Principal Analyst, IT Compliance @Carnival Corporation
Compliance
Salary unspecified
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 1mth ago

[Hiring] Principal Analyst, IT Compliance @Carnival Corporation

1mth ago - Carnival Corporation is hiring a remote Principal Analyst, IT Compliance. 💸 Salary: unspecified 📍Location: USA

Role Description

The Principal Analyst, IT Compliance is responsible for developing and documenting strategies which ensure that IT practices adhere to relevant laws, regulations, and industry standards, such as Sarbanes-Oxley (SOX) and Payment Card Industry (PCI) compliance. The Principal Analyst is a trusted advisor to senior management serving as the interface between IT, and both internal and external auditors.

The Principal Analyst is the Subject Matter Expert in IT compliance, leading and conducting assessments of the most critical areas in the company, and presenting findings while also reviewing findings from internal and external auditors. The role will maintain absolute confidentiality of sensitive files, data and materials accessed, discussed, or observed while adhering to compliance policies and procedures.

Essential Functions:

  • Regulatory Compliance Assessment:
    • Lead and oversee assessments conducted by more junior analysts.
    • Review evidence demonstrating the organization’s compliance with applicable laws, regulations, and industry standards.
    • Interview stakeholders to ensure compliance requirements are met and understood.
    • Review policies, procedures, and controls to ensure alignment with requirements.
    • Decision maker in working with cross-functional teams to resolve compliance issues.
    • Represent IT in communicating compliance-related work product to internal and external stakeholders and executive leadership.
  • Research and Innovation:
    • Function as a SME for IT Compliance.
    • Stay abreast of emerging technologies, industry trends, and best practices.
    • Research new tools, frameworks, and methodologies that can enhance solution designs and delivery.
    • Evaluate and recommend appropriate solutions.
    • Develop and communicate technology roadmaps.
    • Review and improve tools, methods, processes, and procedures.
  • Compliance Monitoring and Reporting:
    • Lead ongoing compliance activities, track regulatory changes, and prepare reports for management and regulatory agencies.
    • Document compliance findings, issues, and serve as the decision maker for remediation efforts.
    • Conduct impact assessments to determine the impact of regulatory changes and report findings to leadership.
    • Assess compliance-related risks and lead the development of risk mitigation strategies.
    • Build processes that drive automation and continuous compliance monitoring.
  • Internal and External Audits and Reviews:
    • Conduct internal assessments and reviews to evaluate the effectiveness of controls and identify areas for improvement.
    • Review access controls, data protection measures, and security configurations.
    • Lead the response to both Internal and External Audits and other stakeholders' findings and inquiries.
  • Training and Awareness:
    • Act as the top expert in compliance policies, standards, and procedures.
    • Provide training and awareness programs to educate analyst team and stakeholders about compliance requirements and best practices.
  • Policy and Procedure Development:
    • Take the lead in developing, reviewing, and updating IT policies, procedures, and standards to address compliance requirements.
    • Review and approve documents such as acceptable use policies and data retention policies plans.
    • Represent the department in communicating policies and procedures to stakeholders and executive leadership.
  • Vendor and Third-Party Compliance Management:
    • Provide oversight and decision making in vendor selection.
    • Assess the compliance of vendors and third-party service providers to ensure they meet all security and regulatory requirements.
    • Oversee audits of third-party service providers and lead the work to resolve vendor issues.
  • Performs other duties as assigned.

Qualifications

  • Bachelor's Degree in information technology, computer science, or related field or related equivalent work experience.
  • 7 years’ experience:
    • As an Auditor/assessor in a regulatory environment.
    • Conducting assessments specific to PCI and SOX.
    • Applying access controls and IAM principles.
    • Implementing and assessing segregation or separations of duties.
    • Working in a compliance role as part of a large Information Technology department.
    • Documenting and communicating regulatory requirements, standards, policies, procedures, and vulnerabilities related to compliance.
    • Leading critical compliance projects.
  • 5+ years experience:
    • Participating in cross-functional technology teams.
    • Planning and managing large projects.
    • Auditor for IT systems.
  • Required Certifications:
    • CISA (Certified Information Systems Auditor) or CIA (Certified Internal Audit).
  • Preferred certifications:
    • PMP (Project Management Professional).
    • CISM (Certified Information Security Manager).
    • CFSA (Certified Financial Systems Analyst).
    • CITGCP (Certified IT General Controls Practitioner).
    • CSOXI (Certified Sarbanes Oxley Act Practitioner).
    • PCIP (Payment Card Industry Professional).
    • CISSP (Certified Information Systems Security Professional).
  • Preferred Experience:
    • 1+ year in the cruise and/or travel industry.

Requirements

  • Expert level knowledge of systems architecture and network applications and protocols, configuration, logging, monitoring, and administration to understand impacts on compliance.
  • Ability to support a multisite enterprise environment.
  • Recognized Strategic Authority in the field of regulatory and security standards and requirements including PCI, SOX and GDPR.
  • Expertise in Cybersecurity frameworks such as NIST CSF.
  • Ability to engage and manage compliance projects to a successful outcome.
  • Intermediate-to-advanced technical knowledge across cloud platforms (AWS, Azure, GCP), IAM/PAM systems, Operating Systems (Linux/Windows), Databases and DevOps/CI-CD pipelines to support control validation and risk.
  • Ability to develop dashboards, reports, etc. that can be consumed by executives.
  • Advanced skills in critical thinking, creative problem solving, and root cause analysis with the ability to lead teams through this process.
  • Flexibility to adjust to changing priorities and manage multiple deadlines.
  • Outstanding analytical and attention to detail with exceptional business acumen.
  • Ability to manage tight deadlines, prioritize workload and achieve exceptional results.
  • Ability to write and review comprehensive and concise technical reports and presentations to be consumed by non-technical individuals.
  • Ability to create PowerPoint presentations that are informative and engaging and deliver them to various audiences including executive management.
  • Exceptional communication, team building, conflict management, and organizational skills.
  • Excellent track record of working collaboratively with cross-functional teams to achieve common goals and drive exceptional results.
  • Proficiency in MS Office.
  • Proven ability to quickly learn and teach new technologies and concepts.
  • Demonstrated capability in managing organizational dynamics.

Benefits

  • Health Benefits:
    • Cost-effective medical, dental and vision plans.
    • Employee Assistance Program and other mental health resources.
    • Additional programs include company paid term life insurance and disability coverage.
  • Financial Benefits:
    • 401(k) plan that includes a company match.
    • Employee Stock Purchase plan.
  • Paid Time Off:
    • Holidays – All full-time and part-time with benefits employees receive days off for 8 company-wide holidays, plus 2 additional floating holidays to be taken at the employee’s discretion.
    • Vacation Time – All full-time employees at the manager and below level start with 14 days/year; director and above level start with 19 days/year.
    • Sick Time – All full-time employees receive 80 hours of sick time each year.
  • Other Benefits:
    • Complementary stand-by cruises, employee discounts on confirmed cruises, plus special rates for family and friends.
    • Personal and professional learning and development resources including tuition reimbursement.
Before You Apply
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Principal Analyst, IT Compliance @Carnival Corporation
Compliance
Salary unspecified
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 1mth ago
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 127,468+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later