The Principal Analyst, IT Compliance is responsible for developing and documenting strategies which ensure that IT practices adhere to relevant laws, regulations, and industry standards, such as Sarbanes-Oxley (SOX) and Payment Card Industry (PCI) compliance. The Principal Analyst is a trusted advisor to senior management serving as the interface between IT, and both internal and external auditors. The Principal Analyst is the Subject Matter Expert in IT compliance, leading and conducting assessments of the most critical areas in the company, and presenting findings while also reviewing findings from internal and external auditors. The role will maintain absolute confidentiality of sensitive files, data and materials accessed, discussed, or observed while adhering to compliance policies and procedures.
Essential Functions:
Regulatory Compliance Assessment: Lead and oversee assessments conducted by more junior analysts, reviewing evidence demonstrating the organization’s compliance with applicable laws, regulations, and industry standards. Interview stakeholders to ensure compliance requirements are met and understood. Review policies, procedures, and controls to ensure alignment with requirements. Decision maker in working with cross functional teams to resolve compliance issues. Represent IT in communicating compliance related work product to internal and external stakeholders and executive leadership.
Research and Innovation: Function as a SME for IT Compliance. Stay abreast of emerging technologies, industry trends, and best practices. Research new tools, frameworks, and methodologies that can enhance solution designs and delivery. Evaluate and recommend appropriate solutions. Develop and communicate technology roadmaps. Review and improve tools, methods, processes, and procedures.
Compliance Monitoring and Reporting: Lead ongoing compliance activities, track regulatory changes, and prepare reports for management and regulatory agencies. Document compliance findings, issues, and serve as the decision maker for remediation efforts. Conduct impact assessments to determine the impact of regulatory changes and report findings to leadership. Assess compliance-related risks and lead the development of risk mitigation strategies. Stay abreast of regulatory changes and industry developments to ensure compliance programs remain current and effective. Build processes that drive automation and continuous compliance monitoring
Internal and External Audits and Reviews: Conduct internal assessments and reviews to evaluate the effectiveness of controls and identify areas for improvement. Review access controls, data protection measures, and security configurations. Lead the response to both Internal and External Audits and other stakeholder's findings and inquiries, preparing and presenting official documentation where appropriate.
Training and Awareness: Act as the top expert in compliance policies, standards, and procedures. Provide training and awareness programs to educate analyst team and stakeholders about compliance requirements and best practices.
Policy and Procedure Development: Takes the lead in developing, reviewing, and update IT policies, procedures, and standards to address compliance requirements. Reviews and approves documents such as acceptable use policies and data retention policies plans . Represents the department in communicating policies and procedures to stakeholders and executive leadership.
Vendor and Third-Party Compliance Management: Provide oversight and decision making in vendor selection, assess the compliance of vendors and third-party service providers to ensure they meet all security and regulatory requirements. Oversee audits of third-party service providers and lead the work to resolve vendor issues.
Performs other duties as assigned
Qualifications:
Bachelor's Degree in information technology, computer science, or related field or related equivalent work experience
7 years’ experience:
- As an Auditor/assessor in a regulatory environment.
- Conducting assessments specific to PCI and SOX.
- Applying access controls and IAM principles.
- Implementing and assessing segregation or separations of duties
- Working in a compliance role as part of a large Information Technology department.
- Documenting and communicating regulatory requirements, standards, policies, procedures, and vulnerabilities related to compliance.
- Leading critical compliance projects.
5+ years experience:
- Participating in cross-functional technology teams.
- Planning and managing large projects.
- Auditor for IT systems
Required Certifications:
- CISA (Certified Information Systems Auditor) or CIA (Certified Internal Audit)
Preferred certifications:
- PMP (Project Management Professional)
- CISM (Certified Information Security Manager)
- CFSA (Certified Financial Systems Analyst)
- CITGCP (Certified IT General Controls Practitioner
- CSOXI (Certified Sarbanes Oxley Act Practitioner)
- PCIP (Payment Card Industry Professional)
- CISSP (Certified Information Systems Security Professional)
Preferred Experience:
- 1+ year in the cruise and/or travel industry
Knowledge, Skills, and Abilities:
- Expert level knowledge of systems architecture and network applications and protocols, configuration, logging, monitoring, and administration to understand impacts on compliance.
