Specialist, Cybersecurity Risk

Carnival Corporation

Miami (FL)

On-site

USD 85,000 - 125,000

Full time

25 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health benefits
401(k) with company match
Paid time off
Employee discounts
Tuition reimbursement

Job summary

Carnival Corporation is seeking a Cybersecurity Risk Specialist to support first- and third-party risk management across the enterprise. The role helps identify, assess, and report cybersecurity risks aligned with business objectives and regulatory requirements, collaborating with IT, OT cybersecurity, governance, and sourcing teams.

The ideal candidate has knowledge of GRC, risk management, and security controls; 1–2 years in cybersecurity; professional certifications preferred.

Qualifications

  • Bachelor’s degree in cybersecurity, information security, or a related field.
  • 1–2 years of cybersecurity or IT risk management experience.
  • Knowledge of GRC concepts, security controls, and frameworks.
  • Certifications such as CRISC, CISSP, CISA, Security+ preferred.
  • Experience with GRC tools like LogicGate, Archer or ServiceNow IRM.

Responsibilities

  • Identify, assess and monitor first- and third-party cybersecurity risks and mitigation.
  • Maintain risk registers, track risks and escalate as needed.
  • Prepare governance materials, executive dashboards, metrics and reports.
  • Collaborate across Cybersecurity Risk Management, IT, Legal, Privacy and sourcing teams.
  • Support annual planning, roadmaps and maturity assessments.

Skills

Problem-solving
Communication
Stakeholder management
Analytical thinking
Team collaboration
Leadership

Education

Bachelor's degree

Tools

GRC tools (LogicGate, Archer, ServiceNow IRM)

Job description

The Cybersecurity Risk Specialist is responsible for supporting the organization’s cybersecurity first-party risk management and third party risk management program. The role supports risk management processes that enable the organization to manage, control and report on cybersecurity risk in alignment with business objectives, regulatory requirements, and enterprise risk appetite. The ideal candidate possesses a broad understanding of IT cybersecurity governance, risk and compliance and people, process, and technology controls used to manage cybersecurity risk.

Essential Functions
  • Support the identification, assessment and monitoring of inherent and residual cybersecurity risks (first and third party), help recommend mitigation strategies, assist with monitoring mitigation activities, and support risk escalation and acceptance processes.
  • Support the maintenance of cybersecurity risk registers and help ensure risks are appropriately identified, documented, updated, tracked, and escalated. Assist in identifying emerging threats, trends, and systemic risks that may impact organizational objectives.
  • Support enterprise risk management integration and cybersecurity risk reporting activities. Monitor cybersecurity key risk indicators (KRIs), key performance indicators (KPIs), and programming maturity metrics. Prepare governance and risk management materials, executive dashboards, scorecards, metrics, and reports for senior leadership and business stakeholders.
  • Collaborate with Cybersecurity Risk Management team, Operational Technology (OT) Cybersecurity Risk Management, Cybersecurity Governance, Cybersecurity Compliance, IT, Maritime Cybersafety, Global Cybersecurity Services (GCS) Domain Leads, Sourcing, Legal, Privacy, and business stakeholders regarding cybersecurity requirements and contractual obligations.
  • Identify opportunities to improve cybersecurity risk management services programs, capabilities, effectiveness, operational resilience, and maturity. Support annual cybersecurity planning, strategic roadmap development, and maturity assessments.
Knowledge, Skills & Abilities
  • Scope: The position supports the global Cybersecurity Risk Management programs (first party and supply chain) and Global Cybersecurity Services to promote effective cybersecurity risk management across the enterprise.
  • Problem-solving: This position requires strong analytical, communication, stakeholder management, and problem-solving skills.
  • Impact: Role helps facilitate risk-based decisioning by key stakeholders and the organization. Ability to act as a champion of cybersecurity and risk management best practices.
  • Leadership: Supports cross-collaboration across Global Cybersecurity Services and the brands.
For all roles
  • Knowledge: Understanding of workplace policies and procedures / Familiarity with team collaboration tools and techniques.
  • Skills: Strong time management and organizational skills
  • Abilities: Ability to maintain reliable and consistent attendance / Capacity to be punctual and meet deadlines / Ability to collaborate effectively with colleagues and work as part of a team / Demonstrated professionalism in all interactions and tasks.
Essential/Minimum qualifications
  • Knowledge of governance, risk and compliance (GRC). cybersecurity principles, risk management principles and methodologies, and security control frameworks.
  • Understanding of security concepts: security awareness, identity and access management (including privileged access, segregation of duties principles, and least privilege principles), vulnerability management, data protection, application security, network security, security architecture, and security operations.
  • Strong written and verbal communication skills.
  • Strong analytical, organizational, and documentation skills.
Essential Experience Required
  • Bachelor’s degree in Cybersecurity, Information Security, Information Technology, Computer Science, Risk Management, Business Administration, or a related field.
  • 1-2 years of experience in cybersecurity, information security, IT risk management, governance, or related disciplines.
  • Knowledge of information technology, cybersecurity and risk management.
  • Preferred Experience:
  • Professional certifications such as: CRISC (Certified in Risk and Information Systems Control), CISSP (Certified Information Systems Security Professional), CISA (Certified Information Systems Auditor), Security+, CGRC (Certified in Governance, Risk and Compliance)
  • Experience with GRC platforms such as LogicGate, Archer or ServiceNow IRM.
  • Familiarity with regulatory and privacy requirements such as SOX, PCI DSS, GDPR, CCPA, CIS, SEC cybersecurity regulations, or other industry-specific requirements.
  • Knowledge of third-party risk management and supplier cybersecurity assessments.

