The Walt Disney Company Logo

The Walt Disney Company

Staff Security Specialist, Information Security

Posted 9 Hours Ago
Be an Early Applicant
Hybrid
Orlando, FL
Senior level
Hybrid
Orlando, FL
Senior level
The Staff Security Specialist will provide security expertise to ensure compliance controls are implemented in projects, systems, and third-party services. Responsibilities include leading reviews of assessments, coordinating remediation activities, verifying compliance against standards, and recommending improvements to security posture while staying informed on emerging threats and trends.
The summary above was generated by AI

At Disney, we're storytellers. We make the impossible, possible. The Walt Disney Company is a world-class entertainment and technological leader. Walt's passion was to continuously envision new ways to move audiences around the world-a passion that remains our touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, news, movies and a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences - and we're constantly looking for new ways to enhance and protect these exciting experiences.
The Global Information Security (GIS) group provides services and solutions to protect the value and use of Disney's information through risk evaluation, collaboration, standardization, enforcement, and education across the enterprise. We protect the brand and reputation while enabling and supporting business objectives. GIS teams are located in Seattle, Burbank, and Orlando.
This role will provide security expertise to ensure new projects, existing systems and third-party service providers have required security, privacy and compliance controls in place. The Staff Security Specialist will review system architecture, data flow and operational processes when evaluating systems. The Staff Security Specialist will also conceptualize and develop solutions to improve security posture and lead projects from conception to design to implementation. Without this additional support security work will not be completed timely resulting in project delays or new systems potentially going live with security vulnerabilities.
What You'll Do:

  • Lead the review reports, assessments, and findings to identify remediation and/or corrective action needed.
  • Drive coordination with IT and business partners to facilitate necessary remediation and corrective action.
  • Verify remediation and corrective action activity achieves compliance against security standards such as CIS Benchmarks, NIST, and TWDC policies and standards.
  • Document open items in status reports, including next steps, dependencies, and stakeholders.
  • Lead communication of results to stakeholders, including technical and non-technical audiences.
  • Provide recommendations to improve security posture.
  • Lead in improving security baselines and standards.
  • Stay updated on evolving security guidelines and incorporate them into IT and business practices.
  • Stay informed on emerging threats and vulnerabilities.
  • Proactively recommend adjustments to mitigate risks.
  • Work closely with business partners, key stakeholders, and internal departments to evaluate current and future security and compliance strategies.
  • Stay informed about information security trends, directions, and technologies in the technology industry.
  • Monitor industry trends and identify best practices and/or methodologies to implement in-house.


Required Qualifications & Skills:

  • Minimum of 7 years' experience of related experience leading and facilitating corrective action
  • Highly skilled in coordinating remediation activities across a wide range of technologies.
  • 7+ years experience in identifying risk and execution of mitigation plans.
  • Demonstrated experience in a security program for a large and complex organization.
  • Knowledge of security frameworks and standards.
  • Strong analytical thinking and attention to detail.
  • Demonstrated problem solving skills with an ability to develop creative alternatives to complex problems, as well as continuous process improvement skills.
  • Demonstrated ability to handle sensitive information.
  • Ability to establish credibility and working relationships with a wide range of personnel, including operations, management, executive, and legal staff.
  • Demonstrated professional written, verbal, and presentation communications skills.
  • Solid understanding of project management principles, including a demonstrated ability to multi-task effectively.
  • Proven ability to work effectively in a fast-paced environment as part of a high performance team.


Required Education:

  • Bachelor's degree or equivalent experience in Cyber Security, Computer Science, Management Information Systems, or related field.


Preferred Education:

  • One or more general security certifications including PCNSE, Security+, CySA+, CCNA Cyber Ops, AWS, GSEC, GICSP, CISSP, or other relevant certifications
  • One or more vulnerability assessment or auditing certification including CISSA, CISM, GCCC, GSNA or other relevant certifications


The hiring range for this position in California is $126,400.00 to 169,500.00 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate's geographic region, job-related knowledge, skills and experience among other factors. A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.

Top Skills

Computer Science
Cyber Security
Management Information Systems

Similar Jobs at The Walt Disney Company

Senior level
AdTech • Digital Media • News + Entertainment
The Lead Security Solution Architect at Disney will design, implement, and manage security strategies tailored to business needs. Responsibilities include leading security risk assessments, developing mitigation strategies, and integrating security into existing infrastructures. The role involves mentoring junior staff and ensuring compliance with security policies across the organization.
Top Skills: AWSAzureGoogle Cloud Platform
2 Days Ago
Hybrid
Orlando, FL, USA
Entry level
Entry level
AdTech • Digital Media • News + Entertainment
The Associate Security Specialist is responsible for identifying security gaps through assessments, coordinating remediation efforts, and ensuring compliance with security standards. This role involves documentation, communication with stakeholders, and recommendations to improve security posture while staying informed on emerging threats.
Top Skills: Cybersecurity
4 Days Ago
Hybrid
Orlando, FL, USA
Mid level
Mid level
AdTech • Digital Media • News + Entertainment
The Security Specialist is responsible for addressing cybersecurity gaps, facilitating remediation with IT and business partners, and ensuring compliance with security standards. The role involves communication across teams to implement security improvements and staying informed on regulatory changes and emerging threats.

What you need to know about the Toronto Tech Scene

Although home to some of the biggest names in tech, including Google, Microsoft and Amazon, Toronto has established itself as one of the largest startup ecosystems in the world. And with over 2,000 startups — more than 30 percent of the country's total startups — Toronto continues to attract new businesses. Be it helping entrepreneurs manage their finances, simplifying business operations by automating payroll or assisting pharmaceutical companies in launching new drugs, the city's tech scene is just getting started.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account