Program Manager, Cybersecurity Risk
Job Fit Check
Base Career helps you apply smarter for this job.
Full Job Posting
The Cybersecurity Risk Program Manager is responsible for driving the execution and continuous improvement of the enterprise Cybersecurity Risk Management Program across a global portfolio of operating companies and brands. This role serves as the operational driver for cybersecurity risk governance, coordinating and facilitating risk management activities across multiple business units, geographic regions, and technology organizations to ensure consistent identification, assessment, prioritization, treatment, and reporting of cybersecurity risks.
The Cybersecurity Risk Program Manager partners closely with Governance, Compliance, Global Cybersecurity Service domains, Information Technology, Privacy, Legal, Internal Audit, Sourcing, and business leadership to drive a consistent and scalable cybersecurity risk management program that aligns with the organization's cybersecurity strategy, enterprise cybersecurity risk framework, and business objectives.
This position requires strong program management, stakeholder engagement, analytical, and communication skills to coordinate complex, cross-functional initiatives across a global enterprise while enabling informed, risk-based decision making.
Cybersecurity Risk Program Leadership
Drive the day-to-day execution of the global Cybersecurity Risk Management Program and operational functions.
Ensure the development and maintenance of the cybersecurity risk management framework, operating model, processes, procedures, and governance documentation.
Coordinate enterprise cybersecurity risk assessment activities across applications, infrastructure, cloud services, operational technology, third-party providers, and business initiatives.
Drive continuous improvement of the cybersecurity risk program through process optimization, automation, and governance maturity initiatives.
Enterprise Risk Operations
Facilitate and coordinate maintenance of the Enterprise Cybersecurity Risk Register and IT Cybersecurity Risk Register to ensure risks are appropriately documented, assessed, prioritized, and treated.
Coordinate the lifecycle of cybersecurity risks, including identification, analysis, treatment, acceptance, monitoring, and closure.
Facilitate risk review meetings with business, technology, and cybersecurity stakeholders.
Track remediation plans, risk acceptance decisions, and mitigation progress.
Monitor emerging cyber threats and technology risks that may impact enterprise risk exposure.
Cross-Brand Risk Coordination
Serve as the central coordinator for cybersecurity risk activities across multiple global brands and operating companies.
Promote standardized risk assessment methodologies while accommodating business-specific regulatory and operational requirements.
Facilitate collaboration between corporate cybersecurity teams and brand-level security organizations.
Share risk trends, lessons learned, and leading practices across the enterprise.
Support integration of acquired businesses into the enterprise cybersecurity risk management program.
Program Management
Develop and manage annual cybersecurity risk program roadmaps, milestones, deliverables, and operational plans.
Coordinate cross-functional workstreams supporting enterprise cybersecurity risk initiatives.
Maintain program schedules, action registers, dependencies, and issue logs.
Monitor program performance, resource needs, and operational metrics.
Support strategic cybersecurity initiatives by integrating risk management into project governance and technology delivery processes.
Executive Reporting & Metrics
Support the development of executive dashboards, key risk indicators (KRIs), key performance indicators (KPIs), and operational metrics for cybersecurity risk.
Assist with preparation of risk reports for executive leadership, cybersecurity governance committees, enterprise risk committees, and audit committees.
Communicate risk in clear business terms to technical and non-technical stakeholders.
Governance, Compliance & Continuous Improvement
Coordinate policy exception reviews, risk acceptance documentation, and governance approvals.
Support internal audits, external audits, customer assessments, and regulatory examinations by providing risk documentation and evidence.
Identify opportunities to enhance cybersecurity risk methodologies, reporting capabilities, and governance processes.
Support implementation and optimization of Governance, Risk, and Compliance (GRC) platforms.
Promote automation, workflow improvements, and standardized reporting across the cybersecurity risk program.
Benchmark program maturity against industry best practices and recommend strategic enhancements.
Knowledge, Skills & Abilities
Scope: Oversees enterprise-wide cybersecurity risk management activities, frameworks, assessments, reporting, governance, and cross-brand coordination.
Problem-solving: Addresses gaps in risk processes, remediation tracking, governance maturity, and cross-functional alignment to strengthen enterprise risk posture.
Impact: Improves organizational resilience by ensuring risks are consistently identified, prioritized, communicated, and mitigated across global operations.
Leadership: Influences diverse stakeholders, guides global teams, and drives adoption of standardized risk methodologies and governance improvements.
For all roles:
Knowledge: Understanding of workplace policies and procedures / Familiarity with team collaboration tools and techniques.
Skills
Strong time management and organizational skills
Abilities: Ability to maintain reliable and consistent attendance / Capacity to be punctual and meet deadlines / Ability to collaborate effectively with colleagues and work as part of a team / Demonstrated professionalism in all interactions and tasks.
Essential/Minimum qualifications:
Bachelor’s degree in Cybersecurity, Information Security, Information Technology, Risk Management, Computer Science, Business Administration, or a related field.
Strong understanding of cybersecurity principles, technology risk, governance processes, and control frameworks.