Travel: No or very little travel likely

Work Conditions: Work primarily in a climate-controlled environment with minimal safety/health hazard potential.

Physical Demands: Must be able to remain in a stationary position at a desk and/or computer for extended periods of time.

This position is classified as "in-office." As an in-office role, it requires employees to work from a designated Carnival office in South Florida Monday through Thursday each week. Employees may work from their homes on Fridays. Candidates must be located in (or willing to relocate to) the Miami/Ft. Lauderdale area.

Offers to selected candidates will be made on a fair and equitable basis, taking into account specific job-related skills and experience.

Benefits
  • Health Benefits:
    • Cost-effective medical, dental and vision plans
    • Employee Assistance Program and other mental health resources
    • Additional programs include company paid term life insurance and disability coverage
  • Financial Benefits:
    • 401(k) plan that includes a company match
    • Employee Stock Purchase plan
  • Paid Time Off:
    • Holidays – All full-time and part-time with benefits employees receive days off for 8 company-wide holidays, plus 2 additional floating holidays to be taken at the employee’s discretion.
    • Vacation Time – All full-time employees at the manager and below level start with 14 days/year; director and above level start with 19 days/year. Part-time with benefits employees receive time off based on the number of hours they work, with a minimum of 84 hours/year. All employees gain additional vacation time with further tenure.
    • Sick Time – All full-time employees receive 80 hours of sick time each year. Part-time with benefits employees receive time off based on the number of hours they work, with a minimum of 60 hours each year.
  • Other Benefits:
    • Complementary stand-by cruises, employee discounts on confirmed cruises, plus special rates for family and friends
    • Personal and professional learning and development resources including tuition reimbursement
    • On-site Fitness center at our Miami campus
About Us

Carnival Corporation & plc is the worlds largest leisure travel company, our mission to deliver unforgettable happiness to our guest through our diverse portfolio of leading cruise brands and island destinations, including Carnival Cruise Line, Holland America Line, Princess Cruises, and Seabourn in North America and Australia; P&O Cruises and Cunard Line in the United Kingdom; AIDA in Germany; Costa Cruises in Southern Europe.

Join us and embark on a career that offers not only the chance to grow professionally but also the opportunity to be part of a global community that makes a difference.

In addition to other duties/functions, this position requires full commitment and support for promoting ethical and compliant culture. More specifically, this position requires integrity, honesty, and respectful treatment of others, as well as a willingness to speak up when they see misconduct or have concerns.

Carnival Corporation & plc and Carnival Cruise Line is an equal employment opportunity/affirmative action employer. In this regard, it does not discriminate against any qualified individual on the basis of sex, race, color, national origin, religion, sexual orientation, age, marital status, mental, physical or sensory disability, or any other classification protected by applicable local, state, federal, and/or international law.

https://www.dol.gov/sites/dolgov/files/WHD/legacy/files/eppac.pdf

https://www.dol.gov/sites/dolgov/files/WHD/legacy/files/f... .pdf

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Specialist, Cybersecurity Risk
Sr. Specialist, Cybersecurity Risk

Carnival Corporation • Miami (FL)

On-site
USD 110,000 - 160,000
Health Benefits
401(k) plan
Paid Time Off
+1
Sr. Specialist, Cybersecurity Risk
Sr. Specialist, Cybersecurity Risk

Carnival Corporation & plc • Miami (FL)

Hybrid
USD 110,000 - 150,000
Health Benefits
401(k) plan
Paid Time Off
+3
Sr. Specialist, Cybersecurity Risk
Sr. Specialist, Cybersecurity Risk

CARNIVAL CRUISE LINES • Miami (FL)

Hybrid
USD 120,000 - 160,000
Health benefits
Paid time off
Employee discounts
Specialist, Cybersecurity Risk
Specialist, Cybersecurity Risk

Carnival Corporation & plc • Miami (FL)

Hybrid
USD 85,000 - 120,000
Health benefits
401(k) plan
Paid time off
+1
Specialist, Cybersecurity Risk
Specialist, Cybersecurity Risk

CARNIVAL CRUISE LINES • Miami (FL)

On-site
USD 85,000 - 120,000
Health benefits
401(k) with match
Employee stock purchase plan
+4
Program Manager, Cybersecurity Risk
Program Manager, Cybersecurity Risk

Carnival Corporation • Miami (FL)

On-site
USD 110,000 - 170,000
Health Benefits
401(k) Plan
Paid Time Off
+1
Program Manager, Cybersecurity Risk
Program Manager, Cybersecurity Risk

Carnival Corporation & plc • Miami (FL)

Hybrid
USD 120,000 - 180,000
Health benefits
401(k) plan
Paid Time Off
+3
Program Manager, Cybersecurity Risk Supply Chain
Program Manager, Cybersecurity Risk Supply Chain

Carnival Corporation & plc • Miami (FL)

Hybrid
USD 120,000 - 190,000
Health benefits
401(k) plan
Paid time off
+1
Program Manager, Cybersecurity Risk Supply Chain
Program Manager, Cybersecurity Risk Supply Chain

CARNIVAL CRUISE LINES • Miami (FL)

Hybrid
USD 140,000 - 180,000
Annual bonus program
Cruise discounts
On-site fitness center
Program Manager, Cybersecurity Risk
Program Manager, Cybersecurity Risk

CARNIVAL CRUISE LINES • Miami (FL)

Hybrid
USD 120,000 - 160,000
Health benefits
401(k) plan with company match
Paid time off & holidays
+1