Carnival Corporation
IT Compliance Analyst
Carnival Corporation, Miami, Florida, us, 33222
The Analyst, IT Compliance is an individual contributor role with accountability for ensuring the compliance posture as CCL follows the guidelines established for Carnival Corporation, the respective governing bodies and applicable federal and international laws and regulations. The resource supports the maintenance of n integrated programs with secure infrastructure to protect the integrity, confidentiality, and availability of Carnival Cruise Lines (CCL) information systems assets. The resource will interface with user community to ensure both understanding and compliance with regulatory requirements. The team member will recommend and monitors computing practices to ensure that individual and departmental access and rights, resources, and information are compliant The resource will be an active participant in annual assessments (SOX, PCI) and will also coordinate remediation of compliance gaps (SOX, PCI, EUGDPR, PII, etc.) and support the greater ecosystem in the event of security incidents including recovery, intrusions, and/or system abuses. The team member is required to maintain current knowledge of security and compliance trends and issues. The resource will support projects across the CCL organization.
Essential Functions:
Coordinateand execute remediation efforts arising from compliance deficiencies (Policies, SOX, PII, EUGDPR, CCPA, PCI, HIPPA, Pen tests, etc.) Effectively plan and manage information protection initiatives and projects to ensure that objectives, schedules and budgets are met.Review security and controls to address areas such as applications, databases, infrastructure, security administration, user identification and authentication, access to data, monitoring and reporting. Implement and enforce control framework related to CCL's regulatory and compliance standards (PCI, SOX, EUGDPR, CCPA, PII, HIPPA, etc.)Review and update CCL information security policies and procedures. Update compliance guidelines and standards for CCL applications, databases, infrastructure, networking systems and computing platforms.Evaluate security and control aspects of technologies including internally developed applications and defines security requirements to ensure compliance guidelines are met and maintained.Perform periodic compliance assessments of information applications and technology, analyze results, and develop action plans to mitigate risks. Manage the exception process for risks that cannot be remediated in stipulated timelines.Provide consultative services and awareness to business units regarding risks, standards of due care and appropriate information security safeguardsPerform other information system department functions as assigned by the CCL's Security and Compliance Manager.Qualifications:Bachelor's degree inComputer Science, Information Security, Information Systems / Technology, Engineering, Business, or Management/ Admin preferred3+ years ofrelated and progressively more responsible and expansive work experience in IT Security and Compliance disciplines required.3+ years of experience with minimum of 5 years in IT Security and Compliance preferredKnowledge, Skills and Abilities:Hands-onexpertise with supporting PCI Assessments and SOX audits Compliance controls reviews for applications and databases related to SOX, PCI, PII, EUGDPR, HIPPA, etc. Experience reviewing and updating IT policies, standards and guidelines from the lens of a compliance professional.Highly organized and effective time management skills including the ability to balance competing projects concurrently; asking questions and getting information in order to diagnose security related problem.Excellent written and verbal communication skills.Interpersonal skills at a level to function well in a wide range of administrative and management environments and a strong image of professional discipline.Proven ability as a member of an IT Compliance or Information Security team with a focus on compliance with the ability to communicate compliance related concepts to a broad range of technical and non-technical staff Proven ability as a project leader. Strong analytical and organizational skills with strong critical thinking and problem-solving abilities.High level of integrity and trust. Respects and maintains confidentiality of enterprise information including specified security plans and controls.abreast of current and emerging technical information security developments. Research, recommend and implement security tools and measures.Demonstrated experience with at least two security control frameworks (e.g. SOX, SOC 2, ISO, NIST, COSO, COBIT, etc.); Familiarity with common compliance standards (SOX, SOC2, PCI-DSS, GDPR, COSO, COBIT, NIST, and/or ISO 27001. Experience working directly with internal or external auditors for at least one of the listed standards. Hands-on experience with a variety of reporting operations and proceduresAttends meetings and compliance related conferences; Participates in employee focus groups and committees related to information security and compliance.Ability to plan, coordinate, and execute complex IT security and compliance assignments; design and applies tools, techniques, and procedures to maintain highest standards of IT Security and Compliance.Licenses/Certifications:Active certifications in one of the related areas of security and compliance such as CISA, CISM, CISSP, CRISC, GIAC, ISC, CEH, IAM, GSLC. Active certifications in one of the related areas of security and compliance such as CISA, CISM, CISSP, CRISC, GIAC, ISC, CEH, IAM, GSLC required.Physical Demands: Must be able to remain in a stationary position at a desk and/or computer for extended periods of time. Requires regular movement throughout CCL facilities.
Travel: Less than 25% shore-based travel
Work Conditions: Work primarily in a climate-controlled environment with minimal safety/health hazard potential.Other job specific working conditions.
