Director, Brand Information Security Officer

Other Jobs To Apply

No other job posts for this day.

The Director, Brand Information Security Officer (BISO) serves as the senior cybersecurity leader and trusted advisor for the assigned brand or business unit, acting as the primary liaison between Global Cybersecurity Services (GCS), technology leadership, and business stakeholders. The BISO acts on behalf of the brand to align its cybersecurity strategy, risk management, compliance activities, and operational security initiatives with corporate security objectives while ensuring the successful delivery of security services, capabilities, and outcomes. The BISO drives security maturity, facilitates risk-informed decision making, acts as a collaborative consultant on identified issues, and takes ownership for delivering measurable security and business results across four role tenants: Security Governance & Compliance; Incident Remediation & Vulnerability Management; GCS Service Delivery & Requirements Management; and Business Advisory, Security Consulting & Solution Ownership.

 

Essential Functions:

  • Security Governance, Risk & Compliance: Lead and oversee the brand’s cybersecurity strategy and governance program in alignment with Corporate and GCS security objectives. Ensure compliance with corporate security policies, standards, controls, and applicable regulatory requirements. Coordinate audits, assessments, control reviews, risk evaluations, maturity assessments, executive reporting, and security roadmap activities to strengthen the brand’s security posture. Drive the adoption of GCS control frameworks, policies, and standards within the brand.

  • Incident Remediation & Vulnerability Management: Oversee and coordinate the identification, assessment, prioritization, remediation, validation, and closure of security vulnerabilities, audit findings, control deficiencies, risks, and cybersecurity incidents. Drive remediation governance through accountability, tracking, escalation, root cause analysis, corrective action planning, lessons learned, and vulnerability reduction reporting. Support Incident Remediation through GCS Security Operations processes at the onset and throughout the Incident Life-Cycle, as needed. Deliver a value-added perspective on behalf of the brand and GCS functions to enhance Vulnerability Management reporting and provide a foundation for truth in reporting. Drive vulnerability management remediation within the brand to reduce risks to acceptable levels established by GCS in conjunction with Brand leadership. Provide insight into Incident Response playbooks and ensure geographical nuances for respective brands are incorporated.

  • GCS Service Delivery & Requirements Management: Serve as the primary representative and point of accountability for delivering current and future defined GCS services to the assigned brand or business unit. Gather, document, validate, prioritize, and communicate business, technology, security, compliance, and operational requirements to GCS and relevant corporate security domains. Champion the intake process and drive requirements gathering for GCS and Brand-specific initiatives.

  • Business Advisory, Security Consulting & Solution Ownership: Act as a trusted security advisor and consultant to business and technology leadership. Partner collaboratively with brand stakeholders to identify issues, understand challenges, evaluate risks, and develop pragmatic, business-aligned security solutions while taking ownership for driving issues and initiatives through completion.

  • Stakeholder Partnership & Cross-Functional Collaboration: Facilitate collaborative problem solving across brand teams, GCS security domains, technology organizations, legal, privacy, audit, compliance, maritime, operations, vendors, and other partners to align priorities, resolve barriers, and deliver intended security and business outcomes. Own and manage Change Management principles, including but not limited to partnership and communication, to promote GCS, Brand-specific, and overall company objectives.

  • Leadership, Resource Planning & Security Culture: Build, lead, mentor, and develop individual contributors, teams, matrixed resources, project teams, and external partners. Lead according to company values, leadership principles, and expected behaviors, fostering accountability, collaboration, inclusion, integrity, engagement, professional growth, and high-performance outcomes.

  • Metrics, Reporting, Budget & Continuous Improvement: Establish security metrics, executive dashboards, remediation and vulnerability management reporting, risk transparency, and service delivery measures. Support budgeting, forecasting, resource planning, vendor management, investment prioritization, and continuous improvement of GCS services and brand security maturity. Leverage, facilitate, and drive adoption of core metrics back to the brands.

 

Knowledge, Skills & Abilities:

  • Strong knowledge of cybersecurity governance, risk management, compliance, privacy, data protection, security control frameworks, and regulatory requirements relevant to a global, complex organization.

  • Practical understanding of IAM, GRC, security architecture, infrastructure security, application security, data security, cloud security, threat management, security operations, vulnerability management, incident response, incident remediation, business continuity, disaster recovery, and maritime / operational technology security where applicable.

