Sr. Specialist, Cybersecurity Risk

Posted Yesterday
Be an Early Applicant
Miami, FL, USA
Hybrid
Senior level
Manufacturing
The Role
Facilitates the enterprise cybersecurity risk management program by conducting risk assessments, maintaining risk registers, monitoring mitigation activities, and preparing risk metrics and reports. Develops governance frameworks, playbooks, and documentation while supporting compliance, supply chain risk, maturity assessments, and strategic planning. Collaborates with cybersecurity, technology, legal, privacy, audit, and business stakeholders to communicate risks and enable informed decision-making.
Summary Generated by Built In

The Senior Specialist, Cybersecurity Risk is responsible for facilitating the enterprise cybersecurity risk management program. The role fulfills cybersecurity risk management processes that enable the organization to manage, control and report on cybersecurity risk in alignment with business objectives, regulatory requirements, and enterprise risk appetite. The ideal candidate possesses a broad understanding of IT cybersecurity governance, risk and compliance and people, process, and technology controls used to manage cybersecurity risk.

 

Essential Functions:

  • Identify, evaluate and monitor inherent and residual risks, recommend mitigation strategies, monitor mitigation activities, and support risk escalation and acceptance processes. Conduct and facilitate cybersecurity risk assessments for information and maritime operational technologies and infrastructure, applications and systems, business initiatives, vendors/supply chain, and operational processes.

  • Maintain cybersecurity risk registers and ensure risks are appropriately identified, documented, updated, tracked, and escalated. Assist in identifying emerging threats, trends, and systemic risks that may impact organizational objectives.

  • Support enterprise risk management integration and cybersecurity risk reporting activities. Monitor cybersecurity key risk indicators (KRIs), key performance indicators (KPIs), and program maturity metrics. Support the preparation and maintenance of cybersecurity risk scorecards, metrics, and reports for senior leadership and business stakeholders.

  • Develop, maintain and revise Cybersecurity Risk Management Framework, playbooks, procedures, guidelines, documentation/reporting templates, and other relevant documentation. Support the administration and continuous improvement of the cybersecurity governance, security awareness, risk management, supply chain risk, compliance risk frameworks.

  • Collaborate closely with Cybersecurity Governance, Cybersecurity Compliance, Operational Technology (OT) Cybersecurity Risk Management, IT, Maritime Cybersafety, Global Cybersecurity Services (GCS) Domain Leads, Sourcing, Legal, Privacy, and business stakeholders regarding cybersecurity requirements and contractual obligations. Communicate risk in clear business terms to technical and non-technical stakeholders.

  • Identify opportunities to improve governance and cybersecurity risk management services programs, capabilities, effectiveness, operational resilience, and maturity. Support annual cybersecurity planning, strategic roadmap development, and maturity assessments. Analyze enterprise risk trends and identify systemic risks requiring leadership attention.

 

Knowledge, Skills & Abilities:

  • Scope: The position serves as a key liaison among cybersecurity, technology, business units, legal, privacy, audit, compliance, and enterprise risk management functions to promote consistent governance practices and effective cybersecurity risk management across the enterprise.

  • Problem-solving: : This position requires strong analytical, communication, stakeholder management, and problem-solving skills.

  • Impact: Role helps facilitate risk-based decisioning by key stakeholders and the organization. Ability to influence stakeholders and facilitate risk-based decision-making.

  • Leadership: Facilitates cross-collaboration and serves as a subject matter expert on cybersecurity best practices and GCS services.

 

For all roles:

  • Knowledge: Understanding of workplace policies and procedures / Familiarity with team collaboration tools and techniques.

  • Skills: Strong time management and organizational skills

  • Abilities: Ability to maintain reliable and consistent attendance / Capacity to be punctual and meet deadlines / Ability to collaborate effectively with colleagues and work as part of a team / Demonstrated professionalism in all interactions and tasks.

 

Essential/Minimum qualifications:

Core Competencies:

  • Working knowledge of governance, risk and compliance (GRC). cybersecurity principles, risk management principles and methodologies, and security control frameworks.

