Sr. Specialist, Cybersecurity Risk
Carnival Corporation
- Location
- Miami, FL, United States
- Work model
- On-Site
- Level
- Senior
- H-1B history
- 9 approvals (FY2023)
- Posted
- Sep 8, 2026
Skills
About this role
The Senior Specialist, Cybersecurity Risk is responsible for facilitating the enterprise cybersecurity risk management program. The role fulfills cybersecurity risk management processes that enable the organization to manage, control and report on cybersecurity risk in alignment with business objectives, regulatory requirements, and enterprise risk appetite. The ideal candidate possesses a broad understanding of IT cybersecurity governance, risk and compliance and people, process, and technology controls used to manage cybersecurity risk. Essential Functions: Identify, evaluate and monitor inherent and residual risks, recommend mitigation strategies, monitor mitigation activities, and support risk escalation and acceptance processes. Conduct and facilitate cybersecurity risk assessments for information and maritime operational technologies and infrastructure, applications and systems, business initiatives, vendors/supply chain, and operational processes. Maintain cybersecurity risk registers and ensure risks are appropriately identified, documented, updated, tracked, and escalated. Assist in identifying emerging threats, trends, and systemic risks that may impact organizational objectives. Support enterprise risk management integration and cybersecurity risk reporting activities. Monitor cybersecurity key risk indicators (KRIs), key performance indicators (KPIs), and program maturity metrics. Support the preparation and maintenance of cybersecurity risk scorecards, metrics, and reports for senior leadership and business stakeholders. Develop, maintain and revise Cybersecurity Risk Management Framework, playbooks, procedures, guidelines, documentation/reporting templates, and other relevant documentation. Support the administration and continuous improvement of the cybersecurity governance, security awareness, risk management, supply chain risk, compliance risk frameworks. Collaborate closely with Cybersecurity Governance, Cybersecurity Compliance, Operational Technology (OT) Cybersecurity Risk Management, IT, Maritime Cybersafety, Global Cybersecurity Services (GCS) Domain Leads, Sourcing, Legal, Privacy, and business stakeholders regarding cybersecurity requirements and contractual obligations. Communicate risk in clear business terms to technical and non-technical stakeholders. Identify opportunities to improve governance and cybersecurity risk management services programs, capabilities, effectiveness, operational resilience, and maturity. Support annual cybersecurity planning, strategic roadmap development, and maturity assessments. Analyze enterprise risk trends and identify systemic risks requiring leadership attention. Knowledge, Skills & Abilities: Scope: The position serves as a key liaison among cybersecurity, technology, business units, legal, privacy, audit, compliance, and enterprise risk management functions to promote consistent governance practices and effective cybersecurity risk management across the enterprise. Problem-solving: : This position requires strong analytical, communication, stakeholder management, and problem-solving skills. Impact: Role helps facilitate risk-based decisioning by key stakeholders and the organization. Ability to influence stakeholders and facilitate risk-based decision-making. Leadership: Facilitates cross-collaboration and serves as a subject matter expert on cybersecurity best practices and GCS services. For all roles: Knowledge: Understanding of workplace policies and procedures / Familiarity with team collaboration tools and techniques.
Skills
Strong time management and organizational skills Abilities: Ability to maintain reliable and consistent attendance / Capacity to be punctual and meet deadlines / Ability to collaborate effectively with colleagues and work as part of a team / Demonstrated professionalism in all interactions and tasks. Essential/Minimum qualifications: Core Competencies: Working knowledge of governance, risk and compliance (GRC). cybersecurity