This position is classified as "in-office." As an in-office role, it requires employees to work from a designated Carnival office in South Florida from Tuesday through Thursday. Employees may work from home on Mondays and Fridays. Some positions may require additional in-office time each week and final schedule is determined by your leader. Candidates must be located in (or willing to relocate to) the Miami/Ft. Lauderdale area.
Offers to selected candidates will be made on a fair and equitable basis, taking into account specific job-related skills and experience.
At Carnival, your total rewards package is much more than your base salary. All non-sales roles participate in an annual cash bonus program, while sales roles have an incentive plan. Director and above roles may also be eligible to participate in Carnival's discretionary equity incentive plan.Plus, Carnival provides comprehensive and innovative benefits to meet your needs, including:Health Benefits:
Cost-effective medical, dental and vision plansEmployee Assistance Program and other mental health resourcesAdditional programs include company paid term life insurance and disability coverage
Financial Benefits:
401(k) plan that includes a company matchEmployee Stock Purchase plan
Paid Time Off
Holidays - All full-time and part-time with benefits employees receive days off for 7 company-wide holidays, plus an additional floating holiday to be taken at the employee's discretion.Vacation Time - All full-time employees at the manager and below level start with 14 days/year; director and above level start with 19 days/year. Part-time with benefits employees receive time off based on the number of hours they work, with a minimum of 84 hours/year. All employees gain additional vacation time with further tenure.Sick Time - All full-time employees receive 80 hours of sick time each year. Part-time with benefits employees receive time off based on the number of hours they work, with a minimum of 60 hours each year.
Other Benefits
Complementary stand-by cruises, employee discounts on confirmed cruises, plus special rates for family and friendsPersonal and professional learning and development resources including tuition reimbursementOn-site preschool program and wellness center at our Miami campus
#LI-Hybrid
#LI-SH1
Carnival Corporation & plc is the world's largest leisure travel company, committed to creating exceptional experiences for its guests through a diverse range of cruise brands. The company operates several renowned cruise lines, including Carnival Cruise Line, Holland America Line, Princess Cruises, Seabourn, AIDA, and Costa Cruises. Carnival is known for its passion for excellence, guest satisfaction, and creating a work environment that fosters growth, teamwork, and personal fulfillment for its employees.
We are an equal opportunity employer, providing a work environment that encourages respect, inclusion, and diversity. Carnival is committed to creating a safe and supportive environment for all employees, free from discrimination and harassment. We offer extensive training programs, career advancement opportunities, and an inclusive work culture.
Carnival Corporation & plc is committed to adhering to all local, state, and federal labor laws, and provides its employees with the necessary resources to comply with regulatory requirements. We value diversity, equality, and transparency in all aspects of our operations.
For further information regarding our policies and compliance, please refer to the following resources:
FMLA Poster
EEO Poster
EPPA Poster
OFCCP EEO Supplement
Essential Functions:
Coordinateand execute remediation efforts arising from compliance deficiencies (Policies, SOX, PII, EUGDPR, CCPA, PCI, HIPPA, Pen tests, etc.) Effectively plan and manage information protection initiatives and projects to ensure that objectives, schedules and budgets are met.Review security and controls to address areas such as applications, databases, infrastructure, security administration, user identification and authentication, access to data, monitoring and reporting. Implement and enforce control framework related to CCL's regulatory and compliance standards (PCI, SOX, EUGDPR, CCPA, PII, HIPPA, etc.)Review and update CCL information security policies and procedures. Update compliance guidelines and standards for CCL applications, databases, infrastructure, networking systems and computing platforms.Evaluate security and control aspects of technologies including internally developed applications and defines security requirements to ensure compliance guidelines are met and maintained.Perform periodic compliance assessments of information applications and technology, analyze results, and develop action plans to mitigate risks. Manage the exception process for risks that cannot be remediated in stipulated timelines.Provide consultative services and awareness to business units regarding risks, standards of due care and appropriate information security safeguardsPerform other information system department functions as assigned by the CCL's Security and Compliance Manager.Qualifications:Bachelor's degree inComputer Science, Information Security, Information Systems / Technology, Engineering, Business, or Management/ Admin preferred3+ years ofrelated and progressively more responsible and expansive work experience in IT Security and Compliance disciplines required.3+ years of experience with minimum of 5 years in IT Security and Compliance preferredKnowledge, Skills and Abilities:Hands-onexpertise with supporting PCI Assessments and SOX audits Compliance controls reviews for applications and databases related to SOX, PCI, PII, EUGDPR, HIPPA, etc. Experience reviewing and updating IT policies, standards and guidelines from the lens of a compliance professional.Highly organized and effective time management skills including the ability to balance competing projects concurrently; asking questions