Jobs and Careers
CA

Sr. Governance Security GFIT Manager

Carnival Corporation & plc
United Statesfull_timeVerifiedPosted 8 Feb 2025

About the role

This candidate will be required to establish, develop, maintain, and enforce governance policies and procedures related to the global governance and security of the Carnival Global Financial Systems (CGFS) managed by GFiT.  As the primary contact to Brand Management regarding security and compliance requirements over the financial systems, this role has direct influence over the governance of Oracle EBS, Kofax/MarkView, OBIEE, APEX Applications (i.e., STAR, DSD, JE Review, GIM, etc.), BlackLine, FastPath, IT2, Robotic Process Automation, Hyperion Planning, FASTT, Lease Accelerator System, PowerBI, Carnival SEAS and any new applications/enhancements introduced into CGFS.  This candidate is responsible for the on-going analysis and identification of governance and compliance needs for incoming projects (i.e., Treasury HUB, AP Automation, application upgrades and enhancements, etc.) as well as with the implementation of new applications, functionality, or modules, through enhancements to the GFiT controls and overall process improvements. This role ensures adherence with Global Cybersecurity Services and global regulatory requirements (i.e., SOX, GDPR, CCPA, NIST, etc.).  The Sr Manager will interface with internal/external audit teams addressing audit requests managing any gap remediation as needed for the GFiT environment as well as the execution of third-party audit team Agreed Upon Procedures.

Essential Functions:

  • Responsible for technology-related compliance issues, including information security, business continuity and identity management for all the applications managed by GFiT. 
  • Manage the design and operationalization of any process or technology controls as required by applicable regulatory compliance frameworks. On-going analysis of governance and compliance needs and identification of enhancements to the GFiT internal controls, keep track of new regulations, industry best practices, implementation of new functionality or software, and implement continuous process improvement. Review security and role setups to identify sensitive access and provide guidance on role assignments to avoid potential segregation of duties issues or excess access being granted.           
  • Manage and address all inquiries, audit requests, walkthroughs, and access requests related to CGFS for the internal/external audit or Brand SOX teams.  Manage the third-party audit team responsible for performing Agreed Upon Procedures over the GFiT Change Management process up through the delivery of the final report. Perform the annual control effectiveness certification on behalf of the GFiT environment.        
  • Responsible for the monitoring and disposition of items requiring further review or action as identified via the Data Security Dashboard (DSD), application alerts and FastPath applications.
  • Responsible for the roll out and management of the various access reviews performed across CGFS.  Manage the STAR application and deployment of the user access reviews, identify and rollout potential enhancements to the application and conduct reviewer training across the organization.
  • Engage with the GFiT PMO team to identify and address governance items, security risks and controls for each project/enhancement.
  • Advise internal business stakeholders on security and compliance requirements and work in cross-functional partnership to help ensure those requirements are met.
  • Participate in and review the Business Continuity Plan/Disaster Recovery procedures and communications to support any BCP/DR processes, identify risks, address governance requirements, and determine/ensure appropriate approval captures.  Participate in BCP/DR events/tests to ensure coverage of the various Governance applications.    

Qualifications:

  • Bachelor’s degree in Accounting, Systems Management, Information Systems, or equivalent is required.
  • Minimum of 10 years of experience in ERP risk management or compliance of financial systems. Must be adept at building strong relationships with various business units to define and deliver application needs. Good communication and organizational skills are essential, as well as the ability to work well in a team and interact with all levels of management globally.
  • Should have expertise in regulatory compliance, IT audit, application security, policy compliance, general computer controls, and/or technology risk management.
  • Must be adept at building strong relationships with various internal controls-focused areas across the Organization. Good communication and organizational skills are essential, as well as the ability to work well in a team and interact wit

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Carnival Corporation & plc

View company profile →