  • Understanding of security concepts: security awareness, identity and access management (including privileged access, segregation of duties principles, and least privilege principles), vulnerability management, data protection, application security, network security, security architecture, and security operations.

  • Risk Appetite and Risk Tolerance Alignment

  • Issue Management and Remediation Oversight

  • Performance Metrics and Reporting

  • Governance Document Administration

  • Excellent written and verbal communication skills. 

  • Strong analytical, organizational, and documentation skills. 

 

Essential experience required:

  • Bachelor’s degree in Cybersecurity, Information Security, Information Technology, Computer Science, Risk Management, Business Administration, or a related field.

  • 2-5 years of experience in cybersecurity, information security, IT risk management, governance, or related disciplines.

  • Experience conducting risk identification, assessment. monitoring and reporting, control reviews, or compliance assessments.

  • Experience developing guidance documentation and senior management reporting.

  • Preferred Experience:

  • Professional certifications such as: CRISC (Certified in Risk and Information Systems Control), CISSP (Certified Information Systems Security Professional), CISA (Certified Information Systems Auditor), Security+, CGRC (Certified in Governance, Risk and Compliance)

  • Experience with GRC platforms such as LogicGate, Archer or ServiceNow IRM.

  • Familiarity with regulatory and privacy requirements such as SOX, PCI DSS, GDPR, CCPA, CIS, SEC cybersecurity regulations, or other industry-specific requirements.

  • Knowledge of third-party risk management and supplier cybersecurity assessments.

 

Travel: No or very little travel likely

Work Conditions: Work primarily in a climate-controlled environment with minimal safety/health hazard potential.

Physical Demands: Must be able to remain in a stationary position at a desk and/or computer for extended periods of time.

 

This position is classified as “in-office.”  As an in-office role, it requires employees to work from a designated Carnival office in South Florida Monday through Thursday each week. Employees may work from their homes on Fridays.  Candidates must be located in (or willing to relocate to) the Miami/Ft. Lauderdale area. 

 

Offers to selected candidates will be made on a fair and equitable basis, taking into account specific job-related skills and experience.   

 

At Carnival, your total rewards package is much more than your base salary. All non-sales roles participate in an annual cash bonus program, while sales roles have an incentive plan. Director and above roles may also be eligible to participate in Carnival’s discretionary equity incentive plan. Plus, Carnival provides comprehensive and innovative benefits to meet your needs, including: 

 

  • Health Benefits: 
    • Cost-effective medical, dental and vision plans 
    • Employee Assistance Program and other mental health resources 
    • Additional programs include company paid term life insurance and disability coverage  
  • Financial Benefits: 
    • 401(k) plan that includes a company match 
    • Employee Stock Purchase plan 
  • Paid Time Off 
    • Holidays – All full-time and part-time with benefits employees receive days off for 8 company-wide holidays, plus 2 additional floating holidays to be taken at the employee’s discretion.  
    • Vacation Time – All full-time employees at the manager and below level start with 14 days/year; director and above level start with 19 days/year.  Part-time with benefits employees receive time off based on the number of hours they work, with a minimum of 84 hours/year.  All employees gain additional vacation time with further tenure. 
    • Sick Time – All full-time employees receive 80 hours of sick time each year.  Part-time with benefits employees receive time off based on the number of hours they work, with a minimum of 60 hours each year.   
  • Other Benefits 
    • Complementary stand-by cruises, employee discounts on confirmed cruises, plus special rates for family and friends 
    • Personal and professional learning and development resources including tuition reimbursement  
    • On-site Fitness center at our Miami campus 

 

 

 

 

#Corp

#LI-HybridRemote

#LI-SH1

About Us

About Us

Carnival Corporation is the world’s largest leisure travel company, our mission to deliver unforgettable happiness to our guest through our diverse portfolio of leading cruise brands and island destinations, including Carnival Cruise Line, Holland America Line, Princess Cruises, and Seabourn in North America and Australia; P&O Cruises and Cunard Line in the United Kingdom; AIDA in Germany; Costa Cruises in Southern Europe.


Join us and embark on a career that offers not only the chance to grow professionally but also the opportunity to be part of a global community that makes a difference.


