Cybersecurity Compliance Manager
Carnival Corporation & plcAbout the role
The Manager, Cybersecurity Compliance is responsible for managing the overall Global Compliance Program, including but not limited to regulatory needs such as SOX, PCI-DSS, Data Privacy (GDPR/CCPA, etc) and best practices from NIST CSF, ISO, SOC2, etc. Additionally, this role is responsible for leading the compliance team’s continuing compliance initiatives and regulatory compliance testing initiatives. The Manager, Cybersecurity Compliance role will work with Operating Unit Security Leaders to ensure global compliance to all current regulatory guidelines and to GISCS policies and standards. This position will be responsible for enhancing the global compliance and cybersecurity controls as it relates to shipboard and shoreside environments. This role is required to measure and report KPIs, KRIs, audit findings, accomplishments, and publish to senior management and key stakeholders. Additionally, this position will serve as a liaison between internal and external auditor groups to integrate compliance regulation and controls to protect the company assets and data globally. This position will oversee a team of Compliance Analysts that are responsible for the execution of regulatory control testing, continuing compliance activities, and have a deep background in Information Security and compliance. This position will also be responsible for continuing to modernize existing security and compliance practices, specifically automating testing processes and shifting from a periodic testing approach to a continuous compliance model. This person will also lead a team in the planning and performance of annual assessments, testing, validation and overseeing the management of risks identified. This role is responsible for the reporting on current regulatory compliance and internal security policy compliance to senior leadership. This role entails developing a compliance team, either through direct or an indirect matrix reporting, to ensure the compliance framework is optimized and monitored. Also, the role is responsible for the performance of the team, and will need to recruit, train, coach, and develop the compliance team.
Essential Functions:
- Develop brand IT Compliance Framework to include (but not be limited to) SOX, PCI-DSS, Data Privacy (GDPR/CCPA, etc.), IMO etc. to achieve a strong compliance maturity model. Ownership of a formal Compliance Governance process which aligns and prioritizes Data Privacy and Security compliance initiatives. Develop and establish executive dashboard reporting on compliance events, findings, accomplishments and publish to senior management and key stakeholders.
- Manage the GISCS IT Compliance program, which includes conducting the annual validation and assessment including but not limited to SOX, PCI-DSS, Data Privacy Regulations (GDPR, CCPA, etc.), and external legal agreements; and determine scope, process, testing, documentation, reporting and remediation. Coordinate with IT Stakeholders, internal and external auditors, and Operating Unit Security Officers to ensure on-going IT compliance with published internal corporate policies and government regulations.
- Oversee the development and execution of GISCS’s annual and on-going PCI-DSS continuous compliance program, SOX ITGC testing, and GDPR compliance assessments plans to ensure the integrity, effectiveness, and efficiency of the compliance framework. Raise awareness to the Business and IT stakeholders of compliance requirements, regulations, and controls.
- Support the strategy to mature current Compliance practices to achieve departmental goal of shifting from “regulatory compliance” driven team to a Risk-based program and proactively work to identify potential gaps. Implement all necessary actions with relevant IT stakeholders and internal and external audit partners to achieve objectives of an effective compliance program and communicate to all key stakeholders and leadership.
- Define and identify requirement gaps and work in conjunction with Business and IT Management to develop and implement remediation and/or mitigation for control process improvements. Evaluate management responses and assess remediation plans. In partnership with Business and IT Management, drive consistent and measurable Compliance risk identification and management process for decision making by senior leadership across all Carnival Corporation brands.
- Proactively monitor & communicate changes in business processes and provide guidance and support to internal stakeholders. Support system implementations to ensure adequate requirements are incorporated, guidelines are followed, and process changes are documented.
- Identify opportunities for automation in current compliance activities and leverage technologies to modernize and streamline team workflows.
- Develop team’s skills, training requests, and career paths. Foster a strong team sp
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s