Program Manager, Cybersecurity Risk Supply Chain

Posted Yesterday
Be an Early Applicant
Miami, FL, USA
Hybrid
Senior level
Manufacturing
The Role
Leads the global cybersecurity supply chain risk management program, coordinating risk assessments, governance, remediation, reporting, audits, and third-party risk activities across brands and regions. Maintains risk registers, facilitates stakeholder reviews, tracks risk acceptance and mitigation, supports GRC platform optimization, develops executive metrics, and drives process automation and continuous improvement. Requires strong cybersecurity governance, program management, communication, and cross-functional coordination skills in a complex global organization.
Summary Generated by Built In

The Cybersecurity Supply Chain Risk Program Manager is responsible for driving the execution and continuous improvement of the enterprise Cybersecurity Supply Chain Risk Management Program across a global portfolio of operating companies and brands. This role serves as the operational driver for Supply Chain cybersecurity risk governance, coordinating and facilitating Supply Chain risk management activities across multiple business units, geographic regions, and technology organizations to ensure consistent identification, assessment, prioritization, treatment, and reporting of cybersecurity risks.

 

Working within global Cybersecurity Risk team, the Cybersecurity Supply Chain Risk Program Manager partners closely with Governance, Compliance, Global Cybersecurity Service domains, Information Technology, Privacy, Legal, Internal Audit, Sourcing, and business leadership to drive a consistent and scalable supply chain risk management program that aligns with the organization's cybersecurity strategy, enterprise cybersecurity risk framework, and business objectives.

 

This position requires strong program management, stakeholder engagement, analytical, and communication skills to coordinate complex, cross-functional initiatives across a global enterprise while enabling informed, risk-based decision making.

 

Essential Functions:

Cybersecurity Supply Chain Risk Program Leadership

  • Drive the day-to-day execution of the global Cybersecurity Supply Chain Risk Management Program and operational functions.

  • Ensure the development and maintenance of the cybersecurity supply chain risk management framework, operating model, processes, procedures, and governance documentation.

  • Coordinate enterprise cybersecurity supply chain risk assessment activities across brands, third-party providers, and business initiatives.

  • Drive continuous improvement of the cybersecurity supply chain risk program through process optimization, automation, and governance maturity initiatives..

Enterprise Risk Operations

  • Facilitate and coordinate maintenance of the Enterprise Cybersecurity Risk Register and IT Cybersecurity Risk Register to ensure risks are appropriately documented, assessed, prioritized, and treated.

  • Coordinate the lifecycle of cybersecurity supply chain risks, including identification, analysis, acceptance, monitoring, and closure.

  • Facilitate risk review meetings with business, technology, and cybersecurity stakeholders.

  • Track risk acceptance decisions, due diligence and risk mitigation progress

  • Monitor emerging cyber threats and technology risks that may impact enterprise risk exposure.                                

Cross-Brand Risk Coordination

  • Serve as the central coordinator for cybersecurity supply chain risk activities across multiple global brands and operating companies.

  • Promote standardized supply chain risk assessment methodologies while accommodating a diverse set of vendor types and business-specific regulatory and operational requirements.

  • Facilitate collaboration between corporate cybersecurity teams and brand-level IT organizations.

  • Share risk trends, lessons learned, and leading practices across the enterprise.

  • Support integration of acquired businesses into the enterprise cybersecurity risk management program.

Executive Reporting & Metrics

  • Support the development of executive dashboards, key risk indicators (KRIs), key performance indicators (KPIs), and operational metrics for cybersecurity risk.

  • Assist with preparation of risk reports for executive leadership, cybersecurity governance committees, enterprise risk committees, and audit committees.

  • Communicate risk in clear business terms to technical and non-technical stakeholders.

Governance, Compliance & Continuous Improvement

  • Coordinate risk acceptance documentation.

  • Support internal audits, external audits, customer assessments, and regulatory examinations by providing risk documentation and evidence.

  • Coordinate cybersecurity risk assessments for vendors, suppliers, strategic partners, and outsourced service providers.

  • Track third-party remediation activities and ongoing risk monitoring.