In addition to other duties/functions, this position requires full commitment and support for promoting ethical and compliant culture. More specifically, this position requires integrity, honesty, and respectful treatment of others, as well as a willingness to speak up when they see misconduct or have concerns.


Carnival Corporation and Carnival Cruise Line is an equal employment opportunity/affirmative action employer. In this regard, it does not discriminate against any qualified individual on the basis of sex, race, color, national origin, religion, sexual orientation, age, marital status, mental, physical or sensory disability, or any other classification protected by applicable local, state, federal, and/or international law. 


https://www.dol.gov/sites/dolgov/files/WHD/legacy/files/eppac.pdf

https://www.dol.gov/sites/dolgov/files/WHD/legacy/files/fmlaen.pdf

Skills Required

  • Bachelor’s degree in Cybersecurity, Information Security, Information Technology, Computer Science, Risk Management, Business Administration, or a related field
  • 2–5 years of experience in cybersecurity, information security, IT risk management, governance, or related disciplines
  • Experience conducting risk identification, assessment, monitoring, and reporting
  • Experience conducting control reviews or compliance assessments
  • Experience developing guidance documentation and senior management reporting
  • Professional certification such as CRISC, CISSP, CISA, Security+, or CGRC
  • Experience with GRC platforms such as LogicGate, Archer, or ServiceNow IRM
  • Familiarity with regulatory and privacy requirements such as SOX, PCI DSS, GDPR, CCPA, CIS, or SEC cybersecurity regulations
  • Knowledge of third-party risk management and supplier cybersecurity assessments
  • Strong written and verbal communication, analytical, organizational, documentation, stakeholder management, and problem-solving skills
  • Ability to work in-office in the Miami/Fort Lauderdale area Monday through Thursday
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Framingham, MA
26,000 Employees
Year Founded: 1951

What We Do

CCL Industries Inc. employs approximately 26,000 people operating 213 production facilities in 43 countries with corporate offices in Toronto, Canada, and Framingham, Massachusetts. CCL is the world’s largest converter of pressure sensitive and specialty extruded film materials for a wide range of decorative, instructional, functional and security applications for government institutions and large global customers in the consumer packaging, healthcare & chemicals, consumer electronic device and automotive markets. Extruded & laminated plastic tubes, aluminum aerosols & specialty bottles, folded instructional leaflets, precision decorated & die cut components, electronic displays, polymer bank note substrate and other complementary products and services are sold in parallel to specific end-use markets. Avery is the world’s largest supplier of labels, specialty converted media and software solutions for short-run digital printing applications for businesses and consumers available alongside complementary products sold through distributors, mass market stores and e-commerce retailers. Checkpoint is a leading developer of RF and RFID based technology systems for loss prevention and inventory management applications, including labeling and tagging solutions, for the retail and apparel industries worldwide. Innovia is a leading global producer of specialty, high-performance, multi-layer, surface-engineered films for label, packaging and security applications. The Company is partly backward integrated into materials science with capabilities in polymer extrusion, adhesive development, coating & lamination, surface engineering and metallurgy, deployed as needed across the four business segments.

Similar Jobs

Holland America Group Logo Holland America Group

Sr. Specialist, Cybersecurity Risk

Transportation • Travel • Hospitality
Hybrid
Miami, FL, USA
8898 Employees
Hybrid
Miami, FL, USA
2661 Employees

Square Logo Square

Strategic Account Manager

eCommerce • Fintech • Hardware • Payments • Software • Financial Services
Remote or Hybrid
Miami, FL, USA
12000 Employees
108K-203K Annually

Acquia Logo Acquia

Artificial Intelligence Engineer

AdTech • Cloud • Marketing Tech • Productivity • Software • Analytics • Automation
Easy Apply
Remote or Hybrid
United States
1100 Employees
150K-200K Annually

Similar Companies Hiring

Fortune Brands Innovations Thumbnail
Manufacturing
Deerfield, IL
10000 Employees
Rosendin Thumbnail
Other • Manufacturing
San Jose, CA
6219 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account