At a Glance
- Tasks: Conduct security compliance assessments and manage third-party risk evaluations.
- Company: Join Disney, a global leader in entertainment and technology, creating unforgettable experiences.
- Benefits: Enjoy competitive pay, bonuses, and a range of medical and financial benefits.
- Why this job: Be part of a team that secures the magic while innovating in cybersecurity.
- Qualifications: 3+ years in IT audit or security, with experience in third-party risk management.
- Other info: Opportunities for growth in a dynamic, collaborative environment.
The predicted salary is between 70000 - 84000 £ per year.
At Disney, we’re storytellers. The Walt Disney Company (TWDC) is a world-class entertainment and technological leader. Our commitment is to create and deliver unforgettable experiences. The Enterprise Technology mission is to deliver technology solutions that align with business strategies while enabling enterprise efficiency and promoting cross-company collaborative innovation. The Global Information Security (GIS) organisation strives to secure the magic by employing best-in-class services to assess, prevent, detect, and respond to cyber threats that present risk to The Walt Disney Company.
The GIS Compliance team oversees ongoing security programs to evaluate the health of TWDC’s control environment. These programs include external audits, internal control validation, third-party assessments, and ongoing consulting. The department is responsible for understanding and interpreting regulated controls and assessment requirements for TWDC.
Responsibilities of Role:
- Coordinate and conduct security compliance assessments, including scheduling, planning, and scoping.
- Evaluate security compliance with external requirements and internal policies and standards.
- Identify and validate key control attributes for testing.
- Conduct informational walkthroughs to clarify processes and architectures.
- Collect and verify artifacts to support the assessment of security controls and procedures.
- Proactively manage and follow up on all requests.
- Document assessment findings and recommendations to management, highlighting the effectiveness and efficiency of control mechanisms.
- Document assessment results and detailed control process narratives in workpapers.
- Communicate the elements of effective and sustainable control design to IT and business partners.
- Coordinate continuous control monitoring mechanisms, collaborating with IT, Segment, and business partners to source and interpret data reflecting the current state of the control environment for TWDC.
- Facilitate the collection of control attestations and questionnaires for targeted controls and systems.
- Manage inventories and track remediation efforts and compensating controls.
- Stay informed about compliance and assessment trends within TWDC, at suppliers, and from legislators and regulatory bodies.
Must Haves:
- Minimum 3 years of IT audit, or IT security and/or compliance experience.
- Must have 3+ years Third-Party Risk Management experience.
- Experience with audits/assessments in complex environments.
- Experience interpreting and auditing external security regulations.
- Working knowledge of common IT security frameworks.
- Ability to grasp underlying technology stacks and document end-to-end service delivery flows.
- Good organizational, analytical, and problem-solving skills - balancing multiple priorities under tight deadlines.
- Excellent written, verbal, and visual communication for partners (internal & external) in all roles and levels.
Nice To Haves:
- Prior experience working within a global media, entertainment organization or fortune 100 company.
- Security certification (CISSP, CISA, GSEC) or comparable certification.
Education:
- Bachelor’s degree in Computer Science, Information Systems, Software, Electrical or Electronics Engineering, or comparable field of study, and/or equivalent work experience.
Security Specialist, Third-Party Risk Management employer: Disney Cruise Line - The Walt Disney Company
Contact Detail:
Disney Cruise Line - The Walt Disney Company Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Specialist, Third-Party Risk Management
✨Tip Number 1
Familiarise yourself with the specific compliance frameworks mentioned in the job description, such as PCI, SOX, and GDPR. Understanding these regulations will not only help you in interviews but also demonstrate your commitment to the role.
✨Tip Number 2
Network with professionals in the cybersecurity and compliance fields, especially those who have experience in third-party risk management. Engaging with industry experts can provide insights and potentially lead to referrals.
✨Tip Number 3
Stay updated on the latest trends and challenges in cybersecurity, particularly those affecting large organisations like Disney. Being knowledgeable about current events can help you stand out during discussions with interviewers.
✨Tip Number 4
Prepare to discuss your previous experiences with audits and assessments in complex environments. Be ready to share specific examples that highlight your problem-solving skills and ability to manage multiple priorities under tight deadlines.
We think you need these skills to ace Security Specialist, Third-Party Risk Management
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in IT audit, security compliance, and third-party risk management. Use specific examples that demonstrate your skills in these areas.
Craft a Compelling Cover Letter: In your cover letter, express your passion for cybersecurity and how your background aligns with Disney's mission to secure the magic. Mention any relevant certifications and experiences that make you a strong candidate.
Showcase Communication Skills: Since the role requires excellent communication, provide examples in your application of how you've effectively communicated complex information to various stakeholders in previous roles.
Highlight Problem-Solving Abilities: Demonstrate your analytical and problem-solving skills by including specific instances where you've successfully managed multiple priorities or resolved compliance issues under tight deadlines.
How to prepare for a job interview at Disney Cruise Line - The Walt Disney Company
✨Understand the Company Culture
Before your interview, take some time to research Disney's values and culture. Understanding their commitment to storytelling and innovation will help you align your answers with their mission and demonstrate that you're a good fit for the team.
✨Showcase Your Compliance Knowledge
Be prepared to discuss your experience with compliance assessments and third-party risk management. Highlight specific frameworks you've worked with and how you've successfully navigated complex environments in your previous roles.
✨Prepare for Technical Questions
Expect questions related to IT security frameworks and external regulations. Brush up on your knowledge of PCI, SOX, and GDPR, and be ready to explain how you've applied this knowledge in past projects.
✨Demonstrate Strong Communication Skills
Since the role involves collaborating with various partners, practice articulating your thoughts clearly and concisely. Use examples from your experience to illustrate how you've effectively communicated complex information to both technical and non-technical stakeholders.