yoinka

Director, Brand Information Security Officer

Carnival Corporation

Miami, FL, United StatesStaffH-1B sponsor company
Sign in to applyVerified 1h ago
Location
Miami, FL, United States
Work model
On-Site
Level
Staff
H-1B history
9 approvals (FY2023)
Posted
Aug 27, 2026

Skills

Cybersecurity

About this role

The Director, Brand Information Security Officer (BISO) serves as the senior cybersecurity leader and trusted advisor for the assigned brand or business unit, acting as the primary liaison between Global Cybersecurity Services (GCS), technology leadership, and business stakeholders. The BISO acts on behalf of the brand to align its cybersecurity strategy, risk management, compliance activities, and operational security initiatives with corporate security objectives while ensuring the successful delivery of security services, capabilities, and outcomes. The BISO drives security maturity, facilitates risk-informed decision making, acts as a collaborative consultant on identified issues, and takes ownership for delivering measurable security and business results across four role tenants: Security Governance & Compliance; Incident Remediation & Vulnerability Management; GCS Service Delivery & Requirements Management; and Business Advisory, Security Consulting & Solution Ownership. Essential Functions: Security Governance, Risk & Compliance: Lead and oversee the brand’s cybersecurity strategy and governance program in alignment with Corporate and GCS security objectives. Ensure compliance with corporate security policies, standards, controls, and applicable regulatory requirements. Coordinate audits, assessments, control reviews, risk evaluations, maturity assessments, executive reporting, and security roadmap activities to strengthen the brand’s security posture. Drive the adoption of GCS control frameworks, policies, and standards within the brand. Incident Remediation & Vulnerability Management: Oversee and coordinate the identification, assessment, prioritization, remediation, validation, and closure of security vulnerabilities, audit findings, control deficiencies, risks, and cybersecurity incidents. Drive remediation governance through accountability, tracking, escalation, root cause analysis, corrective action planning, lessons learned, and vulnerability reduction reporting. Support Incident Remediation through GCS Security Operations processes at the onset and throughout the Incident Life-Cycle, as needed. Deliver a value-added perspective on behalf of the brand and GCS functions to enhance Vulnerability Management reporting and provide a foundation for truth in reporting. Drive vulnerability management remediation within the brand to reduce risks to acceptable levels established by GCS in conjunction with Brand leadership. Provide insight into Incident Response playbooks and ensure geographical nuances for respective brands are incorporated. GCS Service Delivery & Requirements Management: Serve as the primary representative and point of accountability for delivering current and future defined GCS services to the assigned brand or business unit. Gather, document, validate, prioritize, and communicate business, technology, security, compliance, and operational requirements to GCS and relevant corporate security domains. Champion the intake process and drive requirements gathering for GCS and Brand-specific initiatives. Business Advisory, Security Consulting & Solution Ownership: Act as a trusted security advisor and consultant to business and technology leadership. Partner collaboratively with brand stakeholders to identify issues, understand challenges, evaluate risks, and develop pragmatic, business-aligned security solutions while taking ownership for driving issues and initiatives through completion. Stakeholder Partnership & Cross-Functional Collaboration: Facilitate collaborative problem solving across brand teams, GCS security domains, technology organizations, legal, privacy, audit, compliance, maritime, operations, vendors, and other partners to align priorities, resolve barriers, and deliver intended security and business outcomes. Own and manage Change Management principles, including but not limited to partnership and communication, to promote GCS, Brand-specific, and overall company objectives. Leadership,

Listing verified 1h ago. Applications go through the company's official careers site.

← Back to Yoinka

Director, Brand Information Security Officer at Carnival Corporation, Miami, FL, United States | Yoinka