  • Strong consulting, advisory, stakeholder management, negotiation, influence, collaboration, facilitation, executive communication, and requirements-gathering skills, with the ability to translate complex technical and regulatory concepts into business-focused priorities and decisions.

  • Demonstrated ability to define priorities, execute strategic initiatives, manage remediation, oversee vulnerability reduction, deliver GCS services, measure outcomes, and drive continuous improvement in security maturity.

  • Strong ownership mentality with a focus on accountability, inclusive leadership, practical security enablement, collaborative solutioning, ethical conduct, and measurable business and security outcome.

  • Strategic: Shape and recommend local security strategy, maturity priorities, security roadmaps, risk reduction plans, future GCS service adoption priorities, and investment priorities aligned to global security objectives and brand or business unit priorities.

  • Tactical: Translate corporate policies, standards, domain requirements, collected brand or business unit requirements, and future defined GCS services into brand or business unit execution plans, resource plans, remediation priorities, reporting cadences and stakeholder commitments.

  • Operational: Manage day-to-day security execution, issue escalation, vendor follow-up, incident coordination, remediation execution, vulnerability management follow-up, control implementation, status reporting, resource coordination and support for security SMEs.

 

 

For all roles:

  • Knowledge: Understanding of workplace policies and procedures / Familiarity with team collaboration tools and techniques.

  • Skills: Strong time management and organizational skills

  • Abilities: Ability to maintain reliable and consistent attendance / Capacity to be punctual and meet deadlines / Ability to collaborate effectively with colleagues and work as part of a team / Demonstrated professionalism in all interactions and tasks.

 

Essential/Minimum qualifications:

  • Bachelor’s degree in Information Security, Computer Science, Information Technology, Engineering, Business Administration, Business Informatics, or a related field required; equivalent work experience may be considered where appropriate. Master’s degree preferred. Professional certifications such as CISSP, CISM, CISA, CRISC, CCSP, GSLC, ISO 27001, C-CISO, or equivalent cybersecurity, risk, governance, or compliance certifications preferred.

 

Essential experience required:

  • 10+ years of progressive experience within cybersecurity, information security, IT risk, governance, compliance, or technology leadership roles. Demonstrated experience leading enterprise security programs within large and complex organizations, including audits, compliance initiatives, incident response, incident remediation, vulnerability management, cyber risk programs, requirements management, service delivery, stakeholder engagement, and cross-functional delivery in a matrixed environment.

 

Travel: Less than 25% non-shipboard travel likely

Work Conditions:Work primarily in a climate-controlled environment with minimal safety/health hazard potential.

Physical Demands: Must be able to remain in a stationary position at a desk and/or computer for extended periods of time.

 

This position is classified as “in-office.”  As an in-office role, it requires employees to work from a designated Carnival office in South Florida Monday through Thursday each week. Employees may work from their homes on Fridays.  Candidates must be located in (or willing to relocate to) the Miami/Ft. Lauderdale area. 

 

Offers to selected candidates will be made on a fair and equitable basis, taking into account specific job-related skills and experience.  

 

At Carnival, your total rewards package is much more than your base salary. All non-sales roles participate in an annual cash bonus program, while sales roles have an incentive plan. Director and above roles may also be eligible to participate in Carnival’s discretionary equity incentive plan. Plus, Carnival provides comprehensive and innovative benefits to meet your needs, including: 

 

  • Health Benefits: 
    • Cost-effective medical, dental and vision plans 
    • Employee Assistance Program and other mental health resources 
    • Additional programs include company paid term life insurance and disability coverage  
  • Financial Benefits: 
    • 401(k) plan that includes a company match 
    • Employee Stock Purchase plan 
  • Paid Time Off 
    • Holidays – All full-time and part-time with benefits employees receive days off for 8 company-wide holidays, plus 2 additional floating holidays to be taken at the employee’s discretion.  
    • Vacation Time – All full-time employees at the manager and below level start with 14 days/year; director and above level start with 19 days/year. Part-time with benefits employees receive time off based on the number of hours they work, with a minimum of 84 hours/year. All employees gain additional vacation time with further tenure. 
    • Sick Time – All full-time employees receive 80 hours of sick time each year. Part-time with benefits employees receive time off based on the number of hours they work, with a minimum of 60 hours each year.  
  • Other Benefits 
    • Complementary stand-by cruises, employee discounts on confirmed cruises, plus special rates for family and friends 
    • Personal and professional learning and development resources including tuition reimbursement  
    • On-site Fitness center at our Miami campus 

