Security Analyst, Financial Systems

Carnival Corporation
Miami, FL, United States
15 days ago

Role details

Contract type
Permanent contract
Employment type
Part-time / full-time
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours

Tech stack

Cyber Security Identity and Access Management Information Technology Audit IT General Controls (ITGC) Information Technology

Job description

The Senior Security Analyst, Financial Systems is a senior member of the GFiT Governance & Security team and is responsible for leading and executing advanced security monitoring, risk assessment, and control activities across the GFiT environment. This role plays a key part in identifying, analyzing, and mitigating complex security risks impacting financial systems and data, while ensuring alignment with corporate security standards, ITGC/SOX requirements, and regulatory expectations.

In addition to hands-on security operations, the Senior Security Analyst provides subject-matter expertise during system implementations, enhancements, and incident response activities; partners closely with application, infrastructure, and governance teams; and supports internal and external audits. This role is expected to operate with a high degree of independence and contribute to continuous improvement of security processes and controls within the GFiT environment.

Responsibilities

  • Security Monitoring & Incident Management
  • Lead advanced monitoring and analysis of security alerts and logs from security tools, identifying trends, anomalies, and potential threats impacting GFiT financial systems.
  • Perform in-depth investigation of complex security events and incidents, including root-cause analysis, impact assessment, and coordination of remediation efforts with technical teams.
  • Serve as an escalation point for higher-risk or cross-functional security issues.
  • Risk Assessment & Control Oversight
  • Conduct and support security risk assessments across the GFiT environment, identifying control gaps and recommending risk-based remediation strategies.
  • Evaluate the security impact of system changes, new applications, and enhancements, ensuring risks are identified and addressed early in the lifecycle.
  • Support ongoing ITGC and SOX control execution related to security monitoring, access management, and incident response.
  • Implementation & Change Support
  • Act as a security subject-matter expert during implementations of new applications, integrations, and infrastructure changes, advising on secure design and configuration.
  • Review and assess security requirements, technical designs, and change requests to ensure alignment with corporate security standards and policies.
  • Partner with application, infrastructure, and PMO teams to ensure security considerations are embedded into delivery plans.
  • Audit, Compliance & Documentation
  • Serve as a key point of contact for internal and external auditors, supporting walkthroughs, evidence collection, and remediation discussions related to financial systems security.
  • Review and validate security documentation, procedures, and evidence to ensure audit readiness and consistency.
  • Identify opportunities to strengthen control design, documentation quality, and audit efficiency.
  • Continuous Improvement
  • Provide guidance to GFiT team members, supporting knowledge sharing and skill development.
  • Contribute to the development and refinement of security standards, procedures, and operational practices within GFiT.
  • Proactively identify opportunities to improve security monitoring, reporting, and operational effectiveness and raise to GFiT leadership.
  • Performs other duties as assigned, In addition to other duties/functions, this position requires full commitment and support for promoting ethical and compliant culture. More specifically, this position requires integrity, honesty, and respectful treatment of others, as well as a willingness to speak up when they see misconduct or have concerns.

Requirements

  • Bachelor’s degree in Information Technology, Computer Science, Systems Management or a related field.
  • Professional certification in compliance or financial systems (e.g., GIFS, CISM, CEH, SSCP) is preferred.
  • Strong analytical and problem-solving skills.
  • Ability to work independently and as part of a team
  • Excellent communication and interpersonal skills, with the ability to liaise effectively with internal and external security/audit representatives.
  • Minimum of 7 years of experience in IT Security, Security Operations, IT Audit and/or compliance of financial systems.
  • Proven track record of managing security initiatives and regulatory assessments.
  • Experience with security/regulatory standards and best practices in financial systems.
  • Familiarity with financial systems and security tools.
  • This position is classified as “remote.” As a remote role, it allows employees to work full-time from their home. It may also require regular travel to Carnival headquarters in Miami, FL for in-office collaboration. Sourcing of candidates is primarily done in Carnival’s remote hubs of Orlando, Tampa, Atlanta, Houston, and Dallas. If the search is extended past those areas, candidates must be located in one of the following U.S. states: FL, GA, TX and NC

Benefits & conditions

At Carnival, your total rewards package is much more than your base salary. All non-sales roles participate in an annual cash bonus program, while sales roles have an incentive plan. Director and above roles may also be eligible to participate in Carnival’s discretionary equity incentive plan. Plus, Carnival provides comprehensive and innovative benefits to meet your needs, including:

  • Health Benefits:
  • Cost-effective medical, dental and vision plans
  • Employee Assistance Program and other mental health resources
  • Additional programs include company paid term life insurance and disability coverage
  • Financial Benefits:
  • 401(k) plan that includes a company match
  • Employee Stock Purchase plan
  • Paid Time Off:
  • Holidays - All full-time and part-time with benefits employees receive days off for 8 company-wide holidays, plus 2 additional floating holidays to be taken at the employee’s discretion.
  • Vacation Time - All full-time employees at the manager and below level start with 14 days/year; director and above level start with 19 days/year. Part-time with benefits employees receive time off based on the number of hours they work, with a minimum of 84 hours/year. All employees gain additional vacation time with further tenure.
  • Sick Time - All full-time employees receive 80 hours of sick time each year. Part-time with benefits employees receive time off based on the number of hours they work, with a minimum of 60 hours each year.
  • Other Benefits:
  • Complementary stand-by cruises, employee discounts on confirmed cruises, plus special rates for family and friends
  • Personal and professional learning and development resources including tuition reimbursement

Corp, * Aida

  • HAP Alaska-Yukon
  • Carnival Corporation
  • Holland America Line
  • Carnival Cruise Line
  • Carnival UK
  • Costa
  • Princess
  • Seabourn

About the company

Carnival Corporation & plc is the world’s largest leisure travel company, our mission to deliver unforgettable happiness to our guest through our diverse portfolio of leading cruise brands and island destinations, including Carnival Cruise Line, Holland America Line, Princess Cruises, and Seabourn in North America and Australia; P&O Cruises and Cunard Line in the United Kingdom; AIDA in Germany; Costa Cruises in Southern Europe.

Join us and embark on a career that offers not only the chance to grow professionally but also the opportunity to be part of a global community that makes a difference.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on eicl.fa.em5.oraclecloud.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:24 min

Evaluating remote software roles and compensation structures

Nacho Iacovino ¡ WWC 2021

1:26 min

Bridging the sim-to-real gap with multi-control networks

Alexander Schwarz Alexander Schwarz ¡ WWC 2025

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon ¡ LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman ¡ WWC 2022

2:49 min

Verifying dependency metadata accuracy through controlled package installations

Uwe Korn Uwe Korn ¡ WWC Europe 2026

2:46 min

Missing equipment retrieval processes for departing employees

Jasmin Azemović Jasmin Azemović · WWC Europe 2026

Videos

See all

Related articles

See all