amam.
A capacidade da Disney de unir tecnologia de nível mundial com criatividade exclusiva nos torna únicos. Ela está no centro do nosso passado, presente e futuro. Somos contadores de histórias e inovadores. Criadores e construtores. Animadores e engenheiros.
Sobre The Walt Disney Company:
A The Walt Disney Company, juntamente com suas subsidiárias e afiliadas, é uma líder diversificada em entretenimento familiar e mídia internacional que inclui três segmentos principais de negócios: Disney Entertainment, ESPN e Disney Experiences. Desde seus primeiros passos como um estúdio de desenho animado na década de 1920 até se tornar o atual nome de destaque na indústria do entretenimento, a Disney orgulhosamente dá continuidade a seu legado de criação de histórias e experiências de padrão internacional para toda a família. As histórias, personagens e experiências da Disney tocam consumidores e visitantes de todas as partes do mundo. Com operações em mais de 40 países, nossos funcionários e colaboradores trabalham juntos para criar experiências de entretenimento adoradas por todos.
Esta vaga é oferecida junto à Disney Entertainment & Sports LLC, que é parte de um segmento de negócios que chamamos de Disney Entertainment and ESPN Product & Technology.
Disney Entertainment & Sports LLC é um empregador de oportunidades iguais. Os candidatos serão selecionados para emprego independente de raça, religião, cor, sexo, orientação sexual, gênero, identidade de gênero, expressão de gênero, nacionalidade, ancestralidade, idade, estado civil, status militar ou de veterano, quadro clínico, informações genéticas ou deficiência, ou qualquer outro motivo proibido por lei federal, estadual ou local. A Disney defende um ambiente de negócios em que ideias e decisões de todas as pessoas nos ajudam a crescer, inovar, criar as melhores histórias e ser relevantes em um mundo em constante evolução.
ACOMODAÇÃO PARA PESSOAS COM NECESSIDADES ESPECIAIS PARA CANDIDATURAS A EMPREGO
The Walt Disney Company and its Affiliated Companies are Equal Employment Opportunity employers and welcome all job seekers including individuals with disabilities and veterans with disabilities. If you have a disability and believe you need a reasonable accommodation in order to search for a job opening or apply for a position, visit the Disney candidate disability accommodations FAQs. We will only respond to those requests that are related to the accessibility of the online application system due to a disability.
Está tendo problemas técnicos? Consulte as perguntas frequentes para obter ajuda.
Processo de contratação
-
Onde começa a sua história?
Explore o Disney Careers e o blog Life at Disney para saber mais sobre todas as oportunidades incríveis que esperam ser descobertas na The Walt Disney Company.
-
Seja parte da história
Há muitas marcas e empresas diferentes a serem exploradas. Depois de encontrar a oportunidade certa para você, dê o próximo passo preenchendo sua candidatura.
-
O próximo capítulo
Depois de se candidatar, você receberá um e-mail permitindo que acesse o painel do candidato. Crie seu login e lembre-se de verificar seu painel com frequência para ver o progresso de sua candidatura.
Conheça este local Bristol, Connecticut
Bristol, Connecticut, fica a apenas duas horas de Boston e Nova York e a apenas uma hora da costa. Da beleza natural de colinas pitorescas e folhagens de outono nos EUA às antenas parabólicas de alta tecnologia da ESPN, Bristol é uma cidade de tamanho considerável com uma atmosfera de cidade pequena, oferecendo lembranças maravilhosas, independentemente do seu ritmo.
Vagas relacionadas
- Senior Product Manager II, Loyalty & Retention Disney Entertainment and ESPN Product & Technology 10147146 Nova Iorque, Nova Iorque Aplicar
- Transmission Specialist I Disney Entertainment and ESPN Product & Technology 10147184 Bristol, Coneticute Aplicar
- Principal Product Manager - Customer Identity Product Disney Entertainment and ESPN Product & Technology 10148453 Nova Iorque, Nova Iorque / Santa Mônica, Califórnia / São Francisco, Califórnia / Seattle, Washington Aplicar
NOSSA CULTURA
Conteúdo relacionado
-
Oportunidades de carreira Histórias de funcionários Disney Cruise Line cast delivers magic in The Bahamas -
Histórias de funcionários From Shore to Sea: Simon, Manager, Fleet Operations Training -
Oportunidades de carreira Desenvolvimento de carreira Diversidade, igualdade e inclusão Cultura e valores Histórias de funcionários Estudantes e recém-formados Vida na Disney LATAM Blog Posts -
Desenvolvimento de carreira Histórias de funcionários Disney Cruise Line’s leadership team in The Bahamas on growth, building careers, and making magic -
Histórias de funcionários Celebrating Tonie Rose, first woman at Disney Cruise Line to lead a pool deck crew -
Histórias de funcionários Trabalho e inovação Podcast Life at Disney | Transformando Dados em Soluções de Negócio na América Latina
-
Liderança executiva
Nossos executivos seniores trazem enorme experiência, pensamento visionário e um compromisso compartilhado com excelência, criatividade e inovação para a operação cotidiana da empresa.
Saiba mais -
Inclusão
Na Disney, queremos que todos sintam que fazem parte de algo e prosperem. Criar um ambiente acolhedor e respeitoso para nossos funcionários e hóspedes é fundamental para a cultura da nossa empresa e nossos negócios. Nós nos esforçamos para criar ambientes de trabalho acolhedores que impulsionem a inovação e reforcem uma cultura em que todos os funcionários se sintam bem-vindos, respeitados e valorizados.
Saiba mais
Inscrever-se para receber alertas de vagas
Obtenha as oportunidades de emprego mais recentes assim que se tornarem disponíveis.
COMPARTILHAR
Links abertos em novas guias.