What are the responsibilities and job description for the PCL Information Security Director position at Carnival Corporation?
TheCarnival Corporate Information Security Officer (BISO)serves a pivotal role in safeguarding the information assets and security posture of the assigned brand or business unit. The BISO acts as a strategic partner to both the business and the Office of the Chief Information Security Officer (CISO), ensuring that the brand or unit's IT activities align with corporate securityobjectives, industry standards, and regulatory requirements.Key responsibilities include :
1.Strategic Security Leadership : The BISO leads the development and implementation of security initiatives specific to the brand, driving security strategy and aligning it with the overarching security vision set by the global CISO. This includes managing security risks, setting priorities, and ensuring that security programs effectively mitigate potential threats while supporting business objectives.
2.Compliance and Risk Management : The BISO ensures that all security policies, standards, and practices are adhered to within the brand or business unit. This includes fostering a strong security culture, promoting awareness, and ensuring that security compliance is consistentlymaintained across all brand-related IT operations. The BISO works closely with legal, risk, and compliance teams to assess and mitigate risks, conduct regular audits, and respond to any gaps in compliance.
3.Guidance and Consultation for Brand / Operating Unit IT : As a trusted advisor, the BISO provides guidance on a wide range of security domains, such as access management, data protection, incident response, and security architecture. The role involves ensuring that the IT team has the necessary resources,expertise, and tools to implement effective security controls and meet regulatory and security requirements.
4.Brand-Specific Risk Identification and Mitigation : The BISO actively works toidentify security risks that are unique to the brand or business unit. This involves a detailed understanding of the brand's operations, technology stack, and potential threat landscape. The BISO then works to mitigate those risks through targeted initiatives, awareness programs, and collaboration with cross-functional teams, including operations, development, and infrastructureteams.
5.Collaboration with Global CISO : Reporting directly to the Global CISO, the BISO ensures that security efforts at the brand level are consistent with corporate security strategies and policies. The BISO provides regular reports to both the Global CISO and the Brand / Operating Unit Executives, highlighting compliance status,identified risks, and ongoing security initiatives. Thisrole is key infacilitating clear communication between the brand and corporate leadership, ensuring transparency in security posture and risk management.
6. Incident Response and Crisis Management : The BISO plays an integral rolein the event of a security breach or incident, ensuring prompt identification, containment, and resolution of security issues. The BISO coordinates with relevant stakeholders within the brand and across the organization to minimize impact and ensure that proper post-incident analysis and remediation plans are in place.
7.Continuous Improvement and Security Maturity : The BISO is committed to the continuous enhancement of the brand's security posture, driving ongoing security maturity initiatives. This includes staying ahead ofemerging threats, adopting best practices, and recommending improvements to existing security frameworks to adapt to the evolving landscape of cyber threats.
In summary, the Carnival BISO is a critical role that bridges the gap between corporate securityobjectives and the operational realities of the brand, ensuring robust protection of information assets, compliance with security policies, and the effective mitigation of security risks. Through close collaboration with IT, legal, compliance, and security teams, the BISO contributes to the overall security strategy and resilience of the organization.
Essential Functions :
- Prioritize, oversee, and manage security and compliance related projects and business-as-usual activities in the brand, ensuring successful execution and reporting. These projects and activities span across Identity and Access Management, Governance Risk and Compliance, Security Architecture, Maritime Safety, Infrastructure Application and Data Security, and Threat Management.1. Resource Allocation : Proposing and allocating funds for security tools, software, and hardware to protect the company's information assets.
Risk Management : Budgeting for risk assessments, penetration testing, and other security assessments to identify vulnerabilities and mitigate risks.
Compliance : Proposing and allocating funds for compliance efforts to meet legislative and regulatory requirements related to information security.
Continuous Improvement : Allocating funds for ongoing security improvements, such as security updates, patches, and upgrades to existing security infrastructure.
Qualifications :
Knowledge, Skills & Abilities :
Physical Demands : Must be able to remain in a stationary position at a desk and / or computer for extended periods of time. Requires regular movement throughout CCL facilities.
Travel : Less then 25% with non-shipboard travel likely
Work Conditions : Work primarily in a climate-controlled environment with minimal safety / health hazard potential.
This position is classified as "in-office." As an in-office role, it requires employees to work from a designated Carnival office in South Florida Tuesday through Thursday each week. Employees may work from their homes on Mondays and Fridays. Candidates must be located in (or willing to relocate to) the Miami / Ft. Lauderdale area.
Offers to selected candidates will be made on a fair and equitable basis, taking into account specific job-related skills and experience.
At Carnival, your total rewards package is much more than your base salary. All non-sales roles participate in an annual cash bonus program, while sales roles have an incentive plan. Director and above roles may also be eligible to participate in Carnival's discretionary equity incentive plan.Plus, Carnival provides comprehensive and innovative benefits to meet your needs, including :
Cost-effective medical, dental and vision plans
401(k) plan that includes a company match
Holidays - All full-time and part-time with benefits employees receive days off for 8 company-wide holidays, plus 2 additional floating holidays to be taken at the employee's discretion.
Complementary stand-by cruises, employee discounts on confirmed cruises, plus special rates for family and friends
LI-Hybrid
LI-SH1
About Us
Carnival Corporation & plc is the world's largest leisure travel company, our mission to deliver unforgettable happiness to our guests through our diverse portfolio of leading cruise brands and island destinations, including Carnival Cruise Line, Holland America Line, Princess Cruises, and Seabourn in North America and Australia; P&O Cruises and Cunard Line in the United Kingdom; AIDA in Germany; Costa Cruises in Southern Europe.
Join us and embark on a career that offers not only the chance to grow professionally but also the opportunity to be part of a global community that makes a difference.
In addition to other duties / functions, this position requires full commitment and support for promoting ethical and compliant culture. More specifically, this position requires integrity, honesty, and respectful treatment of others, as well as a willingness to speak up when they see misconduct or have concerns.
Carnival Corporation & plc and Carnival Cruise Line is an equal employment opportunity / affirmative action employer. In this regard, it does not discriminate against any qualified individual on the basis of sex, race, color, national origin, religion, sexual orientation, age, marital status, mental, physical or sensory disability, or any other classification protected by applicable local, state, federal, and / or international law.