Excellent communication, facilitation, organizational, and stakeholder management skills.
Essential experience required:
5+ years of experience in cybersecurity, information security, enterprise risk management, governance, compliance, audit, or related disciplines.
3+ years of experience leading enterprise programs or cross-functional initiatives within a complex global organization.
Experience
managing project and program risks.
Demonstrated ability to manage multiple priorities across geographically dispersed teams.
Travel: No or very little travel likely
Work Conditions: Work primarily in a climate-controlled environment with minimal safety/health hazard potential.
Physical Demands: Must be able to remain in a stationary position at a desk and/or computer for extended periods of time.
This position is classified as “in-office.” As an in-office role, it requires employees to work from a designated Carnival office in South Florida Monday through Thursday each week.
Employees may work from their homes on Fridays.
Candidates must be located in (or willing to relocate to) the Miami/Ft.
Lauderdale area.
Offers to selected candidates will be made on a fair and equitable basis, taking into account specific job-related skills and experience.
At Carnival, your total rewards package is much more than your base salary.
All non-sales roles participate in an annual cash bonus program, while sales roles have an incentive plan.
Director and above roles may also be eligible to participate in Carnival’s discretionary equity incentive plan.
Plus, Carnival provides comprehensive and innovative benefits to meet your needs, including:
- Health Benefits:
- Cost-effective medical, dental and vision plans
- Employee Assistance Program and other mental health resources
- Additional programs include company paid term life insurance and disability coverage
- Financial Benefits:
- 401(k) plan that includes a company match
- Employee Stock Purchase plan
• Paid Time Off
- Holidays – All full-time and part-time with benefits employees receive days off for 8 company-wide holidays, plus 2 additional floating holidays to be taken at the employee’s discretion.
- Vacation Time – All full-time employees at the manager and below level start with 14 days/year; director and above level start with 19 days/year. Part-time with benefits employees receive time off based on the number of hours they work, with a minimum of 84 hours/year. All employees gain additional vacation time with further tenure.
- Sick Time – All full-time employees receive 80 hours of sick time each year. Part-time with benefits employees receive time off based on the number of hours they work, with a minimum of 60 hours each year.
- Other Benefits
- Complementary stand-by cruises, employee discounts on confirmed cruises, plus special rates for family and friends
- Personal and professional learning and development resources including tuition reimbursement
- On-site Fitness center at our Miami campus
#Corp
#LI-Hybrid
#LI-SH1
About Carnival Corporation & plc / Carnival Cruise Line (CCL/ABG)
World's largest leisure travel company and cruise line operator.
Visit company websiteApply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at Carnival Corporation & plc / Carnival Cruise Line (CCL/ABG)
Rehearsal and Wardrobe Operations Specialist
Fort Lauderdale, USA
One of the best-known names in cruising, Princess is the world’s leading international premium cruise line and tour company, carrying millions of guests each year to hundreds of destinations around the globe. We give our
Supervisor, Rehearsal Production Shows & Vocals
Davie, USA
The Supervisor is responsible for ensuring the seamless execution of large-scale cast changes through meticulous planning and coordination of shoreside and shipboard schedules and maintenance visits worldwide. This inclu
Marketing Coordinator
Miami, USA
One of the best-known names in cruising, Cunard is the world’s leading international premium cruise line, carrying millions of guests each year to hundreds of destinations around the globe. With parent company Carnival C
HR Business Partner
Seattle, USA
Holland America Line has been exploring the world since 1873. Our ships offer innovative features and enriching experiences focused on destination exploration and personalized travel, inviting guests to savor the journey
Manager, Dry Docks
Miami, USA
The Dry Dock Logistics Manager is responsible for planning and managing logistics functions to support the execution of dry docks and special projects for the CCL fleet. This role involves overseeing on-stie logistics pr
Cruise Vacation Planner (Remote and live near Miami)
Miami, USA
JOB SUMMARY: The Cruise Vacation Planner - Outbound Sales is a revenue-generating sales professional responsible for developing relationships with new-to-Cunard and returning guests and converting qualified opportunities
Fun Expert Agent( Remote in FL, GA, TX, NC)
Miami, USA
JOB SUMMARY: The Agent, Fun Expert identifies where the guest is in the booking journey, plans possible itineraries, answers vacation planning questions, notates guest needs and submits future leads to the outbound team.
Sr. Business Analyst, Global Cyber Security
Miami, USA
The Global Cyber Security Senior Business Analyst is responsible for appropriately applying business analysis tools and techniques to enable project success within the Global Cyber Security PMO team. This role involves t
Rehearsal and Wardrobe Operations Specialist
Fort Lauderdale, USA
Supervisor, Rehearsal Production Shows & Vocals
Davie, USA
Marketing Coordinator
Miami, USA
HR Business Partner
Seattle, USA
Manager, Dry Docks
Miami, USA
Cruise Vacation Planner (Remote and live near Miami)
Miami, USA
Fun Expert Agent( Remote in FL, GA, TX, NC)
Miami, USA
Sr. Business Analyst, Global Cyber Security
Miami, USA