- Ability to support a multisite enterprise environment.
- Recognized Strategic Authority in the field of regulatory and security standards and requirements including PCI, SOX and GDPR.
- Expertise in Cybersecurity frameworks such as NIST CSF.
- Ability to engage and manage compliance projects to a successful outcome.
- Intermediate-to-advanced technical knowledge across cloud platforms (AWS, Azure, GCP), IAM/PAM systems, Operating Systems (Linux/Windows), Databases and DevOps/CI-CD pipelines to support control validation and risk.
- Ability to develop dashboards, reports, etc. that can be consumed by executives.
- Advanced skills in critical thinking, creative problem solving, and root cause analysis with the ability to lead teams through this process.
- Flexibility to adjust to changing priorities and manage multiple deadlines.
- Outstanding analytical and attention to detail with exceptional business acumen.
- Ability to manage tight deadlines, prioritize workload and achieve exceptional results.
- Ability to write and review comprehensive and concise technical reports and presentations to be consumed by non-technical individuals.
- Ability to create PowerPoint presentations that are informative and engaging and deliver them to various audiences including executive management. Comfortable presenting to senior executives.
- Exceptional communication, team building, conflict management, and organizational skills.
- Excellent track record of working collaboratively with cross-functional teams to achieve common goals and drive exceptional results.
- Proficiency in MS Office
- Proven ability to quickly learn and teach new technologies and concepts.
- Demonstrated capability in managing organizational dynamics.
Physical Demands: Must be able to remain in a stationary position at a desk and/or computer for extended periods of time.
Travel: Less than 25% non-shipboard travel likely
Work Conditions: Work primarily in a climate-controlled environment with minimal safety/health hazard potential.
This position is classified as “remote.” As a remote role, it allows employees to work full-time from their home. It may also require regular travel to Carnival headquarters in Miami, FL for in-office collaboration. Sourcing of candidates is primarily done in Carnival’s remote hubs of Orlando, Tampa, Atlanta, Houston, and Dallas. If the search is extended past those areas, candidates must be located in one of the following U.S. states: FL, GA, TX and NC
At Carnival, your total rewards package is much more than your base salary. All non-sales roles participate in an annual cash bonus program, while sales roles have an incentive plan. Director and above roles may also be eligible to participate in Carnival’s discretionary equity incentive plan. Plus, Carnival provides comprehensive and innovative benefits to meet your needs, including:
- Health Benefits:
- Cost-effective medical, dental and vision plans
- Employee Assistance Program and other mental health resources
- Additional programs include company paid term life insurance and disability coverage
- Financial Benefits:
- 401(k) plan that includes a company match
- Employee Stock Purchase plan
- Paid Time Off:
- Holidays – All full-time and part-time with benefits employees receive days off for 8 company-wide holidays, plus 2 additional floating holidays to be taken at the employee’s discretion.
- Vacation Time – All full-time employees at the manager and below level start with 14 days/year; director and above level start with 19 days/year. Part-time with benefits employees receive time off based on the number of hours they work, with a minimum of 84 hours/year. All employees gain additional vacation time with further tenure.
- Sick Time – All full-time employees receive 80 hours of sick time each year. Part-time with benefits employees receive time off based on the number of hours they work, with a minimum of 60 hours each year.
