Sr IT Security Risk Assessor

Job ID 784094BR

Location Burbank, California, United States; Seattle, Washington, United States

Business The Walt Disney Company (Corporate)

Date posted Apr. 20, 2021

Job Summary:

At Disney, we’re storytellers. We make the impossible, possible. The Walt Disney Company is a world-class entertainment and technological leader. Walt’s passion was to continuously envision new ways to move audiences around the world—a passion that remains our touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, news, movies and a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences — and we’re constantly looking for new ways to enhance and protect these exciting experiences.

The Global Information Security (GIS) group provides services and solutions to protect the value and use of Disney’s information through risk evaluation, collaboration, standardization, enforcement, and education across the enterprise. We are here to protect the brand and reputation while enabling and supporting the business units. GIS teams are located in Seattle, Glendale, and Orlando.

In order to ensure that our services keep TWDC secure, we follow an ongoing, iterative process, including continued reevaluation of our services over time to address emerging threats, as well as changes in business and technology. This process includes:

  1. Analysis of known and emerging threats to determine risks against TWDC assets;
  2. Creation, maintenance, governance and communication of security policies and standards across TWDC;
  3. Assessment and audit of compliance against the security policies and standards;
  4. Assurance that TWDC assets are effectively managed and monitored to meet TWDC security criteria.

We look to add people to our team who are focused on delivery, prioritize data-driven decisions over opinions, are continuous learners, passionate about information security and love their work.

The Technology Risk Management team operates as trusted advisors to ensure risks to the confidentiality, integrity, and availability of TWDC data and services are identified and assessed, while driving for risks to be managed at an acceptable level. This is accomplished by analyzing identified risks, key risk measures, and control measurements across the technology environment; while also engaging key stakeholder and leveraging the risk management framework.

Responsibilities:

The Senior Security Specialist, Risk Management is responsible for supporting the strategic advancement and the operational excellence of Technology Risk Management’s functions, including but not limited to:

Risk Analysis & Reporting

  • Compile risk artifacts and perform risk analysis of strategic technology risks, supporting artifacts, historical losses, technology measurements and projects.
  • Identify, qualify and prioritize technology risks to TWDC
  • Analyze, measure, and monitor a breadth of technology risks and facilitate treatment decisions.
  • Develop and provide risk (reporting) content for various operational and senior-leadership meetings, briefings and dashboards.
  • Develop and refine key risk indicators
  • Assist in the design of risk dashboards at executive, operational, and tactical levels

Engagement, Advisement, & Communication:

  • Support and partner with other GIS teams and TWDC Segments/ business partners on technology risk management matters
  • Guide and advise partner teams on relevant risk management processes and risk reduction strategies
  • Communicate both verbally and in writing with team members and management on risk management issues

Program & Task Management

  • Develop and contribute content for program materials (i.e. strategy, procedures, policies, training) and other supporting documentation

Manage vendor/ contractors for identified efforts

Basic Qualifications:

Minimum 3 years in technology organizations, with 7-10 years of information security / risk/ assurance work experience supporting a moderate to large organization

  • Experienced with Microsoft suite, e.g. Word, Excel, Powerpoint
  • Proven understanding of information security principles, risk assessment and risk management procedures and methodologies.
  • Strong analytical skills; ability to analyze collected data, interpret results, and create related reports
  • Ability to multi-task, manage, prioritize and organize one’s own time while delivering accurately, on time, and with attention to detail.
  • Ability to understand and articulate complex business/risk management issues in a clear, concise, and easily consumable audience-specific format; especially executive-level messaging
  • Ability to develop strong and effective working relationships
  • Able to problem-solve and perform necessary research to identify relevant artifacts or solutions
  • Must have situational awareness and ability adjust conversation and approach based on culture/ environmental factors
  • Must have clear and concise verbal and written communications skills; ability to articulate recommendations and risk interpretations in a clear, concise and audience-specific format
  • Able to proactively provide status and concerns that may impact the execution of assigned project or tasks

Preferred Qualifications:

Required: BA/BS in business, or BA/BS in cyber security or computer science related field, or equivalent military experience

Additional Information:

DISNEYTECH

About The Walt Disney Company (Corporate):

At Disney Corporate you can see how the businesses behind the Company’s powerful brands come together to create the most innovative, far-reaching and admired entertainment company in the world. As a member of a corporate team, you’ll work with world-class leaders driving the strategies that keep The Walt Disney Company at the leading edge of entertainment. See and be seen by other innovative thinkers as you enable the greatest storytellers in the world to create memories for millions of families around the globe.

About The Walt Disney Company:

The Walt Disney Company, together with its subsidiaries and affiliates, is a leading diversified international family entertainment and media enterprise with the following business segments: media networks, parks and resorts, studio entertainment, consumer products and interactive media. From humble beginnings as a cartoon studio in the 1920s to its preeminent name in the entertainment industry today, Disney proudly continues its legacy of creating world-class stories and experiences for every member of the family. Disney’s stories, characters and experiences reach consumers and guests from every corner of the globe. With operations in more than 40 countries, our employees and cast members work together to create entertainment experiences that are both universally and locally cherished.

This position is with Disney Worldwide Services, Inc., which is part of a business segment we call The Walt Disney Company (Corporate).

Disney Worldwide Services, Inc. is an equal opportunity employer. Applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, or protected veteran status or any other basis prohibited by federal, state or local law. Disney fosters a business culture where ideas and decisions from all people help us grow, innovate, create the best stories and be relevant in a rapidly changing world.

More Information

Apply for this job

Leave your thoughts

Share this job