 

 

 

 

#Corp

#LI-Hybrid

#LI-LS1

About Us

Carnival Corporation & plc is the world’s largest leisure travel company, our mission to deliver unforgettable happiness to our guest through our diverse portfolio of leading cruise brands and island destinations, including Carnival Cruise Line, Holland America Line, Princess Cruises, and Seabourn in North America and Australia; P&O Cruises and Cunard Line in the United Kingdom; AIDA in Germany; Costa Cruises in Southern Europe.


Join us and embark on a career that offers not only the chance to grow professionally but also the opportunity to be part of a global community that makes a difference.

In addition to other duties/functions, this position requires full commitment and support for promoting ethical and compliant culture. More specifically, this position requires integrity, honesty, and respectful treatment of others, as well as a willingness to speak up when they see misconduct or have concerns.

Carnival Corporation & plc and Carnival Cruise Line is an equal employment opportunity/affirmative action employer. In this regard, it does not discriminate against any qualified individual on the basis of sex, race, color, national origin, religion, sexual orientation, age, marital status, mental, physical or sensory disability, or any other classification protected by applicable local, state, federal, and/or international law.

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...

Other Jobs To Apply

Entry Level Graphic Designer

Flight Attendant (PT + FT Available)

Teen-Friendly Remote Online Data Entry Specialist – Flexible Hours, Competitive Pay, Earn From Home with arenaflex

Amazon Picker/Packer

Apple Mac Management JAMF Engineer

Project Administrator- (Corporate Coding Resources) REMOTE

Remote Entry-Level Typing Specialist, $15/hr, No Experience Required – Full/Part-Time

Fulfillment Center Area Manager

Hiring Now - Work from Home - No Experience

Work from Home Product Testing $25-$45 per hour

Delivery Driver - Flexible Shift

Onsite Medical & Safety Specialist

Independent Delivery Driver - Flexible Scheduling

Area Manager, Early Career (2027) – GA, KY, TN (Fulfillment & Operations)

Cloud Data Center Technician - 24/7 Ops & Travel

Dock Associate in Tracy, California ($20.00)

Mixing Center - Warehouse Associate

flex driver

Amazon DOT Delivery Driver(Professional Driving Experience Required) $22.25

Delivery Driver Helper (Amazon Packages)

Area Operations Manager - Fast-Paced Fulfillment

Medical Assistant - Hybrid (Work From Home/Clinic)

Customer Service Rep - Work From Home (PT/FT)

[Remote-Position] YouTube Content Moderator Jobs Remote $27Hr

Claims Specialist- Anchorage, AK (Hybrid)

Customer Service Agent - Graveyard Shift (Work From Home)

Customer Service - Work from home ($250 Bonus)

Weekend driver/courier (part-time) | North Miami Beach

Easy Online Typing Jobs - Work at Your Own Schedule

Immediate Start Costco Working From Home , Careers At Costco

Service Desk Analyst I — Onsite IT Support & Onboarding

Join Today: Delta Airlines Careers Remote Customer Service, Delta

Investment Finance Expert - Valuation - AI Trainer

Delta Airlines Online Careers Remote Jobs At Home (No Experience/Entry Level)

Remote Entry-Level Customer Support – No Experience Required

Netflix Remote Jobs No Experience $30/Hour -

Entry Level Chat Support Specialist (Fully Remote)

Remote Out of Office Position / Data Entry (Hiring Immediately)

Part-time Evening Phone Coordinator

Customer Service Representative Agent Work From Home - Part Time Focus Group Panelists

_Fully Remote Position (Flexible & Beginner Friendly) Start ASAP + Bonuses

Delta Remote Jobs (Data Entry)- Hiring Now

Programmer - AI Trainer

AMAZON Walker Delivery

Amazon Customer Service - United States - Work From Home

Home office - Nmet nyelv? banking support munkatrs (m/w/d)

Fulfillment Center Lead - Operations & Training

Frito-Lay - Warehouser/Material Handler $18-$26/hr

Distribution Analyst

Hospital Response Advocate- On Call