- Other Benefits:
- Complementary stand-by cruises, employee discounts on confirmed cruises, plus special rates for family and friends
- Personal and professional learning and development resources including tuition reimbursement
#CCL
#LI-EJ
#LI-Remote
About UsAbout Us
At Carnival Cruise Line, our mission is to consistently deliver safe, fun, and memorable vacations at a great value. As the world’s most popular cruise line, we offer a variety of unique experiences across our fleet, ensuring that every voyage is filled with excitement and discovery. From world-class entertainment and dining to exploring stunning destinations, we create lasting memories for our guests while maintaining a dedication to the places we visit and the lives we touch.
Join us and embark on a career that offers not only the chance to grow professionally but also the opportunity to be part of a global community that makes a difference.
In addition to other duties/functions, this position requires full commitment and support for promoting ethical and compliant culture. More specifically, this position requires integrity, honesty, and respectful treatment of others, as well as a willingness to speak up when they see misconduct or have concerns.
Carnival Corporation and Carnival Cruise Line is an equal employment opportunity/affirmative action employer. In this regard, it does not discriminate against any qualified individual on the basis of sex, race, color, national origin, religion, sexual orientation, age, marital status, mental, physical or sensory disability, or any other classification protected by applicable local, state, federal, and/or international law.
https://www.dol.gov/sites/dolgov/files/WHD/legacy/files/eppac.pdf
https://www.dol.gov/sites/dolgov/files/WHD/legacy/files/fmlaen.pdf
Skills Required
- Bachelor's degree in information technology, computer science, or a related field, or equivalent work experience
- 7 years of experience as an auditor or assessor in a regulatory environment
- 7 years of experience conducting PCI and SOX assessments
- 7 years of experience applying access controls and IAM principles
- 7 years of experience implementing and assessing segregation of duties
- 7 years of experience in an IT compliance role within a large IT department
- 7 years of experience documenting and communicating regulatory requirements, standards, policies, procedures, and compliance vulnerabilities
- 7 years of experience leading critical compliance projects
- 5 or more years of experience participating in cross-functional technology teams
- 5 or more years of experience planning and managing large projects
- 5 or more years of experience auditing IT systems
- CISA or CIA certification
- PMP certification
- CISM certification
- CFSA certification
- CITGCP certification
- CSOXI certification
- PCIP certification
- CISSP certification
- At least 1 year of experience in the cruise or travel industry
- Expert knowledge of systems architecture, network applications and protocols, configuration, logging, monitoring, and administration
- Technical knowledge of cloud platforms, IAM/PAM systems, operating systems, databases, and DevOps/CI/CD pipelines
- Expertise in cybersecurity frameworks such as NIST CSF
- Proficiency in Microsoft Office
Carnival Corporation Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Carnival Corporation and has not been reviewed or approved by Carnival Corporation.
-
Wellbeing & Lifestyle Benefits — Travel perks such as complimentary standby and discounted confirmed cruises, along with wellness resources and an on‑site gym in Miami, add distinctive lifestyle value to the total package.
-
Healthcare Strength — Medical, dental, and vision coverage combined with mental‑health/EAP resources and wellness programs provide comprehensive health support for eligible roles.
-
Leave & Time Off Breadth — U.S. corporate postings outline structured vacation, sick time, and company holidays, indicating clear and predictable time‑off provisions.
Carnival Corporation Insights
What We Do
Carnival Corporation & plc is a global cruise company and one of the largest vacation companies in the world. Our portfolio of leading cruise brands includes Carnival Cruise Lines, Holland America Line, Princess Cruises and Seabourn in North America; P&O Cruises (UK), and Cunard in the United Kingdom; AIDA Cruises in Germany; Costa Cruises in Southern Europe; Iberocruceros in Spain; and P&O Cruises (Australia) in Australia. These brands, which comprise the most recognized cruise brands in North America, the United Kingdom, Germany and Italy, offer a wide range of holiday and vacation products to a customer base that is broadly varied in terms of cultures, languages and leisure-time preferences. We also own a tour company that complements our cruise operations: Holland America Princess Alaska Tours in Alaska and the Canadian Yukon. Combined, our vacation companies attract 10 million guests annually.









