Principal Compliance Analyst

The Walt Disney CompanyBristol, CT
Onsite

About The Position

Technology is at the heart of Disney’s past, present, and future. Disney Entertainment and ESPN Product & Technology is a global organization of engineers, product developers, designers, technologists, data scientists, and more – all working to build and advance the technological backbone for Disney’s media business globally. The team marries technology with creativity to build world-class products, enhance storytelling, and drive velocity, innovation, and scalability for our businesses. We are Storytellers and Innovators. Creators and Builders. Entertainers and Engineers. We work with every part of The Walt Disney Company’s media portfolio to advance the technological foundation and consumer media touch points serving millions of people around the world. The Business Operations team helps guide and articulate technology strategy and research, and is responsible for driving the day-to-day operation of the Product & Technology organization, including: project and portfolio management and tracking; organization-level capital, space, and resource management and allocation; process management; technical incident management; and our administrative and workplace experience support team. P&T is supporting a multi‑year GIS initiative aligned to the NIST Cybersecurity Framework (CSF) to strengthen operational resilience, reduce enterprise risk, and demonstrate measurable security maturity to shareholders, regulators, and external customers. Achieving meaningful improvement across NIST domains requires coordinated execution across numerous security programs, engineering teams, and operational functions. To ensure success, we are establishing a dedicated NIST Security Program Lead responsible for governing and orchestrating the delivery of all NIST‑aligned initiatives across the enterprise security roadmap. This role must be filled as a project hire (employee) rather than a contractor due to the sensitivity of the work. The position will have visibility into confidential security architecture, control weaknesses, internal audit findings, risk assessments, and remediation strategies that directly impact the organization's security posture. The NIST Principal Compliance Analyst operates as the central execution authority for the NIST program, ensuring that all framework‑aligned initiatives progress with clear governance, measurable outcomes, and transparent reporting to senior leadership. The NIST program will be executed using a framework‑driven operational model focused on measurable security maturity and transparent governance. Framework Alignment – All initiatives must map clearly to NIST CSF domains: Identify, Protect, Detect, Respond, and Recover. Measurable Progress – Security improvements must be quantifiable through defined maturity targets and scorecards. Transparent Governance – Program progress must be visible to engineering teams, program leaders, and executive stakeholders. Cross‑Enterprise Collaboration – The program coordinates across security engineering, infrastructure, application development, and operations teams.

Requirements

  • 10+ years in enterprise security, security architecture, risk management, or security program leadership or equivalent program leading experience
  • Experience leading large‑scale security or related transformation programs.
  • Familiarity with operating security programs aligned to NIST, ISO 27001, PCI DSS, or SOX.
  • Experience coordinating cross‑functional engineering, technical, data and/or security initiatives within complex enterprise / technical / service environments.
  • Bachelor’s degree required
  • Enterprise program leadership
  • Matrix leadership across engineering teams
  • Strategic planning and operational execution
  • Security framework interpretation and implementation
  • Executive communication and influence
  • Data‑driven program reporting

Responsibilities

  • Serve as enterprise program leader responsible for execution of the NIST CSF roadmap.
  • Establish the governance model for NIST initiatives including initiative ownership, accountability, and reporting cadence.
  • Coordinate program execution across security engineering, infrastructure teams, and application teams.
  • Ensure initiatives move from design to deployment to operational maturity.
  • Workstream Coordination & Delivery Oversight: IT Asset Management and CMDB maturity, Zero Trust architecture deployment, Data Security Posture Management (DSPM), Privileged Access Management (PAM) expansion, Identity and application authentication governance, Secrets management lifecycle automation, Consumer protection security controls, AI security governance and defensive controls, Insider threat monitoring capabilities, Vendor risk management processes, Patch and vulnerability management automation.
  • Ensure each initiative maintains clear deliverables, milestone tracking, measurable outcomes, and NIST alignment.
  • Execute the P&T work of a GIS driven and designed security maturity measurement framework aligned to NIST CSF.
  • Develop standardized scorecards measuring control maturity, implementation coverage, operational adoption, and risk reduction impact in partnership with GIS.
  • Build program dashboards that show initiative progress, maturity improvement, remediation velocity, and participation across teams.
  • Provide and support executive-level reporting enabling leadership to understand security posture and risk reduction progress.
  • Serve as central communication lead for the NIST program.
  • Develop structured communications including monthly executive briefings and quarterly maturity reports.
  • Translate technical security work into strategic insights for leadership.
  • Ensure leadership visibility into both program progress and emerging risks.
  • Lead execution across a matrixed organization without direct reporting authority.
  • Influence engineering leaders, architects, and security teams to align with NIST objectives.
  • Coordinate contributions from security engineering, identity teams, infrastructure teams, platform teams, and application development.
  • Drive accountability across distributed teams to ensure measurable outcomes.
  • Continuously assess the organization's security posture relative to NIST expectations.
  • Identify gaps between current control maturity and target maturity.
  • Coordinate remediation strategies prioritizing highest risk exposure areas.
  • Ensure remediation initiatives deliver sustainable security improvements.

Benefits

  • A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service