  • Collaborate with Sourcing, Legal, Privacy, and business stakeholders to strengthen third-party and supply chain cybersecurity risk management.

  • Identify opportunities to enhance cybersecurity supply chain risk methodologies, reporting capabilities, and governance processes.

  • Support implementation and optimization of Governance, Risk, and Compliance (GRC) platform.

  • Promote automation, workflow improvements, and standardized reporting across the cybersecurity risk program.

  • Benchmark program maturity against industry best practices and recommend strategic enhancements.

 

Knowledge, Skills & Abilities:

  • Scope: Oversees enterprise-wide cybersecurity supply chain risk management activities, assessments, governance, reporting, and cross-brand coordination.

  • Problem-solving: Addresses gaps in supply chain risk processes, due diligence, remediation tracking, governance maturity, and cross-functional alignment.

  • Impact: Strengthens organizational resilience by ensuring supply chain risks are consistently identified, assessed, communicated, and mitigated across global operations.

  • Leadership: Influences diverse stakeholders, guides global teams, and drives adoption of standardized supply chain risk methodologies and governance improvements.

 

For all roles:

  • Knowledge: Understanding of workplace policies and procedures / Familiarity with team collaboration tools and techniques.

  • Skills: Strong time management and organizational skills

  • Abilities: Ability to maintain reliable and consistent attendance / Capacity to be punctual and meet deadlines / Ability to collaborate effectively with colleagues and work as part of a team / Demonstrated professionalism in all interactions and tasks.

 

Essential/Minimum qualifications:

  • Bachelor’s degree in Cybersecurity, Information Security, Information Technology, Risk Management, Computer Science, Business Administration, or a related field.

  • Strong understanding of cybersecurity principles, technology risk, governance processes, and control frameworks.

  • Excellent communication, facilitation, organizational, and stakeholder management skills.

 

Essential experience required:

  • 5+ years of experience in cybersecurity, information security, enterprise risk management, governance, compliance, audit, or related disciplines.

  • 3+ years of experience leading enterprise programs or cross-functional initiatives within a complex global organization.

  • Experience managing project and program risks.

  • Demonstrated ability to manage multiple priorities across geographically dispersed teams.

 

Travel: No or very little travel likely

Work Conditions: Work primarily in a climate-controlled environment with minimal safety/health hazard potential.

Physical Demands: Must be able to remain in a stationary position at a desk and/or computer for extended periods of time.

 

This position is classified as “in-office.”  As an in-office role, it requires employees to work from a designated Carnival office in South Florida Monday through Thursday each week. Employees may work from their homes on Fridays.  Candidates must be located in (or willing to relocate to) the Miami/Ft. Lauderdale area. 

 

Offers to selected candidates will be made on a fair and equitable basis, taking into account specific job-related skills and experience.   

 

At Carnival, your total rewards package is much more than your base salary. All non-sales roles participate in an annual cash bonus program, while sales roles have an incentive plan. Director and above roles may also be eligible to participate in Carnival’s discretionary equity incentive plan. Plus, Carnival provides comprehensive and innovative benefits to meet your needs, including: 

 

  • Health Benefits: 
    • Cost-effective medical, dental and vision plans 
    • Employee Assistance Program and other mental health resources 
    • Additional programs include company paid term life insurance and disability coverage  
  • Financial Benefits: 
    • 401(k) plan that includes a company match 
    • Employee Stock Purchase plan 
  • Paid Time Off 
    • Holidays – All full-time and part-time with benefits employees receive days off for 8 company-wide holidays, plus 2 additional floating holidays to be taken at the employee’s discretion.  
    • Vacation Time – All full-time employees at the manager and below level start with 14 days/year; director and above level start with 19 days/year.  Part-time with benefits employees receive time off based on the number of hours they work, with a minimum of 84 hours/year.  All employees gain additional vacation time with further tenure. 
    • Sick Time – All full-time employees receive 80 hours of sick time each year.  Part-time with benefits employees receive time off based on the number of hours they work, with a minimum of 60 hours each year.   
  • Other Benefits 
    • Complementary stand-by cruises, employee discounts on confirmed cruises, plus special rates for family and friends 
    • Personal and professional learning and development resources including tuition reimbursement  
    • On-site Fitness center at our Miami campus 

