Specialist, Cybersecurity Risk
Carnival Corporation
- Location
- Miami, FL, United States
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 9 approvals (FY2023)
- Posted
- Sep 8, 2026
Skills
About this role
The Cybersecurity Risk Specialist is responsible for supporting the organization’s cybersecurity first-party risk management and third party risk management program. The role supports risk management processes that enable the organization to manage, control and report on cybersecurity risk in alignment with business objectives, regulatory requirements, and enterprise risk appetite. The ideal candidate possesses a broad understanding of IT cybersecurity governance, risk and compliance and people, process, and technology controls used to manage cybersecurity risk. Essential Functions: Support the identification, assessment and monitoring of inherent and residual cybersecurity risks (first and third party), help recommend mitigation strategies, assist with monitoring mitigation activities, and support risk escalation and acceptance processes. Support the maintenance of cybersecurity risk registers and help ensure risks are appropriately identified, documented, updated, tracked, and escalated. Assist in identifying emerging threats, trends, and systemic risks that may impact organizational objectives. Support enterprise risk management integration and cybersecurity risk reporting activities. Monitor cybersecurity key risk indicators (KRIs), key performance indicators (KPIs), and programming maturity metrics. Prepare governance and risk management materials, executive dashboards, scorecards, metrics, and reports for senior leadership and business stakeholders. Collaborate with Cybersecurity Risk Management team, Operational Technology (OT) Cybersecurity Risk Management, Cybersecurity Governance, Cybersecurity Compliance, IT, Maritime Cybersafety, Global Cybersecurity Services (GCS) Domain Leads, Sourcing, Legal, Privacy, and business stakeholders regarding cybersecurity requirements and contractual obligations. Identify opportunities to improve cybersecurity risk management services programs, capabilities, effectiveness, operational resilience, and maturity. Support annual cybersecurity planning, strategic roadmap development, and maturity assessments. Knowledge, Skills & Abilities: Scope: The position supports the global Cybersecurity Risk Management programs (first party and supply chain) and Global Cybersecurity Services to promote effective cybersecurity risk management across the enterprise. Problem-solving: This position requires strong analytical, communication, stakeholder management, and problem-solving skills. Impact: Role helps facilitate risk-based decisioning by key stakeholders and the organization. Ability to act as a champion of cybersecurity and risk management best practices. Leadership: Supports cross-collaboration across Global Cybersecurity Services and the brands. For all roles: Knowledge: Understanding of workplace policies and procedures / Familiarity with team collaboration tools and techniques.
Skills
Strong time management and organizational skills Abilities: Ability to maintain reliable and consistent attendance / Capacity to be punctual and meet deadlines / Ability to collaborate effectively with colleagues and work as part of a team / Demonstrated professionalism in all interactions and tasks. Essential/Minimum qualifications: Core Competencies: Knowledge of governance, risk and compliance (GRC). cybersecurity principles, risk management principles and methodologies, and security control frameworks. Understanding of security concepts: security awareness, identity and access management (including privileged access, segregation of duties principles, and least privilege principles), vulnerability management, data protection, application security, network security, security architecture, and security operations. Strong written and verbal communication skills. Strong analytical, organizational, and documentation skills. Essential experience required: Bachelor’s degree in Cybersecurity, Information Security, Information Technology, Computer Science, Risk Management, Business Administration, or a