and getting information in order to diagnose security related problem.Excellent written and verbal communication skills.Interpersonal skills at a level to function well in a wide range of administrative and management environments and a strong image of professional discipline.Proven ability as a member of an IT Compliance or Information Security team with a focus on compliance with the ability to communicate compliance related concepts to a broad range of technical and non-technical staff Proven ability as a project leader. Strong analytical and organizational skills with strong critical thinking and problem-solving abilities.High level of integrity and trust. Respects and maintains confidentiality of enterprise information including specified security plans and controls.abreast of current and emerging technical information security developments. Research, recommend and implement security tools and measures.Demonstrated experience with at least two security control frameworks (e.g. SOX, SOC 2, ISO, NIST, COSO, COBIT, etc.); Familiarity with common compliance standards (SOX, SOC2, PCI-DSS, GDPR, COSO, COBIT, NIST, and/or ISO 27001. Experience working directly with internal or external auditors for at least one of the listed standards. Hands-on experience with a variety of reporting operations and proceduresAttends meetings and compliance related conferences; Participates in employee focus groups and committees related to information security and compliance.Ability to plan, coordinate, and execute complex IT security and compliance assignments; design and applies tools, techniques, and procedures to maintain highest standards of IT Security and Compliance.Licenses/Certifications:Active certifications in one of the related areas of security and compliance such as CISA, CISM, CISSP, CRISC, GIAC, ISC, CEH, IAM, GSLC. Active certifications in one of the related areas of security and compliance such as CISA, CISM, CISSP, CRISC, GIAC, ISC, CEH, IAM, GSLC required.Physical Demands: Must be able to remain in a stationary position at a desk and/or computer for extended periods of time. Requires regular movement throughout CCL facilities.
Travel: Less than 25% shore-based travel
Work Conditions: Work primarily in a climate-controlled environment with minimal safety/health hazard potential.Other job specific working conditions.
This position is classified as "in-office." As an in-office role, it requires employees to work from a designated Carnival office in South Florida from Tuesday through Thursday. Employees may work from home on Mondays and Fridays. Some positions may require additional in-office time each week and final schedule is determined by your leader. Candidates must be located in (or willing to relocate to) the Miami/Ft. Lauderdale area.
Offers to selected candidates will be made on a fair and equitable basis, taking into account specific job-related skills and experience.
At Carnival, your total rewards package is much more than your base salary. All non-sales roles participate in an annual cash bonus program, while sales roles have an incentive plan. Director and above roles may also be eligible to participate in Carnival's discretionary equity incentive plan.Plus, Carnival provides comprehensive and innovative benefits to meet your needs, including:Health Benefits:
Cost-effective medical, dental and vision plansEmployee Assistance Program and other mental health resourcesAdditional programs include company paid term life insurance and disability coverage
Financial Benefits:
401(k) plan that includes a company matchEmployee Stock Purchase plan
Paid Time Off
Holidays - All full-time and part-time with benefits employees receive days off for 7 company-wide holidays, plus an additional floating holiday to be taken at the employee's discretion.Vacation Time - All full-time employees at the manager and below level start with 14 days/year; director and above level start with 19 days/year. Part-time with benefits employees receive time off based on the number of hours they work, with a minimum of 84 hours/year. All employees gain additional vacation time with further tenure.Sick Time - All full-time employees receive 80 hours of sick time each year. Part-time with benefits employees receive time off based on the number of hours they work, with a minimum of 60 hours each year.
Other Benefits
Complementary stand-by cruises, employee discounts on confirmed cruises, plus special rates for family and friendsPersonal and professional learning and development resources including tuition reimbursementOn-site preschool program and wellness center at our Miami campus
#LI-Hybrid
#LI-SH1
Carnival Corporation & plc is the world's largest leisure travel company, committed to creating exceptional experiences for its guests through a diverse range of cruise brands. The company operates several renowned cruise lines, including Carnival Cruise Line, Holland America Line, Princess Cruises, Seabourn, AIDA, and Costa Cruises. Carnival is known for its passion for excellence, guest satisfaction, and creating a work environment that fosters growth, teamwork, and personal fulfillment for its employees.
We are an equal opportunity employer, providing a work environment that encourages respect, inclusion, and diversity. Carnival is committed to creating a safe and supportive environment for all employees, free from discrimination and harassment. We offer extensive training programs, career advancement opportunities, and an inclusive work culture.
Carnival Corporation & plc is committed to adhering to all local, state, and federal labor laws, and provides its employees with the necessary resources to comply with regulatory requirements. We value diversity, equality, and transparency in all aspects of our operations.
For further information regarding our policies and compliance, please refer to the following resources:
FMLA Poster
EEO Poster
EPPA Poster
OFCCP EEO Supplement