 

 

 

 

#Corp

#LI-HybridRemote

#LI-SH1

About Us

About Us

Carnival Corporation is the world’s largest leisure travel company, our mission to deliver unforgettable happiness to our guest through our diverse portfolio of leading cruise brands and island destinations, including Carnival Cruise Line, Holland America Line, Princess Cruises, and Seabourn in North America and Australia; P&O Cruises and Cunard Line in the United Kingdom; AIDA in Germany; Costa Cruises in Southern Europe.


Join us and embark on a career that offers not only the chance to grow professionally but also the opportunity to be part of a global community that makes a difference.


In addition to other duties/functions, this position requires full commitment and support for promoting ethical and compliant culture. More specifically, this position requires integrity, honesty, and respectful treatment of others, as well as a willingness to speak up when they see misconduct or have concerns.


Carnival Corporation and Carnival Cruise Line is an equal employment opportunity/affirmative action employer. In this regard, it does not discriminate against any qualified individual on the basis of sex, race, color, national origin, religion, sexual orientation, age, marital status, mental, physical or sensory disability, or any other classification protected by applicable local, state, federal, and/or international law. 


https://www.dol.gov/sites/dolgov/files/WHD/legacy/files/eppac.pdf

https://www.dol.gov/sites/dolgov/files/WHD/legacy/files/fmlaen.pdf

Skills Required

  • Bachelor's degree in Cybersecurity, Information Security, Information Technology, Risk Management, Computer Science, Business Administration, or a related field
  • Strong understanding of cybersecurity principles, technology risk, governance processes, and control frameworks
  • Excellent communication, facilitation, organizational, and stakeholder management skills
  • 5+ years of experience in cybersecurity, information security, enterprise risk management, governance, compliance, audit, or related disciplines
  • 3+ years of experience leading enterprise programs or cross-functional initiatives within a complex global organization
  • Experience managing project and program risks
  • Demonstrated ability to manage multiple priorities across geographically dispersed teams
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Framingham, MA
26,000 Employees
Year Founded: 1951

What We Do

CCL Industries Inc. employs approximately 26,000 people operating 213 production facilities in 43 countries with corporate offices in Toronto, Canada, and Framingham, Massachusetts. CCL is the world’s largest converter of pressure sensitive and specialty extruded film materials for a wide range of decorative, instructional, functional and security applications for government institutions and large global customers in the consumer packaging, healthcare & chemicals, consumer electronic device and automotive markets. Extruded & laminated plastic tubes, aluminum aerosols & specialty bottles, folded instructional leaflets, precision decorated & die cut components, electronic displays, polymer bank note substrate and other complementary products and services are sold in parallel to specific end-use markets. Avery is the world’s largest supplier of labels, specialty converted media and software solutions for short-run digital printing applications for businesses and consumers available alongside complementary products sold through distributors, mass market stores and e-commerce retailers. Checkpoint is a leading developer of RF and RFID based technology systems for loss prevention and inventory management applications, including labeling and tagging solutions, for the retail and apparel industries worldwide. Innovia is a leading global producer of specialty, high-performance, multi-layer, surface-engineered films for label, packaging and security applications. The Company is partly backward integrated into materials science with capabilities in polymer extrusion, adhesive development, coating & lamination, surface engineering and metallurgy, deployed as needed across the four business segments.

Similar Jobs

Holland America Group Logo Holland America Group

Program Manager

Transportation • Travel • Hospitality
Hybrid
Miami, FL, USA
8898 Employees
Hybrid
Miami, FL, USA
2661 Employees

TransUnion Logo TransUnion

Java Engineer

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
4 Locations
13000 Employees
90K-150K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Inside Sales Representative

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
11 Locations
40000 Employees
45K-85K Annually

Similar Companies Hiring

Fortune Brands Innovations Thumbnail
Manufacturing
Deerfield, IL
10000 Employees
Rosendin Thumbnail
Other • Manufacturing
San Jose, CA
6219 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account